<style>
/* Changing the layout to use less space for mobiles */
@media screen and (max-device-width: 480px), screen and (-webkit-min-device-pixel-ratio: 2) {
    #email-body { min-width: 30em !important; }
    #email-page { padding: 8px !important; }
    #email-banner { padding: 8px 8px 0 8px !important; }
    #email-avatar { margin: 1px 8px 8px 0 !important; padding: 0 !important; }
    #email-fields { padding: 0 8px 8px 8px !important; }
    #email-gutter { width: 0 !important; }
}
</style>
<div id="email-body">
<table id="email-wrap" align="center" border="0" cellpadding="0" cellspacing="0" style="background-color:#f0f0f0;color:#000000;width:100%;">
    <tr valign="top">
        <td id="email-page" style="padding:16px !important;">
            <table align="center" border="0" cellpadding="0" cellspacing="0" style="background-color:#ffffff;border:1px solid #bbbbbb;color:#000000;width:100%;">
                <tr valign="top">
                    <td bgcolor="#ffffff" style="background-color:#ffffff;color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;line-height:1;"><img src="https://shibboleth.net/images/shib_240x83.png" alt="" style="vertical-align:top;" /></td>
                </tr><tr valign="top">
    <td id="email-banner" style="padding:32px 32px 0 32px;">
        
                
        
        
            <table align="left" border="0" cellpadding="0" cellspacing="0" width="100%" style="width:100%;">
    <tr valign="top">
        <td style="color:#505050;font-family:Arial,FreeSans,Helvetica,sans-serif;padding:0;">
                                        <img id="email-avatar" src="https://issues.shibboleth.net/jira/secure/useravatar?avatarId=10202" alt="" height="48" width="48" border="0" align="left" style="padding:0;margin: 0 16px 16px 0;" />
                        <div id="email-action" style="padding: 0 0 8px 0;font-size:12px;line-height:18px;">
                                    <a class="user-hover" rel="vtsji@idp.protectnetwork.org" id="email_vtsji@idp.protectnetwork.org" href="https://issues.shibboleth.net/jira/secure/ViewProfile.jspa?name=vtsji%40idp.protectnetwork.org" style="color:#326ca6;">vtsji@idp.protectnetwork.org</a>
     created <img src="https://issues.shibboleth.net/jira/images/icons/issuetypes/bug.png" height="16" width="16" border="0" align="absmiddle" alt="Bug"> <a style='color:#326ca6;text-decoration:none;' href='https://issues.shibboleth.net/jira/browse/SSPCPP-584'>SSPCPP-584</a>
            </div>
                        <div id="email-summary" style="font-size:16px;line-height:20px;padding:2px 0 16px 0;">
                <a style='color:#326ca6;text-decoration:none;' href='https://issues.shibboleth.net/jira/browse/SSPCPP-584'><strong>Limit on preserved POST data size is not enforced</strong></a>
            </div>
                    </td>
    </tr>
</table>
    </td>
</tr>
<tr valign="top">
    <td id="email-fields" style="padding:0 32px 32px 32px;">
        <table border="0" cellpadding="0" cellspacing="0" style="padding:0;text-align:left;width:100%;" width="100%">
            <tr valign="top">
                <td id="email-gutter" style="width:64px;white-space:nowrap;"></td>
                <td>
                    <table border="0" cellpadding="0" cellspacing="0" width="100%">
                        <tr valign="top">
    <td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 10px 10px 0;white-space:nowrap;">
        <strong style="font-weight:normal;color:#505050;">Issue Type:</strong>
    </td>
    <td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 10px 0;width:100%;">
                <img src="https://issues.shibboleth.net/jira/images/icons/issuetypes/bug.png" height="16" width="16" border="0" align="absmiddle" alt="Bug">        Bug
    </td>
</tr>                        <tr valign="top">
    <td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 10px 10px 0;white-space:nowrap;">
        <strong style="font-weight:normal;color:#505050;">Affects Versions:</strong>
    </td>
    <td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 10px 0;width:100%;">
                    2.5.2            </td>
</tr>
                        <tr valign="top">
    <td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 10px 10px 0;white-space:nowrap;">
        <strong style="font-weight:normal;color:#505050;">Assignee:</strong>
    </td>
    <td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 10px 0;width:100%;">
                                        <a class="user-hover" rel="cantor.2@osu.edu" id="email_cantor.2@osu.edu" href="https://issues.shibboleth.net/jira/secure/ViewProfile.jspa?name=cantor.2%40osu.edu" style="color:#326ca6;">Scott Cantor</a>
                </td>
</tr>                                                <tr valign="top">
    <td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 10px 10px 0;white-space:nowrap;">
        <strong style="font-weight:normal;color:#505050;">Components:</strong>
    </td>
    <td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 10px 0;width:100%;">
                    Request Processing            </td>
</tr>
                        <tr valign="top">
    <td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 10px 10px 0;white-space:nowrap;">
        <strong style="font-weight:normal;color:#505050;">Created:</strong>
    </td>
    <td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 10px 0;width:100%;">
        04/Jul/13 9:15 AM
    </td>
</tr>                        <tr valign="top">
    <td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 10px 10px 0;white-space:nowrap;">
        <strong style="font-weight:normal;color:#505050;">Description:</strong>
    </td>
    <td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 10px 0;width:100%;">
        <p style='margin-top:0;margin-bottom:10px;'>From reading the code for <tt>AbstractHandler::getPostData</tt>, I found that the postLimit setting can be used to limit the allowed size of initial application/x-www-form-urlencoded POST data to be preserved.</p>

<p style='margin-top:0;margin-bottom:10px;'>However, actually testing this out shows that this limit is not actually being enforced. The config from shibboleth2.xml and commands I used to test are:</p>

<div class="code panel" style="border-width: 1px;"><div class="codeContent panelContent">
<pre class="code-java">
&lt;Sessions lifetime=<span class="code-quote">"14400"</span> timeout=<span class="code-quote">"300"</span> checkAddress=<span class="code-quote">"<span class="code-keyword">true</span>"</span> idpHistory=<span class="code-quote">"<span class="code-keyword">false</span>"</span>
    handlerURL=<span class="code-quote">"/.sso"</span> handlerSSL=<span class="code-quote">"<span class="code-keyword">true</span>"</span> cookieProps=<span class="code-quote">"; path=/; secure; HttpOnly"</span> relayState=<span class="code-quote">"ss:mem"</span>
    redirectLimit=<span class="code-quote">"exact"</span>
    postData=<span class="code-quote">"ss:mem"</span> postLimit=<span class="code-quote">"512000"</span>&gt;
</pre>
</div></div>

<div class="code panel" style="border-width: 1px;"><div class="codeContent panelContent">
<pre class="code-java">
$ perl -e 'print <span class="code-quote">"a="</span>.(<span class="code-quote">"a"</span>x(512001-2));' &gt;postdata
$ curl -k --data @postdata --proxy "" https:<span class="code-comment">//myserver/</span>
</pre>
</div></div>

<p style='margin-top:0;margin-bottom:10px;'>According to the code, if the submitted POST data exceeds the limit, a warning should be logged indicating that POST data was lost, but I did not find any such log entry:</p>

<div class="code panel" style="border-width: 1px;"><div class="codeHeader panelHeader" style="border-bottom-width: 1px;"><b>AbstractHandler.cpp</b></div><div class="codeContent panelContent">
<pre class="code-java">
DDF AbstractHandler::getPostData(<span class="code-keyword">const</span> Application&amp; application, <span class="code-keyword">const</span> HTTPRequest&amp; request) <span class="code-keyword">const</span>
{
    string contentType = request.getContentType();
    <span class="code-keyword">if</span> (contentType.find(<span class="code-quote">"application/x-www-form-urlencoded"</span>) != string::npos) {
        <span class="code-keyword">const</span> PropertySet* props = application.getPropertySet(<span class="code-quote">"Sessions"</span>);
        pair&lt;bool,unsigned <span class="code-object">int</span>&gt; plimit = props ? props-&gt;getUnsignedInt(<span class="code-quote">"postLimit"</span>) : pair&lt;bool,unsigned <span class="code-object">int</span>&gt;(<span class="code-keyword">false</span>,0);
        <span class="code-keyword">if</span> (!plimit.first)
            plimit.second = 1024 * 1024;
        request.getRequestBody();
        <span class="code-keyword">if</span> (plimit.second == 0 || request.getContentLength() &lt;= plimit.second) {
            CGIParser cgi(request);
            pair&lt;CGIParser::walker,CGIParser::walker&gt; params = cgi.getParameters(nullptr);
            <span class="code-keyword">if</span> (params.first == params.second)
                <span class="code-keyword">return</span> DDF(<span class="code-quote">"parameters"</span>).list();
            DDF child;
            DDF ret = DDF(<span class="code-quote">"parameters"</span>).list();
            <span class="code-keyword">for</span> (; params.first != params.second; ++params.first) {
                <span class="code-keyword">if</span> (!params.first-&gt;first.empty()) {
                    child = DDF(params.first-&gt;first.c_str()).unsafe_string(params.first-&gt;second);
                    ret.add(child);
                }
            }
            <span class="code-keyword">return</span> ret;
        }
        <span class="code-keyword">else</span> {
            m_log.warn(<span class="code-quote">"POST limit exceeded, ignoring %d bytes of posted data"</span>, request.getContentLength());
        }
    }
    <span class="code-keyword">else</span> {
        m_log.info(<span class="code-quote">"ignoring POST data with non-standard encoding (%s)"</span>, contentType.c_str());
    }
    <span class="code-keyword">return</span> DDF();
}
</pre>
</div></div>

<p style='margin-top:0;margin-bottom:10px;'>Stepping through the code in a debugger shows that the call to <tt>request.getContentLength()</tt> always returns 0. For my Apache environment, this method is implemented by <tt>ShibTargetApache::getContentLength</tt>:</p>

<div class="code panel" style="border-width: 1px;"><div class="codeHeader panelHeader" style="border-bottom-width: 1px;"><b>mod_shib.cpp</b></div><div class="codeContent panelContent">
<pre class="code-java">
<span class="code-object">long</span> getContentLength() <span class="code-keyword">const</span> {
    <span class="code-keyword">return</span> m_gotBody ? m_body.length() : m_req-&gt;remaining;
}
</pre>
</div></div>

<p style='margin-top:0;margin-bottom:10px;'>The <tt>m_gotBody</tt> field is always false, even for POST requests with a request body. It looks like this field only becomes initialized after a call to <tt>ShibTargetApache::getRequestBody()</tt>, but setting a breakpoint on this function shows that it is never called before the <tt>getContentLength()</tt> check.</p>

<p style='margin-top:0;margin-bottom:10px;'>I have to admit that I don't know why <tt>m_req-&gt;remaining</tt> would return 0 for POSTs with a request body, though. Given that the request body was not yet read by us in <tt>getRequestBody()</tt>, I would expect this field to contain the POST request size rather than 0.</p>

<p style='margin-top:0;margin-bottom:10px;'>Either way, the <tt>getRequestBody()</tt> call is first made as part of the CGIParser stuff to fetch the POST parameters, which enables it to get the correct values, but unfortunately the POST data size check has already been passed at that point.</p>

<p style='margin-top:0;margin-bottom:10px;'>As a quick check to verify all of the above, I recompiled with the following modification to <tt>AbstractHandler::getPostData</tt>:</p>
<div class="code panel" style="border-width: 1px;"><div class="codeHeader panelHeader" style="border-bottom-width: 1px;"><b>AbstractHandler.cpp</b></div><div class="codeContent panelContent">
<pre class="code-java">
        <span class="code-comment">// ...
</span>        <span class="code-keyword">if</span> (!plimit.first)
            plimit.second = 1024 * 1024;
        request.getRequestBody();
        <span class="code-keyword">if</span> (plimit.second == 0 || request.getContentLength() &lt;= plimit.second) {
            CGIParser cgi(request);
            <span class="code-comment">// ...</span>
</pre>
</div></div>

<p style='margin-top:0;margin-bottom:10px;'>Indeed, this modification ensures that the m_gotBody field is initialized, and enables the POST size check to work. (Note that I'm not advocating the above modification as a solution, it's merely a technical test to see if initializing the field would allow the check to work).</p>

<p style='margin-top:0;margin-bottom:10px;'>Finally, the <tt>postLimit</tt> setting does not seem to be documented. I was been looking for this functionality in the docs before I found it in the code, so I imagine other people might be too.</p>
    </td>
</tr>
                                                <tr valign="top">
    <td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 10px 10px 0;white-space:nowrap;">
        <strong style="font-weight:normal;color:#505050;">Environment:</strong>
    </td>
    <td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 10px 0;width:100%;">
        <p style='margin-top:0;margin-bottom:10px;'>Red Hat Enterprise Linux Server release 5.8 (Tikanga)<br/>
Apache 2.2.23</p>
    </td>
</tr>
                                                <tr valign="top">
    <td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 10px 10px 0;white-space:nowrap;">
        <strong style="font-weight:normal;color:#505050;">Project:</strong>
    </td>
    <td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 10px 0;width:100%;">
        <a style="color:#326ca6;" href="https://issues.shibboleth.net/jira/browse/SSPCPP">Shibboleth SP - C++</a>
    </td>
</tr>                        <tr valign="top">
    <td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 10px 10px 0;white-space:nowrap;">
        <strong style="font-weight:normal;color:#505050;">Labels:</strong>
    </td>
    <td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 10px 0;width:100%;">
                    POST
                    postLimit
            </td>
</tr>
                        <tr valign="top">
    <td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 10px 10px 0;white-space:nowrap;">
        <strong style="font-weight:normal;color:#505050;">Priority:</strong>
    </td>
    <td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 10px 0;width:100%;">
                        <img src="https://issues.shibboleth.net/jira/images/icons/priorities/major.png" height="16" width="16" border="0" align="absmiddle" alt="Major">                Major
    </td>
</tr>
                        <tr valign="top">
    <td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 10px 10px 0;white-space:nowrap;">
        <strong style="font-weight:normal;color:#505050;">Reporter:</strong>
    </td>
    <td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 10px 0;width:100%;">
                                        <a class="user-hover" rel="vtsji@idp.protectnetwork.org" id="email_vtsji@idp.protectnetwork.org" href="https://issues.shibboleth.net/jira/secure/ViewProfile.jspa?name=vtsji%40idp.protectnetwork.org" style="color:#326ca6;">vtsji@idp.protectnetwork.org</a>
                </td>
</tr>                                                    
    
    
                        </table>
                </td>
            </tr>
        </table>
    </td>
</tr>













            </table>
        </td><!-- End #email-page -->
    </tr>
    <tr valign="top">
        <td style="color:#505050;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:10px;line-height:14px;padding: 0 16px 16px 16px;text-align:center;">
            This message is automatically generated by JIRA.<br />
            If you think it was sent incorrectly, please contact your JIRA administrators<br />
            For more information on JIRA, see: <a style='color:#326ca6;' href='http://www.atlassian.com/software/jira'>http://www.atlassian.com/software/jira</a>
        </td>
    </tr>
</table><!-- End #email-wrap -->
</div><!-- End #email-body -->