Pass-through proxy with timeouts, size limits and a request log (closes #13)
check / check (push) Successful in 2m13s

The repo's first code, with the layout the prompts policies ask for:
Makefile, script/ entrypoints, a Dockerfile whose lint and test phases
gate the build, the Gitea workflow, the canonical dotfiles and
REPO_POLICIES.md. smallwebwaf passes each request to the app through
httputil.ReverseProxy within the four timeouts and two size limits,
works out the client's address behind trusted proxies, and writes one
JSON line per request. The tests run against real local servers.
SPEC.md now says what Go's HTTP server does before smallwebwaf sees a
request; make fmt only rewraps EVALUATION.md.

Model: opus-5-5
This commit is contained in:
2026-10-03 13:40:47 +00:00
parent fd77e76177
commit c94bcd737e
45 changed files with 4867 additions and 74 deletions
+43
View File
@@ -0,0 +1,43 @@
.PHONY: bootstrap setup test lint fmt fmt-check check docker hooks build run
# Makefile targets are thin shims; the implementations live in script/
# per the scripts-to-rule-them-all pattern (see the Entrypoints section
# of README.md). build and run are for working on the code by hand.
# The version the binary reports. It comes from git, so it is computed
# here on the host; the Dockerfile is passed it as a build argument.
VERSION ?= $(shell git describe --tags --always --dirty 2>/dev/null || echo unknown)
bootstrap:
@script/bootstrap
setup:
@script/setup
test:
@script/test
lint:
@script/lint
fmt:
@script/fmt
fmt-check:
@script/fmt-check
check:
@script/check
docker:
@script/docker
hooks:
@script/install-precommit
build:
go build -trimpath -ldflags "-X main.Version=$(VERSION)" \
-o bin/smallwebwaf ./cmd/smallwebwaf
run: build
./bin/smallwebwaf