NAME
Langertha::HTTP::BoundedDecode - Bounded Content-Encoding inflate shared by the response-body decoders
VERSION
version 0.503
SYNOPSIS
use Langertha::HTTP::BoundedDecode;
my $bytes = Langertha::HTTP::BoundedDecode::decode_within(
$response->content, # the raw body
scalar $response->header('Content-Encoding'),
$max_decoded_bytes,
{
too_big => sub { croak "body exceeds $_[0]" },
undecodable => sub { croak "cannot decode '$_[0]'" },
unbounded_encoding => sub { croak "cannot bound '$_[0]'" },
},
);
DESCRIPTION
The bounded Content-Encoding inflater behind Langertha's response decoders. "decoded_content" in HTTP::Message undoes a Content-Encoding (gzip, deflate, bzip2) with no size bound, so a small compressed body can inflate to gigabytes in memory — a decompression bomb from a hostile or broken endpoint. This module inflates in bounded blocks and refuses a body once its decoded size passes $max, so the memory is capped.
It carries no error text of its own: each caller passes the three croak points, so Langertha::Content::Image (image fetches, karr k342) and Langertha::Role::HTTP (provider/metrics response bodies, karr k346) keep their own messages while sharing one inflate path. It returns the decoded bytes; charset decoding is the caller's concern.
decode_within
my $bytes = Langertha::HTTP::BoundedDecode::decode_within(
$raw_body, $content_encoding_header, $max, \%handlers );
Undoes the Content-Encoding of $raw_body within $max decoded bytes and returns the decoded bytes. A comma-listed encoding is undone in reverse of the order it was applied. Calls $handlers->{too_big}->($max) as soon as the decoded size passes $max, $handlers->{undecodable}->($encoding) when a supported encoding is corrupt, and $handlers->{unbounded_encoding}->($encoding) for an encoding it cannot bound (anything but gzip / deflate / bzip2 and their x- aliases and identity). Each handler is expected to croak.
SEE ALSO
Langertha::Content::Image - Bounds inline image fetches (karr k342)
Langertha::Role::HTTP - Bounds provider/metrics response bodies (karr k346)
SUPPORT
Issues
Please report bugs and feature requests on GitHub at https://github.com/Getty/langertha/issues.
IRC
Join #langertha on irc.perl.org or message Getty directly.
CONTRIBUTING
Contributions are welcome! Please fork the repository and submit a pull request.
AUTHOR
Torsten Raudssus <getty@cpan.org>
COPYRIGHT AND LICENSE
This software is copyright (c) 2026 by Torsten Raudssus https://raudssus.de/.
This is free software; you can redistribute it and/or modify it under the same terms as the Perl 5 programming language system itself.