ec29590a0f
The webhook adapter enforced max_body_bytes only via the Content-Length header; a Transfer-Encoding: chunked request (content_length=None) or a spoofed small Content-Length bypassed the cap entirely and read the full body (bounded only by aiohttp's implicit 1 MiB default, above any operator-configured smaller limit). - web.Application(client_max_size=max_body_bytes): aiohttp enforces the cap on every read path, chunked included - catch HTTPRequestEntityTooLarge -> 413 (was swallowed into generic 400) - post-read length re-check as defense in depth - chunked-upload regression test Manual port of PR #3955 by @Gutslabs onto current main (handler had been restructured since); authorship preserved.