Do web frameworks check authorization headers before reading the body?

Viewed 94

I was wondering if web frameworks like Flask, Django, Akka HTTP, or Spring check headers before reading the body of the request.

I can have a web server endpoint that is used to upload some files, eg user avatar. Presumably, I could bump the server with huge files but without Auth headers and slow it down.

I think the server should first check if user is authorized / if headers are fine before reading the body into the memory. How do web frameworks solve this problem? Where can I read more how is it handled?

1 Answers

Web frameworks are designed to flexibly handle a large number of use cases. One of these use cases is uploading large files. Any mature framework will have a mechanism for handling this use-case without consuming large amounts of memory, usually by storing the data to disk. Some also expose a method for application handlers to access the raw byte stream directly.

Under the hood frameworks read the headers first. They will typically hand the request off to the application handler after parsing the headers. Authorization is then handled by the app. Most frameworks will expose some method of accessing the raw data stream of the bytes, but the more convenient method is to read and parse the data into convenience structures upon the application's first request for data. Applications may need to configure the framework not to do that. Often, frameworks allow applications to set a max upload size. Above that size, and the client receives an error.

Each framework's documentation can provide details on uploads. Here is the upload documentation for each of the frameworks you specified:

Related