{"record":{"id":"46dec4f4ae41b602","repo":"withastro/astro","slug":"request-body-exceeds-the-configured-limit-of-lim","errorCode":null,"errorMessage":"Request body exceeds the configured limit of ${limit} bytes","messagePattern":"Request body exceeds the configured limit of (.+?) bytes","errorType":"exception","errorClass":"BodySizeLimitError","httpStatus":null,"severity":"error","filePath":"packages/astro/src/core/request-body.ts","lineNumber":19,"sourceCode":"/**\n * Shared utility for reading request bodies with a size limit.\n * Used by both Actions and Server Islands to enforce `security.actionBodySizeLimit`\n * and `security.serverIslandBodySizeLimit` respectively.\n */\n\n/**\n * Read the request body as a `Uint8Array`, enforcing a maximum size limit.\n * Checks the `Content-Length` header for early rejection, then streams the body\n * and tracks bytes received.\n *\n * @throws {BodySizeLimitError} if the body exceeds the configured limit\n */\nexport async function readBodyWithLimit(request: Request, limit: number): Promise<Uint8Array> {\n\tconst contentLengthHeader = request.headers.get('content-length');\n\tif (contentLengthHeader) {\n\t\tconst contentLength = Number.parseInt(contentLengthHeader, 10);\n\t\tif (Number.isFinite(contentLength) && contentLength > limit) {\n\t\t\tthrow new BodySizeLimitError(limit);\n\t\t}\n\t}\n\n\tif (!request.body) return new Uint8Array();\n\tconst reader = request.body.getReader();\n\tconst chunks: Uint8Array[] = [];\n\tlet received = 0;\n\twhile (true) {\n\t\tconst { done, value } = await reader.read();\n\t\tif (done) break;\n\t\tif (value) {\n\t\t\treceived += value.byteLength;\n\t\t\tif (received > limit) {\n\t\t\t\tthrow new BodySizeLimitError(limit);\n\t\t\t}\n\t\t\tchunks.push(value);\n\t\t}\n\t}","sourceCodeStart":1,"sourceCodeEnd":37,"githubUrl":"https://github.com/withastro/astro/blob/52e6c34790cc8ac4e69e6135ace06049867e5c4a/packages/astro/src/core/request-body.ts#L1-L37","documentation":"Astro enforces a maximum request body size for Actions and Server Islands, configured by `security.actionBodySizeLimit` (default 1 MiB). `readBodyWithLimit` performs an early check: if the request carries a `Content-Length` header that parses as a finite number above the limit, it throws `BodySizeLimitError` immediately without reading the body. The Actions runtime converts it to an `ActionError` with code `CONTENT_TOO_LARGE`.","triggerScenarios":"POSTing an Action form or JSON payload larger than `actionBodySizeLimit` with a `Content-Length` header (normal non-streaming clients); a Server Island fallback POST body over the limit; large base64-encoded file payloads sent through an Action input.","commonSituations":"Image/file uploads sent through Actions hitting the 1 MB default; API migrations where an Action now receives previously larger bodies; content-heavy forms (rich text with embedded images).","solutions":["Raise the limit in astro.config: `security: { actionBodySizeLimit: 10 * 1024 * 1024 }`","Shrink the payload — upload files directly (presigned URL / separate endpoint) and send only metadata through the Action","Check the payload size client-side before submitting and warn early"],"exampleFix":"// before — astro.config.mjs\nexport default defineConfig({});\n\n// after — raise the Actions/Server Islands body limit (default 1 MB)\nexport default defineConfig({\n  security: { actionBodySizeLimit: 10 * 1024 * 1024 }, // 10 MB\n});","handlingStrategy":"validation","validationCode":"// Client-side pre-check before submitting an Action payload\nconst LIMIT = 1024 * 1024; // must mirror security.actionBodySizeLimit\nconst size = new Blob([JSON.stringify(input)]).size;\nif (size > LIMIT) {\n  return ui.error(`Payload ${(size / 1024).toFixed(0)} KB exceeds ${LIMIT / 1024} KB`);\n}\nawait actions.save(input);","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Set `security.actionBodySizeLimit` deliberately based on your largest legitimate payload","Keep file uploads out of Actions — upload directly and pass references","Compute payload size client-side (Blob) and warn before the round-trip"],"tags":["actions","server-islands","body-size-limit","http-413","security-config"],"backgroundTag":"request-body-too-large","analyzedSha":"52e6c34790cc8ac4e69e6135ace06049867e5c4a","analyzedAt":"2026-08-18T18:48:03.901Z","contentChangedAt":"2026-08-18T18:48:03.901Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}