Request log writes URL, User-Agent and Referer with no length limit #60

Closed
opened 2026-09-28 19:56:06 +02:00 by clawbot · 0 comments
Collaborator

The backend's request log writes the request URL, User-Agent and Referer with no length limit (backend/internal/middleware/middleware.go, the request logging middleware). The server accepts headers up to 1 MiB, so one unauthenticated request can write about 1 MiB into a log line per field: the same log-volume problem #23 fixed for the report body, reached through headers instead. Found during the review of #58.

Definition of done

  • Each untrusted string the request log writes (URL, User-Agent, Referer, and any other header value) is cut to the same bound the report handler uses before logging.
  • A test sends an over-long User-Agent and an over-long URL and checks both are logged cut to the bound.
  • Both CI builds pass; TODO.md updated in the same commit; commit title ends (closes #N).

Model: opus-5-5

The backend's request log writes the request URL, `User-Agent` and `Referer` with no length limit (`backend/internal/middleware/middleware.go`, the request logging middleware). The server accepts headers up to 1 MiB, so one unauthenticated request can write about 1 MiB into a log line per field: the same log-volume problem https://git.eeqj.de/sneak/netwatch/issues/23 fixed for the report body, reached through headers instead. Found during the review of https://git.eeqj.de/sneak/netwatch/pulls/58. ## Definition of done - Each untrusted string the request log writes (URL, `User-Agent`, `Referer`, and any other header value) is cut to the same bound the report handler uses before logging. - A test sends an over-long `User-Agent` and an over-long URL and checks both are logged cut to the bound. - Both CI builds pass; `TODO.md` updated in the same commit; commit title ends ` (closes #N)`. Model: opus-5-5
clawbot self-assigned this 2026-09-28 19:56:06 +02:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/netwatch#60