fix(backend): cut request log fields to the log bound (closes #60)
check / check (push) Successful in 1m4s

The request log wrote the URL, User-Agent, Referer and other
request-supplied strings with no length limit, and the server accepts
headers up to 1 MiB, so one request could put about 1 MiB per field
into a log line. Every string the request log takes from the request,
including the request ID chi copies from X-Request-Id, is now cut to
the 128-byte bound the report handler already used. That bound and
its helper moved from the handlers package to the logger package so
both use the one copy.

Model: opus-5-5
This commit is contained in:
2026-09-29 07:10:10 +00:00
parent 8833603eff
commit a4f8069047
7 changed files with 92 additions and 37 deletions
+12 -11
View File
@@ -189,7 +189,10 @@ func addrInAny(s string, trusted []netip.Prefix) bool {
}
// Logging returns middleware that logs each request with
// timing, status code, and client information.
// timing, status code, and client information. Every string
// taken from the request is cut to logger.MaxLoggedFieldBytes,
// including the request ID, which chi takes from the client's
// X-Request-Id header when one is sent.
func (s *Middleware) Logging() func(http.Handler) http.Handler {
return func(next http.Handler) http.Handler {
return http.HandlerFunc(
@@ -202,21 +205,19 @@ func (s *Middleware) Logging() func(http.Handler) http.Handler {
latency := time.Since(start)
s.log.InfoContext(ctx, "request",
"request_start", start,
"method", r.Method,
"url", r.URL.String(),
"useragent", r.UserAgent(),
"method", logger.BoundedForLog(r.Method),
"url", logger.BoundedForLog(r.URL.String()),
"useragent", logger.BoundedForLog(r.UserAgent()),
"request_id",
ctx.Value(
middleware.RequestIDKey,
),
"referer", r.Referer(),
"proto", r.Proto,
logger.BoundedForLog(middleware.GetReqID(ctx)),
"referer", logger.BoundedForLog(r.Referer()),
"proto", logger.BoundedForLog(r.Proto),
"remote_ip",
clientIP(
logger.BoundedForLog(clientIP(
r.RemoteAddr,
r.Header,
s.trustedProxies,
),
)),
"status", lrw.statusCode,
"latency_ms",
latency.Milliseconds(),