withastro/astro · error · BodySizeLimitError

Request body exceeds the configured limit of

Error message

Request body exceeds the configured limit of ${limit} bytes

What it means

Astro enforces a maximum request body size for Actions and Server Islands, configured by `security.actionBodySizeLimit` (default 1 MiB). `readBodyWithLimit` performs an early check: if the request carries a `Content-Length` header that parses as a finite number above the limit, it throws `BodySizeLimitError` immediately without reading the body. The Actions runtime converts it to an `ActionError` with code `CONTENT_TOO_LARGE`.

Solutions

  1. Raise the limit in astro.config: `security: { actionBodySizeLimit: 10 * 1024 * 1024 }`
  2. Shrink the payload — upload files directly (presigned URL / separate endpoint) and send only metadata through the Action
  3. Check the payload size client-side before submitting and warn early

Example fix

// before — astro.config.mjs
export default defineConfig({});

// after — raise the Actions/Server Islands body limit (default 1 MB)
export default defineConfig({
  security: { actionBodySizeLimit: 10 * 1024 * 1024 }, // 10 MB
});
Defensive patterns

Strategy: validation

Validate before calling

// Client-side pre-check before submitting an Action payload
const LIMIT = 1024 * 1024; // must mirror security.actionBodySizeLimit
const size = new Blob([JSON.stringify(input)]).size;
if (size > LIMIT) {
  return ui.error(`Payload ${(size / 1024).toFixed(0)} KB exceeds ${LIMIT / 1024} KB`);
}
await actions.save(input);

Prevention

When it happens

Trigger: POSTing an Action form or JSON payload larger than `actionBodySizeLimit` with a `Content-Length` header (normal non-streaming clients); a Server Island fallback POST body over the limit; large base64-encoded file payloads sent through an Action input.

Common situations: Image/file uploads sent through Actions hitting the 1 MB default; API migrations where an Action now receives previously larger bodies; content-heavy forms (rich text with embedded images).

Related errors


AI-assisted analysis of withastro/astro@52e6c34790 (2026-08-18). Data as JSON: /api/errors/46dec4f4ae41b602. Report an issue: GitHub.

Appendix: source

Thrown at packages/astro/src/core/request-body.ts:19

/**
 * Shared utility for reading request bodies with a size limit.
 * Used by both Actions and Server Islands to enforce `security.actionBodySizeLimit`
 * and `security.serverIslandBodySizeLimit` respectively.
 */

/**
 * Read the request body as a `Uint8Array`, enforcing a maximum size limit.
 * Checks the `Content-Length` header for early rejection, then streams the body
 * and tracks bytes received.
 *
 * @throws {BodySizeLimitError} if the body exceeds the configured limit
 */
export async function readBodyWithLimit(request: Request, limit: number): Promise<Uint8Array> {
	const contentLengthHeader = request.headers.get('content-length');
	if (contentLengthHeader) {
		const contentLength = Number.parseInt(contentLengthHeader, 10);
		if (Number.isFinite(contentLength) && contentLength > limit) {
			throw new BodySizeLimitError(limit);
		}
	}

	if (!request.body) return new Uint8Array();
	const reader = request.body.getReader();
	const chunks: Uint8Array[] = [];
	let received = 0;
	while (true) {
		const { done, value } = await reader.read();
		if (done) break;
		if (value) {
			received += value.byteLength;
			if (received > limit) {
				throw new BodySizeLimitError(limit);
			}
			chunks.push(value);
		}
	}

View on GitHub (pinned to 52e6c34790)