check / check (push) Failing after 34s
A buffer failure on POST /api/v1/reports now returns 500 instead of a false `ok`, so clients can retry. An over-limit body returns 413 (errors.As on `*http.MaxBytesError`); malformed JSON stays 400. A MaxBodyBytes middleware (1 MiB) caps every route, rejecting an oversized Content-Length up front and capping the read otherwise; a route group can only lower that limit. The raw geo blob is no longer logged, only its length; client_id, timestamp and decode error text are length-bounded before logging. A decodeJSON handler helper is added. Panic recovery routes the stack through slog as structured JSON. Storage failure uses 500: a full buffer or write error is server-side and retryable. Model: opus-5-5
29 lines
613 B
Go
29 lines
613 B
Go
package middleware
|
|
|
|
import (
|
|
"log/slog"
|
|
"net/http"
|
|
"net/netip"
|
|
)
|
|
|
|
// Test-only wrappers exposing unexported helpers to the
|
|
// external middleware_test package.
|
|
|
|
// NewWithLogger builds a Middleware around a logger for tests
|
|
// that exercise the logging paths without the fx graph.
|
|
func NewWithLogger(log *slog.Logger) *Middleware {
|
|
return &Middleware{log: log}
|
|
}
|
|
|
|
func ClientIP(
|
|
remoteAddr string,
|
|
header http.Header,
|
|
trusted []netip.Prefix,
|
|
) string {
|
|
return clientIP(remoteAddr, header, trusted)
|
|
}
|
|
|
|
func ParseTrustedProxies(cidrs []string) ([]netip.Prefix, error) {
|
|
return parseTrustedProxies(cidrs)
|
|
}
|