SWWAF_CLIENT_REQUEST_HEADER_MAX_BYTES and SWWAF_CLIENT_IDLE_TIMEOUT become settings, as "Configuration surface" in SPEC.md describes them. Milestones 1 and 2 fix them at their defaults (internal/proxy/proxy.go), and the build order in SPEC.md makes them settings in the first stage after milestone 2 (decided in #36).
What it builds
SWWAF_CLIENT_REQUEST_HEADER_MAX_BYTES (default 32K), in the same size form as the other size settings: the largest request line and headers a client may send. Go's server reads 4 KiB past its MaxHeaderBytes before it refuses, which the code already allows for; the setting keeps that, so the limit a client meets is the one set.
SWWAF_CLIENT_IDLE_TIMEOUT (default 120s), in the same duration form as the other timeouts: how long a kept-open connection may wait for its next request.
A value that is set but invalid stops the start with a message naming the setting, including a header size too small for the 4 KiB allowance.
README.md lists both settings and loses the text saying they are fixed; the "Build order" bullet in SPEC.md for milestone 2 stays as it is, since it describes milestone 2.
Definition of done
Tests show each setting's default, a set value taking effect (a request just over the set header size is refused with 431, one just under it reaches the app; an idle connection is closed after the set time), and the start refused for invalid values.
make check green; one PR to next, passed by a reviewer who did not write it.
Model: opus-5-5
`SWWAF_CLIENT_REQUEST_HEADER_MAX_BYTES` and `SWWAF_CLIENT_IDLE_TIMEOUT` become settings, as "Configuration surface" in `SPEC.md` describes them. Milestones 1 and 2 fix them at their defaults (`internal/proxy/proxy.go`), and the build order in `SPEC.md` makes them settings in the first stage after milestone 2 (decided in https://git.eeqj.de/sneak/smallwebwaf/issues/36).
## What it builds
- `SWWAF_CLIENT_REQUEST_HEADER_MAX_BYTES` (default `32K`), in the same size form as the other size settings: the largest request line and headers a client may send. Go's server reads 4 KiB past its `MaxHeaderBytes` before it refuses, which the code already allows for; the setting keeps that, so the limit a client meets is the one set.
- `SWWAF_CLIENT_IDLE_TIMEOUT` (default `120s`), in the same duration form as the other timeouts: how long a kept-open connection may wait for its next request.
- A value that is set but invalid stops the start with a message naming the setting, including a header size too small for the 4 KiB allowance.
- `README.md` lists both settings and loses the text saying they are fixed; the "Build order" bullet in `SPEC.md` for milestone 2 stays as it is, since it describes milestone 2.
## Definition of done
- Tests show each setting's default, a set value taking effect (a request just over the set header size is refused with `431`, one just under it reaches the app; an idle connection is closed after the set time), and the start refused for invalid values.
- `make check` green; one PR to `next`, passed by a reviewer who did not write it.
Model: opus-5-5
clawbot
self-assigned this 2026-10-06 03:53:13 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
SWWAF_CLIENT_REQUEST_HEADER_MAX_BYTESandSWWAF_CLIENT_IDLE_TIMEOUTbecome settings, as "Configuration surface" inSPEC.mddescribes them. Milestones 1 and 2 fix them at their defaults (internal/proxy/proxy.go), and the build order inSPEC.mdmakes them settings in the first stage after milestone 2 (decided in #36).What it builds
SWWAF_CLIENT_REQUEST_HEADER_MAX_BYTES(default32K), in the same size form as the other size settings: the largest request line and headers a client may send. Go's server reads 4 KiB past itsMaxHeaderBytesbefore it refuses, which the code already allows for; the setting keeps that, so the limit a client meets is the one set.SWWAF_CLIENT_IDLE_TIMEOUT(default120s), in the same duration form as the other timeouts: how long a kept-open connection may wait for its next request.README.mdlists both settings and loses the text saying they are fixed; the "Build order" bullet inSPEC.mdfor milestone 2 stays as it is, since it describes milestone 2.Definition of done
431, one just under it reaches the app; an idle connection is closed after the set time), and the start refused for invalid values.make checkgreen; one PR tonext, passed by a reviewer who did not write it.Model: opus-5-5
Built in #71; the header size cannot be
off(see the PR).Model: opus-5-5