The request log (Logging in backend/internal/middleware/middleware.go) wrote the URL, User-Agent, Referer and other strings from the request with no length limit. The server accepts headers up to 1 MiB, so one request could put about 1 MiB per field into a log line (#60).
Every string the request log takes from the request is now cut to 128 bytes, the bound the report handler already used: method, URL, protocol, User-Agent, Referer, request ID and client address.
What the diff does not make obvious:
The request ID comes from the client: chi's RequestID middleware copies the X-Request-Id header when one is sent. It is now read with chi's GetReqID, which returns a string.
The client address can come from X-Forwarded-For or X-Real-IP when the peer is a trusted proxy, and an IPv6 address there may carry a zone of any length. Only the logged copy is cut; rate limiting still uses the full address.
The method is bounded because net/http accepts any token there. The protocol is already limited to HTTP/x.y by net/http; it is bounded anyway so the rule has no exceptions.
The bound and its helper moved unchanged from handlers to logger (logger.MaxLoggedFieldBytes, logger.BoundedForLog) so both packages use one copy. The report tests read the bound from there, and the test-only copy in handlers/export_test.go is gone.
The cut is by bytes, as before, so a character split at the cut shows as a replacement character in the JSON log.
Model: opus-5-5
The request log (`Logging` in `backend/internal/middleware/middleware.go`) wrote the URL, `User-Agent`, `Referer` and other strings from the request with no length limit. The server accepts headers up to 1 MiB, so one request could put about 1 MiB per field into a log line (https://git.eeqj.de/sneak/netwatch/issues/60).
Every string the request log takes from the request is now cut to 128 bytes, the bound the report handler already used: method, URL, protocol, `User-Agent`, `Referer`, request ID and client address.
What the diff does not make obvious:
- The request ID comes from the client: chi's `RequestID` middleware copies the `X-Request-Id` header when one is sent. It is now read with chi's `GetReqID`, which returns a string.
- The client address can come from `X-Forwarded-For` or `X-Real-IP` when the peer is a trusted proxy, and an IPv6 address there may carry a zone of any length. Only the logged copy is cut; rate limiting still uses the full address.
- The method is bounded because `net/http` accepts any token there. The protocol is already limited to `HTTP/x.y` by `net/http`; it is bounded anyway so the rule has no exceptions.
- The bound and its helper moved unchanged from `handlers` to `logger` (`logger.MaxLoggedFieldBytes`, `logger.BoundedForLog`) so both packages use one copy. The report tests read the bound from there, and the test-only copy in `handlers/export_test.go` is gone.
- The cut is by bytes, as before, so a character split at the cut shows as a replacement character in the JSON log.
Model: opus-5-5
PASS: The request log now cuts every string it takes from the request to the report handler's bound through the one shared helper, and the new test fails when that cut is removed.
Model: opus-5-5
PASS: The request log now cuts every string it takes from the request to the report handler's bound through the one shared helper, and the new test fails when that cut is removed.
Model: opus-5-5
The request log wrote the URL, User-Agent, Referer and other
request-supplied strings with no length limit, and the server accepts
headers up to 1 MiB, so one request could put about 1 MiB per field
into a log line. Every string the request log takes from the request,
including the request ID chi copies from X-Request-Id, is now cut to
the 128-byte bound the report handler already used. That bound and
its helper moved from the handlers package to the logger package so
both use the one copy.
Model: opus-5-5
PASS: After the rebase onto next the change is the one that passed review, and TODO.md keeps every entry on next plus this change's entry.
Model: opus-5-5
PASS: After the rebase onto `next` the change is the one that passed review, and `TODO.md` keeps every entry on `next` plus this change's entry.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The request log (
Logginginbackend/internal/middleware/middleware.go) wrote the URL,User-Agent,Refererand other strings from the request with no length limit. The server accepts headers up to 1 MiB, so one request could put about 1 MiB per field into a log line (#60).Every string the request log takes from the request is now cut to 128 bytes, the bound the report handler already used: method, URL, protocol,
User-Agent,Referer, request ID and client address.What the diff does not make obvious:
RequestIDmiddleware copies theX-Request-Idheader when one is sent. It is now read with chi'sGetReqID, which returns a string.X-Forwarded-FororX-Real-IPwhen the peer is a trusted proxy, and an IPv6 address there may carry a zone of any length. Only the logged copy is cut; rate limiting still uses the full address.net/httpaccepts any token there. The protocol is already limited toHTTP/x.ybynet/http; it is bounded anyway so the rule has no exceptions.handlerstologger(logger.MaxLoggedFieldBytes,logger.BoundedForLog) so both packages use one copy. The report tests read the bound from there, and the test-only copy inhandlers/export_test.gois gone.Model: opus-5-5
PASS: The request log now cuts every string it takes from the request to the report handler's bound through the one shared helper, and the new test fails when that cut is removed.
Model: opus-5-5
f6d2d98824toa4f8069047PASS: After the rebase onto
nextthe change is the one that passed review, andTODO.mdkeeps every entry onnextplus this change's entry.Model: opus-5-5
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.