AOSSIE-Org / AOSSIE-Org/EduAid

[Enhancement] Add request payload size limits (MAX_CONTENT_LENGTH) to protect backend API endpoints

Abierto
#564 0 comentarios 0 reacciones 0 asignados Ver en GitHub
enhancement
Lenguaje dominante
JavaScript
Estrellas
171
Forks
425
Métricas de merge de PR
Sin PR fusionados en 30 d

Descripción

### Feature and its Use Cases

## Feature Description

EduAid backend API endpoints currently accept JSON payloads containing text used for quiz generation and question answering. However, there is currently no restriction on the size of incoming request payloads.

Since these endpoints trigger transformer-based NLP models, very large inputs could lead to:

- excessive memory usage
- increased model inference time
- degraded performance for other users
- potential denial-of-service scenarios

Introducing request payload size limits would help protect the backend from extremely large requests before they reach the NLP pipeline.

---

## Potential Use Cases

For example, a client could send a request with an extremely large `input_text` payload (multiple MBs of text). Processing such inputs could:

- significantly increase CPU/GPU usage
- slow down quiz generation for other users
- exhaust backend resources

By enforcing a payload size limit, the API can safely reject overly large requests before expensive NLP processing begins.

---

## Example Scenario

If a request exceeds the allowed size (for example **2MB**), the backend could return a response like:

```json
{
"error": "Request payload too large",
"code": "payload_too_large"
}
```

---

### Additional Context

This enhancement complements other backend protection mechanisms already being introduced in EduAid such as:

- request rate limiting
- defensive input validation
- improved error handling

Adding request payload limits would further strengthen backend stability, especially for endpoints that trigger expensive NLP model inference.

---

### Possible Implementation

One simple approach is to configure Flask’s built-in request size limit:

```python
app.config["MAX_CONTENT_LENGTH"] = 2 * 1024 * 1024 # 2MB limit
```

---

### Code of Conduct

- [x] I have joined the [Discord server](https://discord.gg/hjUhu33uAn) and will post updates there
- [x] I have searched existing issues to avoid duplicates

Guía de contribución

No hay ninguna guía de contribución indexada para este repositorio

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.