You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: deps/undici/src/README.md
+10-1Lines changed: 10 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -378,7 +378,16 @@ The `body` mixins are the most common way to format the request/response body. M
378
378
> The body returned from `undici.request` does not implement `.formData()`.
379
379
380
380
> [!WARNING]
381
-
> Calling `body.formData()` on a fetch response causes undici to buffer and parse the entire body. Since this is dictated by the spec, `body.formData()` must only be called on responses from trusted servers.
381
+
> The body mixins `.arrayBuffer()`, `.blob()`, `.bytes()`, `.json()`, `.text()`,
382
+
> and `.formData()` buffer the entire body in memory before returning. Where
383
+
> applicable, they also decode or parse the payload and retain that
384
+
> representation in memory. Calling these methods therefore means trusting that
385
+
> the response body is small enough to fit in the available memory. Do not use
386
+
> them for responses from untrusted or user-controlled sources. Instead, consume
387
+
> the response body as a stream and enforce an application-specific size limit:
388
+
> use `response.body` for fetch responses or the `body` returned by
389
+
> `undici.request()`. For streaming decoded text, use `body.textStream()` on a
Copy file name to clipboardExpand all lines: deps/undici/src/docs/docs/index.md
+10-1Lines changed: 10 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -380,7 +380,16 @@ The `body` mixins are the most common way to format the request/response body. M
380
380
> The body returned from `undici.request` does not implement `.formData()`.
381
381
382
382
> [!WARNING]
383
-
> Calling `body.formData()` on a fetch response causes undici to buffer and parse the entire body. Since this is dictated by the spec, `body.formData()` must only be called on responses from trusted servers.
383
+
> The body mixins `.arrayBuffer()`, `.blob()`, `.bytes()`, `.json()`, `.text()`,
384
+
> and `.formData()` buffer the entire body in memory before returning. Where
385
+
> applicable, they also decode or parse the payload and retain that
386
+
> representation in memory. Calling these methods therefore means trusting that
387
+
> the response body is small enough to fit in the available memory. Do not use
388
+
> them for responses from untrusted or user-controlled sources. Instead, consume
389
+
> the response body as a stream and enforce an application-specific size limit:
390
+
> use `response.body` for fetch responses or the `body` returned by
391
+
> `undici.request()`. For streaming decoded text, use `body.textStream()` on a
0 commit comments