Header limit of 32 KiB, upstream URL checks, build and run scripts
check / check (push) Successful in 1m46s

The request line and headers are now refused above 32 KiB exactly: Go's
server reads 4 KiB past MaxHeaderBytes, so that is set to 28 KiB, and
the tests try exactly 32 KiB and one byte more. SWWAF_UPSTREAM_URL now
needs a host, and a given port must be from 1 to 65535. make build and
make run call script/build and script/run.

Model: opus-5-5
This commit is contained in:
2026-10-03 14:45:44 +00:00
parent 545ce67f44
commit d63465d278
9 changed files with 81 additions and 33 deletions
+11 -4
View File
@@ -71,7 +71,7 @@ var (
errNotListenAddr = errors.New(
"is not an address to listen on, such as :8080")
errNotUpstreamURL = errors.New(
"is not a URL with only a scheme, a host and a port, " +
"is not a URL with only a scheme, a host and an optional port, " +
"such as http://127.0.0.1:8081")
)
@@ -325,8 +325,8 @@ func parseListenAddr(value string) (string, error) {
}
// parseUpstreamURL reads the app's URL: http or https, a host and an
// optional port, and nothing else, since the request's own path and
// query go to the app unchanged.
// optional port from 1 to 65535, and nothing else, since the request's
// own path and query go to the app unchanged.
func parseUpstreamURL(value string) (*url.URL, error) {
upstream, err := url.Parse(value)
if err != nil {
@@ -334,12 +334,19 @@ func parseUpstreamURL(value string) (*url.URL, error) {
}
onlySchemeAndHost := (upstream.Scheme == "http" || upstream.Scheme == "https") &&
upstream.Host != "" && upstream.User == nil && upstream.Opaque == "" &&
upstream.Hostname() != "" && upstream.User == nil && upstream.Opaque == "" &&
(upstream.Path == "" || upstream.Path == "/") &&
upstream.RawQuery == "" && upstream.Fragment == ""
if !onlySchemeAndHost {
return nil, fmt.Errorf("%q %w", value, errNotUpstreamURL)
}
if upstream.Port() != "" {
port, err := strconv.ParseUint(upstream.Port(), 10, 16)
if err != nil || port == 0 {
return nil, fmt.Errorf("%q %w", value, errNotUpstreamURL)
}
}
return upstream, nil
}