users@jersey.java.net

Re: [Jersey] Denial Of Service attacks with gigabytes of form data?

From: Paul Sandoz <Paul.Sandoz_at_Sun.COM>
Date: Wed, 23 Jul 2008 10:37:28 +0200

Harald Kirsch wrote:
> Ok, that would do it at least for my application, since I am using
> InputStream. But what I get is actually a ByteArrayInputStream and so I
> am afraid the input was first completely read into memory.
>

Jersey does not attempt to buffer bytes when using an InputStream. It
passes the InputStream directly from the container (servlet or
otherwise). So i am not sure what is going on... can you share some code?

Paul.

-- 
| ? + ? = To question
----------------\
    Paul Sandoz
         x38109
+33-4-76188109