check / check (push) Failing after 1s
A buffer failure on POST /api/v1/reports now returns 500 instead of a
false {"status":"ok"}, so clients can retry. Decode errors are split:
an over-limit body returns 413 (via errors.As on *http.MaxBytesError),
malformed JSON stays 400. A new MaxBodyBytes middleware caps every
route (1 MiB default; rejects an oversized Content-Length up-front and
caps the read otherwise), replacing the per-route reader so the health
check and future routes are bounded too. The raw attacker-controlled
geo blob is no longer logged — only its byte length — and client_id and
timestamp are length-bounded before logging. A decodeJSON handler helper
is added per the HTTP server conventions. Panic recovery is now a local
middleware that routes the stack through slog as structured JSON rather
than chi's plain-text stderr. Error bodies still leak nothing internal.
Chosen failure code for a storage failure: 500, since a full buffer or
write error is server-side and retryable, not the client's fault.
Model: opus-4-8
29 lines
613 B
Go
29 lines
613 B
Go
package middleware
|
|
|
|
import (
|
|
"log/slog"
|
|
"net/http"
|
|
"net/netip"
|
|
)
|
|
|
|
// Test-only wrappers exposing unexported helpers to the
|
|
// external middleware_test package.
|
|
|
|
// NewWithLogger builds a Middleware around a logger for tests
|
|
// that exercise the logging paths without the fx graph.
|
|
func NewWithLogger(log *slog.Logger) *Middleware {
|
|
return &Middleware{log: log}
|
|
}
|
|
|
|
func ClientIP(
|
|
remoteAddr string,
|
|
header http.Header,
|
|
trusted []netip.Prefix,
|
|
) string {
|
|
return clientIP(remoteAddr, header, trusted)
|
|
}
|
|
|
|
func ParseTrustedProxies(cidrs []string) ([]netip.Prefix, error) {
|
|
return parseTrustedProxies(cidrs)
|
|
}
|