feat: cap form POST body size and return 413 (closes #92)
check / check (push) Failing after 0s
check / check (push) Failing after 0s
Add a LimitBody middleware that caps the request body at MaxFormBytes (1 MiB) on POST / and POST /generate and rejects an oversized body with 413. It parses the form under the cap before the CSRF middleware, which reads its token from the body with PostFormValue and would otherwise see a truncated body as a missing token (403); a successful parse is cached, so the CSRF check and handler reuse it. Wired ahead of CSRF in SetupRoutes. This makes the limit explicit rather than resting on ParseForm's incidental 10 MB cap, which would silently vanish if a handler switched to io.ReadAll or multipart. Model: opus-4-8
This commit is contained in:
@@ -29,6 +29,14 @@ P1: implement blocked networks configuration to extend SSRF protection
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-09-21 http.Server hardening (closes #92): added
|
||||
`HTTPReadHeaderTimeout` (10s, bounds the slowloris header dribble) and
|
||||
`HTTPIdleTimeout` (120s, bounds keep-alive reuse) alongside the
|
||||
existing timeouts and wired them onto the server; added a `LimitBody`
|
||||
middleware capping the two form POST bodies (`POST /`, `POST /generate`)
|
||||
at `MaxFormBytes` (1 MiB) and returning 413, applied ahead of the CSRF
|
||||
middleware so an oversized body is refused as 413 rather than being read
|
||||
as a missing CSRF token (403); left `WriteTimeout` at 60s unchanged
|
||||
- 2026-08-07 update golangci-lint to v2.12.2 with the canonical
|
||||
`.golangci.yml` (v2 schema, `default: all` minus six disabled
|
||||
linters, `lll` 88, tests included): bumped the pinned
|
||||
|
||||
Reference in New Issue
Block a user