Header limit of 32 KiB, upstream URL checks, build and run scripts
check / check (push) Successful in 1m46s
check / check (push) Successful in 1m46s
The request line and headers are now refused above 32 KiB exactly: Go's server reads 4 KiB past MaxHeaderBytes, so that is set to 28 KiB, and the tests try exactly 32 KiB and one byte more. SWWAF_UPSTREAM_URL now needs a host, and a given port must be from 1 to 65535. make build and make run call script/build and script/run. Model: opus-5-5
This commit is contained in:
@@ -70,7 +70,7 @@ it, and the effective settings are logged at start.
|
||||
|
||||
- `SWWAF_LISTEN_ADDR` (default `:8080`): where `smallwebwaf` listens.
|
||||
- `SWWAF_UPSTREAM_URL` (default `http://127.0.0.1:8081`): the app, as `http` or
|
||||
`https`, a host and a port, and nothing more.
|
||||
`https`, a host and an optional port, and nothing more.
|
||||
- `SWWAF_TRUSTED_PROXIES` (default `10.0.0.0/8,172.16.0.0/12,192.168.0.0/16`,
|
||||
the private address ranges): the netblocks whose `X-Forwarded-For` is
|
||||
believed. A list given replaces the default; set but empty, it trusts nothing.
|
||||
@@ -125,10 +125,10 @@ settings, stop, errors) share the stream as JSON lines marked
|
||||
|
||||
Go's HTTP server, on which `smallwebwaf` is built, reads a request's line and
|
||||
headers before `smallwebwaf` sees the request, and some requests end there,
|
||||
without a line in the log: headers over 32 KiB, which it answers `431` (reading
|
||||
up to 4 KiB past the limit first), headers slower than
|
||||
`SWWAF_CLIENT_REQUEST_TIMEOUT`, whose connection it closes without an answer,
|
||||
and requests it cannot read at all, which it answers itself, mostly with `400`.
|
||||
without a line in the log: headers over 32 KiB, which it answers `431`, headers
|
||||
slower than `SWWAF_CLIENT_REQUEST_TIMEOUT`, whose connection it closes without
|
||||
an answer, and requests it cannot read at all, which it answers itself, mostly
|
||||
with `400`.
|
||||
|
||||
## Why
|
||||
|
||||
@@ -406,8 +406,10 @@ so that they run in minimal containers.
|
||||
image build.
|
||||
- `script/precommit`: run by the git pre-commit hook; runs `script/check`.
|
||||
- `script/install-precommit`: installs that hook; `make hooks` runs it.
|
||||
|
||||
`make build` builds `bin/smallwebwaf`, and `make run` builds and runs it.
|
||||
- `script/build`: builds `bin/smallwebwaf` on the host, with Go installed, for
|
||||
working on the code by hand; `make build` runs it.
|
||||
- `script/run`: builds `bin/smallwebwaf` with `script/build` and runs it;
|
||||
`make run` runs it.
|
||||
|
||||
## TODO
|
||||
|
||||
|
||||
Reference in New Issue
Block a user