check / check (push) Failing after 0s
Add ReadHeaderTimeout and IdleTimeout to the http.Server (named constants beside the existing timeouts) to close the slowloris and idle-keep-alive gaps. Add a SecurityHeaders middleware setting HSTS, a JSON-API CSP (default-src 'none'; frame-ancestors 'none'), X-Frame-Options: DENY, X-Content-Type-Options: nosniff, Referrer-Policy, and Permissions-Policy. It is registered before CORS so the headers ride on preflight responses. Resolve the client IP from X-Forwarded-For / X-Real-IP only when the direct peer is in a trusted-proxy allowlist, defaulting to loopback plus RFC1918 and configurable via TRUSTED_PROXIES; an untrusted peer's forwarded headers are ignored and the direct peer is logged. Uses net/netip; no new dependency. Model: opus-4-8
33 lines
684 B
Go
33 lines
684 B
Go
package server
|
|
|
|
import (
|
|
"time"
|
|
|
|
"github.com/go-chi/chi/v5"
|
|
"github.com/go-chi/chi/v5/middleware"
|
|
)
|
|
|
|
const requestTimeout = 60 * time.Second
|
|
|
|
// SetupRoutes configures the chi router with middleware and
|
|
// all application routes.
|
|
func (s *Server) SetupRoutes() {
|
|
s.router = chi.NewRouter()
|
|
|
|
s.router.Use(middleware.Recoverer)
|
|
s.router.Use(middleware.RequestID)
|
|
s.router.Use(s.mw.Logging())
|
|
s.router.Use(s.mw.SecurityHeaders())
|
|
s.router.Use(s.mw.CORS())
|
|
s.router.Use(middleware.Timeout(requestTimeout))
|
|
|
|
s.router.Get(
|
|
"/.well-known/healthcheck",
|
|
s.h.HandleHealthCheck(),
|
|
)
|
|
|
|
s.router.Route("/api/v1", func(r chi.Router) {
|
|
r.Post("/reports", s.h.HandleReport())
|
|
})
|
|
}
|