check / check (push) Successful in 58s
POST /api/v1/reports stays unauthenticated but is bounded. Each client address, as the trusted-proxy logic resolves it, may send REPORTS_PER_MINUTE reports a minute (default 60, all at once if it likes), using golang.org/x/time/rate; past that it gets 429 with Retry-After. Buckets that have refilled are dropped once a minute, so idle addresses do not pile up. reportbuf refuses a report that would take the report files past DATA_DIR_MAX_BYTES (default 1 GiB) with ErrFull, answered with 507; the count starts from the files already in DATA_DIR, and reports not yet written count at their uncompressed size. CORS adds nothing unless CORS_ALLOWED_ORIGINS lists origins. A limit that is not a positive number stops the server from starting. Model: opus-5-5
36 lines
893 B
Go
36 lines
893 B
Go
package middleware
|
|
|
|
import (
|
|
"log/slog"
|
|
"net/http"
|
|
"net/netip"
|
|
)
|
|
|
|
// Test-only wrappers exposing unexported helpers to the
|
|
// external middleware_test package.
|
|
|
|
// NewWithLogger builds a Middleware around a logger for tests
|
|
// that exercise the logging paths without the fx graph.
|
|
func NewWithLogger(log *slog.Logger) *Middleware {
|
|
return &Middleware{log: log}
|
|
}
|
|
|
|
// NewWithTrustedProxies builds a Middleware that honours forwarded
|
|
// headers from the given networks, for tests of the client address
|
|
// paths without the fx graph.
|
|
func NewWithTrustedProxies(trusted []netip.Prefix) *Middleware {
|
|
return &Middleware{trustedProxies: trusted}
|
|
}
|
|
|
|
func ClientIP(
|
|
remoteAddr string,
|
|
header http.Header,
|
|
trusted []netip.Prefix,
|
|
) string {
|
|
return clientIP(remoteAddr, header, trusted)
|
|
}
|
|
|
|
func ParseTrustedProxies(cidrs []string) ([]netip.Prefix, error) {
|
|
return parseTrustedProxies(cidrs)
|
|
}
|