check / check (push) Failing after 0s
Add ReadHeaderTimeout and IdleTimeout to the http.Server (named constants beside the existing timeouts) to close the slowloris and idle-keep-alive gaps. Add a SecurityHeaders middleware setting HSTS, a JSON-API CSP (default-src 'none'; frame-ancestors 'none'), X-Frame-Options: DENY, X-Content-Type-Options: nosniff, Referrer-Policy, and Permissions-Policy. It is registered before CORS so the headers ride on preflight responses. Resolve the client IP from X-Forwarded-For / X-Real-IP only when the direct peer is in a trusted-proxy allowlist, defaulting to loopback plus RFC1918 and configurable via TRUSTED_PROXIES; an untrusted peer's forwarded headers are ignored and the direct peer is logged. Uses net/netip; no new dependency. Model: opus-4-8
115 lines
2.8 KiB
Go
115 lines
2.8 KiB
Go
// Package config loads application configuration from
|
|
// environment variables, .env files, and config files.
|
|
package config
|
|
|
|
import (
|
|
"errors"
|
|
"log/slog"
|
|
"strings"
|
|
|
|
"sneak.berlin/go/netwatch/internal/globals"
|
|
"sneak.berlin/go/netwatch/internal/logger"
|
|
|
|
_ "github.com/joho/godotenv/autoload" // loads .env file
|
|
"github.com/spf13/viper"
|
|
"go.uber.org/fx"
|
|
)
|
|
|
|
// defaultTrustedProxies lists the networks whose forwarded
|
|
// headers are honoured by default. It covers the RFC1918
|
|
// ranges (to match nginx.conf) plus IPv4 and IPv6 loopback,
|
|
// because the reverse proxy shares the container and reaches
|
|
// the backend over loopback.
|
|
const defaultTrustedProxies = "127.0.0.1/32,::1/128," +
|
|
"10.0.0.0/8,172.16.0.0/12,192.168.0.0/16"
|
|
|
|
// Params defines the dependencies for Config.
|
|
type Params struct {
|
|
fx.In
|
|
|
|
Globals *globals.Globals
|
|
Logger *logger.Logger
|
|
}
|
|
|
|
// Config holds the resolved application configuration.
|
|
type Config struct {
|
|
DataDir string
|
|
Debug bool
|
|
MetricsPassword string
|
|
MetricsUsername string
|
|
Port int
|
|
SentryDSN string
|
|
TrustedProxies []string
|
|
log *slog.Logger
|
|
params *Params
|
|
}
|
|
|
|
// New loads configuration from env, .env files, and config
|
|
// files, returning a fully resolved Config.
|
|
func New(
|
|
_ fx.Lifecycle,
|
|
params Params,
|
|
) (*Config, error) {
|
|
log := params.Logger.Get()
|
|
name := params.Globals.Appname
|
|
|
|
viper.SetConfigName(name)
|
|
viper.SetConfigType("yaml")
|
|
viper.AddConfigPath("/etc/" + name)
|
|
viper.AddConfigPath("$HOME/.config/" + name)
|
|
|
|
viper.AutomaticEnv()
|
|
|
|
viper.SetDefault("DATA_DIR", "./data/reports")
|
|
viper.SetDefault("DEBUG", "false")
|
|
viper.SetDefault("PORT", "8080")
|
|
viper.SetDefault("SENTRY_DSN", "")
|
|
viper.SetDefault("METRICS_USERNAME", "")
|
|
viper.SetDefault("METRICS_PASSWORD", "")
|
|
viper.SetDefault("TRUSTED_PROXIES", defaultTrustedProxies)
|
|
|
|
err := viper.ReadInConfig()
|
|
if err != nil {
|
|
var notFound viper.ConfigFileNotFoundError
|
|
if !errors.As(err, ¬Found) {
|
|
log.Error("config file malformed", "error", err)
|
|
panic(err)
|
|
}
|
|
}
|
|
|
|
s := &Config{
|
|
DataDir: viper.GetString("DATA_DIR"),
|
|
Debug: viper.GetBool("DEBUG"),
|
|
MetricsPassword: viper.GetString("METRICS_PASSWORD"),
|
|
MetricsUsername: viper.GetString("METRICS_USERNAME"),
|
|
Port: viper.GetInt("PORT"),
|
|
SentryDSN: viper.GetString("SENTRY_DSN"),
|
|
TrustedProxies: splitList(viper.GetString("TRUSTED_PROXIES")),
|
|
log: log,
|
|
params: ¶ms,
|
|
}
|
|
|
|
if s.Debug {
|
|
params.Logger.EnableDebugLogging()
|
|
s.log = params.Logger.Get()
|
|
}
|
|
|
|
return s, nil
|
|
}
|
|
|
|
// splitList turns a comma-separated setting into a trimmed
|
|
// slice, dropping empty entries.
|
|
func splitList(raw string) []string {
|
|
parts := strings.Split(raw, ",")
|
|
|
|
out := make([]string, 0, len(parts))
|
|
for _, p := range parts {
|
|
p = strings.TrimSpace(p)
|
|
if p != "" {
|
|
out = append(out, p)
|
|
}
|
|
}
|
|
|
|
return out
|
|
}
|