Files
sim/apps
Waleed ec3156f1bc fix(files): count the document body against the export limit (#6006)
* fix(files): count the document body against the export limit

The 250 MB export cap measured only the embedded assets' declared sizes. The
markdown body was downloaded with no limit and never counted, so a large
document with modest attachments cleared the check and still produced a zip well
over the stated limit, materialized whole in memory.

The body is the largest single entry in most bundles, so excluding it left the
limit unenforced against the item most able to exceed it. It is now capped on
read and counted alongside its assets, and the message names both.

Follow-up to #5995, which introduced the asset caps without extending them to
the body.

* test(v1): cover the file download's rendered-bytes behavior

The route had no tests, and #5995 changed what it serves: rendered bytes, the
resolved content type rather than the record's source MIME, Content-Length from
the rendered length, and a retryable 409 while an artifact compiles.

One test pins the filename/content-type relationship. A review flagged the
download as naming a rendered file with a source extension, but the renderer
picks its output format from the file name — getE2BDocFormat and
COMPILABLE_FORMATS both key on it — so a .docx renders to a docx and the two
cannot disagree. The test makes that argument executable rather than a comment.

* fix(files): report an oversized document body as a size rejection

Capping the body read meant an oversized document threw PayloadSizeLimitError,
which nothing caught, so the caller got a generic 500 — hiding the very limit
message the cap was added to produce. It now returns the same 400 as the bundle
check, naming the export limit.

* chore(files): drop the unreachable export asset-count cap

extractEmbeddedFileRefs stops collecting at MAX_EMBEDDED_IMAGES, so the list this
route receives is already bounded before it arrives and the count check could
never fire. Its test only passed because it mocked the extractor, so it asserted
a branch production cannot reach.

The byte ceilings are the real bound and stay. A comment records where the count
is actually enforced, so the next reader does not add a second one.
2026-07-28 10:59:14 -07:00
..