Document that the multipart part-count cap only applies to the buffered form path

CPPHTTPLIB_MULTIPART_FORM_DATA_FILE_MAX_COUNT is enforced only in
Server::read_content(), where parts are accumulated into req.form. The
streaming ContentReader path keeps nothing and was never in scope, but
this was undocumented (GHSA-923p-8q8g-xcqj). Note the split in the README
and show how to bound the part count from inside a ContentReader handler.
This commit is contained in:
yhirose
2026-08-28 08:26:08 -04:00
parent 139f30e0f1
commit c7db3da982
3 changed files with 70 additions and 0 deletions

View File

@@ -730,6 +730,12 @@ svr.Post("/content_receiver",
});
```
`CPPHTTPLIB_MULTIPART_FORM_DATA_FILE_MAX_COUNT` (default 1024) caps the number of
form-data parts only on the buffered path, where every part is accumulated into
`req.form`. The content receiver keeps nothing, so the cap does not apply here.
If your handler needs an upper bound on the number of parts, count them yourself
and return `false` from the callback to stop the parser.
### Send content with the content provider
```cpp