Check the origin's host and port; cap the size at 1 GiB (closes #61)
check / check (push) Successful in 2m33s

access_control_allow_origin now needs a host name (ASCII letters,
digits, hyphens, dots) or an IP address, and a port, when given, from 1
to 65535, read with net/url, net/netip and strconv. Two hosts, an empty
port, no host, a bad port or a non-ASCII host name abort startup, as a
* inside the value already did.

upstream_max_response_size above 1 GiB aborts startup: the image
processor reads one byte past the limit, which wrapped negative at the
largest 64-bit value, and a response is held whole in memory.
config.example.yml states the maximum.

Model: opus-5-5
This commit is contained in:
2026-09-28 20:03:35 +00:00
parent 8474ed3255
commit 0b756c4974
3 changed files with 74 additions and 18 deletions
+5 -3
View File
@@ -36,9 +36,11 @@ exhaustion
`upstream_fetch_timeout` (default `30s`), `upstream_max_response_size`
(default 50 MiB) and `downstream_timeout` (default `60s`, both the
server's write timeout and the per-request timeout); each has a
`PIXA_` variable; durations are positive Go duration strings, sizes a
whole number of bytes; an invalid value aborts startup naming the key
and the value; documented in `config.example.yml` and `README.md`.
`PIXA_` variable; durations are positive Go duration strings, the size a
whole number of bytes up to 1 GiB, the origin `*` or one scheme, host
name or IP address and optional port; an invalid value aborts startup
naming the key and the value; documented in `config.example.yml` and
`README.md`.
- 2026-09-28 refuse an unparseable `exp` on `/v1/image/` and log swallowed
cache errors (closes #72): an `exp` in the URL that is not a whole
number, an empty `exp=` included, is a 400 naming `exp` and the value,