Check the origin's host and port; cap the size at 1 GiB (closes #61)
access_control_allow_origin now needs a host name (ASCII letters, digits, hyphens, dots) or an IP address, and a port, when given, from 1 to 65535, read with net/url, net/netip and strconv. Two hosts, an empty port, no host, a bad port or a non-ASCII host name abort startup, as a * inside the value already did. upstream_max_response_size above 1 GiB aborts startup: the image processor reads one byte past the limit, which wrapped negative at the largest 64-bit value, and a response is held whole in memory. config.example.yml states the maximum. Model: opus-5-5
This commit is contained in:
+2
-1
@@ -74,7 +74,8 @@ upstream_connections_per_host: 20
|
||||
# Time allowed for one fetch from an upstream host (default: 30s)
|
||||
upstream_fetch_timeout: 30s
|
||||
|
||||
# Largest upstream response accepted, in bytes (default: 52428800, 50 MiB)
|
||||
# Largest upstream response accepted, in bytes, at most 1073741824
|
||||
# (1 GiB) (default: 52428800, 50 MiB)
|
||||
upstream_max_response_size: 52428800
|
||||
|
||||
# Time allowed for answering one client request, the upstream fetch
|
||||
|
||||
Reference in New Issue
Block a user