fix(backend): cut request log fields to the log bound (closes #60) #69

Open
clawbot wants to merge 1 commits from fix/bound-request-log into next
Collaborator

The request log (Logging in backend/internal/middleware/middleware.go) wrote the URL, User-Agent, Referer and other strings from the request with no length limit. The server accepts headers up to 1 MiB, so one request could put about 1 MiB per field into a log line (#60).

Every string the request log takes from the request is now cut to 128 bytes, the bound the report handler already used: method, URL, protocol, User-Agent, Referer, request ID and client address.

What the diff does not make obvious:

  • The request ID comes from the client: chi's RequestID middleware copies the X-Request-Id header when one is sent. It is now read with chi's GetReqID, which returns a string.
  • The client address can come from X-Forwarded-For or X-Real-IP when the peer is a trusted proxy, and an IPv6 address there may carry a zone of any length. Only the logged copy is cut; rate limiting still uses the full address.
  • The method is bounded because net/http accepts any token there. The protocol is already limited to HTTP/x.y by net/http; it is bounded anyway so the rule has no exceptions.
  • The bound and its helper moved unchanged from handlers to logger (logger.MaxLoggedFieldBytes, logger.BoundedForLog) so both packages use one copy. The report tests read the bound from there, and the test-only copy in handlers/export_test.go is gone.
  • The cut is by bytes, as before, so a character split at the cut shows as a replacement character in the JSON log.

Model: opus-5-5

The request log (`Logging` in `backend/internal/middleware/middleware.go`) wrote the URL, `User-Agent`, `Referer` and other strings from the request with no length limit. The server accepts headers up to 1 MiB, so one request could put about 1 MiB per field into a log line (https://git.eeqj.de/sneak/netwatch/issues/60). Every string the request log takes from the request is now cut to 128 bytes, the bound the report handler already used: method, URL, protocol, `User-Agent`, `Referer`, request ID and client address. What the diff does not make obvious: - The request ID comes from the client: chi's `RequestID` middleware copies the `X-Request-Id` header when one is sent. It is now read with chi's `GetReqID`, which returns a string. - The client address can come from `X-Forwarded-For` or `X-Real-IP` when the peer is a trusted proxy, and an IPv6 address there may carry a zone of any length. Only the logged copy is cut; rate limiting still uses the full address. - The method is bounded because `net/http` accepts any token there. The protocol is already limited to `HTTP/x.y` by `net/http`; it is bounded anyway so the rule has no exceptions. - The bound and its helper moved unchanged from `handlers` to `logger` (`logger.MaxLoggedFieldBytes`, `logger.BoundedForLog`) so both packages use one copy. The report tests read the bound from there, and the test-only copy in `handlers/export_test.go` is gone. - The cut is by bytes, as before, so a character split at the cut shows as a replacement character in the JSON log. Model: opus-5-5
clawbot added the needs-review label 2026-09-29 08:30:37 +02:00
clawbot self-assigned this 2026-09-29 08:30:37 +02:00
Author
Collaborator

PASS: The request log now cuts every string it takes from the request to the report handler's bound through the one shared helper, and the new test fails when that cut is removed.

Model: opus-5-5

PASS: The request log now cuts every string it takes from the request to the report handler's bound through the one shared helper, and the new test fails when that cut is removed. Model: opus-5-5
clawbot added 1 commit 2026-09-29 09:13:04 +02:00
The request log wrote the URL, User-Agent, Referer and other
request-supplied strings with no length limit, and the server accepts
headers up to 1 MiB, so one request could put about 1 MiB per field
into a log line. Every string the request log takes from the request,
including the request ID chi copies from X-Request-Id, is now cut to
the 128-byte bound the report handler already used. That bound and
its helper moved from the handlers package to the logger package so
both use the one copy.

Model: opus-5-5
clawbot force-pushed fix/bound-request-log from f6d2d98824 to a4f8069047 2026-09-29 09:13:04 +02:00 Compare
Author
Collaborator

PASS: After the rebase onto next the change is the one that passed review, and TODO.md keeps every entry on next plus this change's entry.

Model: opus-5-5

PASS: After the rebase onto `next` the change is the one that passed review, and `TODO.md` keeps every entry on `next` plus this change's entry. Model: opus-5-5
All checks were successful
check / check (push) Successful in 1m4s
You are not authorized to merge this pull request.
This pull request can be merged automatically.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin fix/bound-request-log:fix/bound-request-log
git checkout fix/bound-request-log
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/netwatch#69