withastro/astro · error · BodySizeLimitError
Request body exceeds the configured limit of
Error message
Request body exceeds the configured limit of ${limit} bytes What it means
Astro enforces a maximum request body size for Actions and Server Islands, configured by `security.actionBodySizeLimit` (default 1 MiB). `readBodyWithLimit` performs an early check: if the request carries a `Content-Length` header that parses as a finite number above the limit, it throws `BodySizeLimitError` immediately without reading the body. The Actions runtime converts it to an `ActionError` with code `CONTENT_TOO_LARGE`.
Solutions
- Raise the limit in astro.config: `security: { actionBodySizeLimit: 10 * 1024 * 1024 }`
- Shrink the payload — upload files directly (presigned URL / separate endpoint) and send only metadata through the Action
- Check the payload size client-side before submitting and warn early
Example fix
// before — astro.config.mjs
export default defineConfig({});
// after — raise the Actions/Server Islands body limit (default 1 MB)
export default defineConfig({
security: { actionBodySizeLimit: 10 * 1024 * 1024 }, // 10 MB
}); Defensive patterns
Strategy: validation
Validate before calling
// Client-side pre-check before submitting an Action payload
const LIMIT = 1024 * 1024; // must mirror security.actionBodySizeLimit
const size = new Blob([JSON.stringify(input)]).size;
if (size > LIMIT) {
return ui.error(`Payload ${(size / 1024).toFixed(0)} KB exceeds ${LIMIT / 1024} KB`);
}
await actions.save(input); Prevention
- Set `security.actionBodySizeLimit` deliberately based on your largest legitimate payload
- Keep file uploads out of Actions — upload directly and pass references
- Compute payload size client-side (Blob) and warn before the round-trip
When it happens
Trigger: POSTing an Action form or JSON payload larger than `actionBodySizeLimit` with a `Content-Length` header (normal non-streaming clients); a Server Island fallback POST body over the limit; large base64-encoded file payloads sent through an Action input.
Common situations: Image/file uploads sent through Actions hitting the 1 MB default; API migrations where an Action now receives previously larger bodies; content-heavy forms (rich text with embedded images).
Related errors
- BAD_REQUEST
- CONTENT_TOO_LARGE
- Could not find server component export
- Could not find server component name
- Could not find server component path
AI-assisted analysis of withastro/astro@52e6c34790 (2026-08-18).
Data as JSON: /api/errors/46dec4f4ae41b602.
Report an issue: GitHub.
Appendix: source
Thrown at packages/astro/src/core/request-body.ts:19
/**
* Shared utility for reading request bodies with a size limit.
* Used by both Actions and Server Islands to enforce `security.actionBodySizeLimit`
* and `security.serverIslandBodySizeLimit` respectively.
*/
/**
* Read the request body as a `Uint8Array`, enforcing a maximum size limit.
* Checks the `Content-Length` header for early rejection, then streams the body
* and tracks bytes received.
*
* @throws {BodySizeLimitError} if the body exceeds the configured limit
*/
export async function readBodyWithLimit(request: Request, limit: number): Promise<Uint8Array> {
const contentLengthHeader = request.headers.get('content-length');
if (contentLengthHeader) {
const contentLength = Number.parseInt(contentLengthHeader, 10);
if (Number.isFinite(contentLength) && contentLength > limit) {
throw new BodySizeLimitError(limit);
}
}
if (!request.body) return new Uint8Array();
const reader = request.body.getReader();
const chunks: Uint8Array[] = [];
let received = 0;
while (true) {
const { done, value } = await reader.read();
if (done) break;
if (value) {
received += value.byteLength;
if (received > limit) {
throw new BodySizeLimitError(limit);
}
chunks.push(value);
}
}View on GitHub (pinned to 52e6c34790)