check / check (push) Successful in 58s
POST /api/v1/reports stays unauthenticated but is bounded. Each client address, as the trusted-proxy logic resolves it, may send REPORTS_PER_MINUTE reports a minute (default 60, all at once if it likes), using golang.org/x/time/rate; past that it gets 429 with Retry-After. Buckets that have refilled are dropped once a minute, so idle addresses do not pile up. reportbuf refuses a report that would take the report files past DATA_DIR_MAX_BYTES (default 1 GiB) with ErrFull, answered with 507; the count starts from the files already in DATA_DIR, and reports not yet written count at their uncompressed size. CORS adds nothing unless CORS_ALLOWED_ORIGINS lists origins. A limit that is not a positive number stops the server from starting. Model: opus-5-5
42 lines
1.0 KiB
Go
42 lines
1.0 KiB
Go
package server
|
|
|
|
import (
|
|
"time"
|
|
|
|
"github.com/go-chi/chi/v5"
|
|
"github.com/go-chi/chi/v5/middleware"
|
|
)
|
|
|
|
const (
|
|
requestTimeout = 60 * time.Second
|
|
|
|
// maxRequestBodyBytes caps every request body. A route group
|
|
// can mount s.mw.MaxBodyBytes with a smaller value to lower
|
|
// its bound, but cannot raise it: this cap runs first.
|
|
maxRequestBodyBytes int64 = 1 << 20 // 1 MiB
|
|
)
|
|
|
|
// SetupRoutes configures the chi router with middleware and
|
|
// all application routes.
|
|
func (s *Server) SetupRoutes() {
|
|
s.router = chi.NewRouter()
|
|
|
|
s.router.Use(s.mw.Recoverer())
|
|
s.router.Use(middleware.RequestID)
|
|
s.router.Use(s.mw.Logging())
|
|
s.router.Use(s.mw.SecurityHeaders())
|
|
s.router.Use(s.mw.CORS(s.params.Config.CORSAllowedOrigins))
|
|
s.router.Use(s.mw.MaxBodyBytes(maxRequestBodyBytes))
|
|
s.router.Use(middleware.Timeout(requestTimeout))
|
|
|
|
s.router.Get(
|
|
"/.well-known/healthcheck",
|
|
s.h.HandleHealthCheck(),
|
|
)
|
|
|
|
s.router.Route("/api/v1", func(r chi.Router) {
|
|
r.With(s.mw.RateLimit(s.params.Config.ReportsPerMinute)).
|
|
Post("/reports", s.h.HandleReport())
|
|
})
|
|
}
|