fix(backend): cut request log fields to the log bound (closes #60)
check / check (push) Successful in 14s
check / check (push) Successful in 14s
The request log wrote the URL, User-Agent, Referer and other request-supplied strings with no length limit, and the server accepts headers up to 1 MiB, so one request could put about 1 MiB per field into a log line. Every string the request log takes from the request, including the request ID chi copies from X-Request-Id, is now cut to the 128-byte bound the report handler already used. That bound and its helper moved from the handlers package to the logger package so both use the one copy. Model: opus-5-5
This commit was merged in pull request #69.
This commit is contained in:
@@ -23,6 +23,12 @@ latest run passes.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-09-29: the request log is bounded (issue #60): the method, URL, protocol,
|
||||
`User-Agent`, `Referer`, request ID (which chi takes from the client's
|
||||
`X-Request-Id` header) and client address it writes are each cut to 128 bytes,
|
||||
the bound the report handler already used, so one request can no longer put
|
||||
about 1 MiB per field into a log line. That bound and its helper now live in
|
||||
the `logger` package, shared by both
|
||||
- 2026-09-29: nginx takes the client address from `X-Forwarded-For` only on
|
||||
requests from the reverse proxies named in the container's `TRUSTED_PROXIES`
|
||||
(issue #64), and by default from none, where it trusted every RFC1918 address
|
||||
|
||||
Reference in New Issue
Block a user