Skip to content

Configuring Body Size Limits

By default, a request body over 1 MiB is rejected with 413 Payload Too Large before your controller method runs — see Request Validation for exactly when this check happens.

Pass bodyLimit (in bytes) to createHttpApplication:

import { createHttpApplication } from "@blixis-io/http";
const app = await createHttpApplication(AppModule, {
bodyLimit: 5 * 1024 * 1024, // 5 MiB
});

The same option works with @blixis-io/testing’s Test.createModule(...).compile(options):

const app = await Test.createModule({ imports: [PostsModule] }).compile({
bodyLimit: 100, // deliberately tiny, to test the 413 path itself
});

Only to routes with a @Body() parameter — a route that never reads the body never triggers either the Content-Length pre-check or the actual byte-length check, regardless of the limit. There’s currently no per-route override; it’s one limit for the whole application. If different routes genuinely need different limits (a file upload endpoint alongside small JSON APIs), that’s a gap worth knowing about now rather than discovering at the worst time — the current framework doesn’t have a built-in answer for it.

A declared Content-Length header is checked first, cheaply, before the body is even read — a client that’s honest about a too-large body gets rejected immediately. The body is then read as a stream and cancelled the moment it crosses the limit, since Content-Length is just a claim the client makes, not a guarantee. A chunked body with no Content-Length is never buffered whole before being rejected.