Skip to content

Fix: handle malformed multipart bodies - #2196

Merged
mnapoli merged 1 commit into
masterfrom
fix-empty-multipart
Oct 5, 2026
Merged

mnapoli merged 1 commit into
masterfrom
fix-empty-multipart

Conversation

@mnapoli

@mnapoli mnapoli commented Oct 5, 2026

Copy link
Copy Markdown
Member

When a POST request has a multipart/form-data content type but a body that riverline/multipart-parser cannot parse, Psr7Bridge lets the parser's exception escape. The Lambda invocation fails before the application runs: the client gets a 5xx, the application cannot handle it, and the process restarts.

This happens with valid requests too: a FormData with no fields is sent by browsers as just the closing boundary (--boundary--), which the parser rejects with LogicException: Can't find multi-part content. We saw this in production with a Laravel Octane application.

PHP-FPM never fails on these bodies: PHP gives an empty $_POST (or what it could parse) and the application decides what to do. This only affects the PSR-7 bridge (Octane, PSR-15 and other handlers that use Psr7Bridge).

The bridge now catches the parser's exceptions (LogicException, which InvalidArgumentException extends) and ignores the body: no parsed body and no uploaded files, the raw body is still available. A failure to create a temporary file is still reported.

I considered returning a 400 instead, but:

  • an empty form is a valid request, it must not be rejected
  • the response would be generated by Bref outside of the application (no middleware, no CORS headers, not reported by the application's error handler)
  • it would make the PSR-7 bridge behave differently from PHP-FPM

The new test covers an empty form, an empty body, a missing closing boundary, a content type without boundary and a nested multipart/mixed part. All 5 cases threw before this change.

The multipart parser throws on bodies it cannot parse, including an empty
form (browsers send only the closing boundary for a FormData with no fields).
The exception failed the whole invocation before the application ran.
PHP-FPM ignores these bodies, so the PSR-7 bridge now does the same.

Claude-Session: https://claude.ai/code/session_016WNB2UWjhyHkDifCSsk3V2
@mnapoli mnapoli changed the title Ignore malformed multipart bodies instead of failing the request Fix: handle malformed multipart bodies Oct 5, 2026
@mnapoli
mnapoli merged commit 7674cea into master Oct 5, 2026
8 checks passed
@mnapoli
mnapoli deleted the fix-empty-multipart branch October 5, 2026 07:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant