The header size and the idle time as settings #70

Open
opened 2026-10-06 03:53:13 +02:00 by clawbot · 1 comment
Collaborator

SWWAF_CLIENT_REQUEST_HEADER_MAX_BYTES and SWWAF_CLIENT_IDLE_TIMEOUT become settings, as "Configuration surface" in SPEC.md describes them. Milestones 1 and 2 fix them at their defaults (internal/proxy/proxy.go), and the build order in SPEC.md makes them settings in the first stage after milestone 2 (decided in #36).

What it builds

  • SWWAF_CLIENT_REQUEST_HEADER_MAX_BYTES (default 32K), in the same size form as the other size settings: the largest request line and headers a client may send. Go's server reads 4 KiB past its MaxHeaderBytes before it refuses, which the code already allows for; the setting keeps that, so the limit a client meets is the one set.
  • SWWAF_CLIENT_IDLE_TIMEOUT (default 120s), in the same duration form as the other timeouts: how long a kept-open connection may wait for its next request.
  • A value that is set but invalid stops the start with a message naming the setting, including a header size too small for the 4 KiB allowance.
  • README.md lists both settings and loses the text saying they are fixed; the "Build order" bullet in SPEC.md for milestone 2 stays as it is, since it describes milestone 2.

Definition of done

  • Tests show each setting's default, a set value taking effect (a request just over the set header size is refused with 431, one just under it reaches the app; an idle connection is closed after the set time), and the start refused for invalid values.
  • make check green; one PR to next, passed by a reviewer who did not write it.

Model: opus-5-5

`SWWAF_CLIENT_REQUEST_HEADER_MAX_BYTES` and `SWWAF_CLIENT_IDLE_TIMEOUT` become settings, as "Configuration surface" in `SPEC.md` describes them. Milestones 1 and 2 fix them at their defaults (`internal/proxy/proxy.go`), and the build order in `SPEC.md` makes them settings in the first stage after milestone 2 (decided in https://git.eeqj.de/sneak/smallwebwaf/issues/36). ## What it builds - `SWWAF_CLIENT_REQUEST_HEADER_MAX_BYTES` (default `32K`), in the same size form as the other size settings: the largest request line and headers a client may send. Go's server reads 4 KiB past its `MaxHeaderBytes` before it refuses, which the code already allows for; the setting keeps that, so the limit a client meets is the one set. - `SWWAF_CLIENT_IDLE_TIMEOUT` (default `120s`), in the same duration form as the other timeouts: how long a kept-open connection may wait for its next request. - A value that is set but invalid stops the start with a message naming the setting, including a header size too small for the 4 KiB allowance. - `README.md` lists both settings and loses the text saying they are fixed; the "Build order" bullet in `SPEC.md` for milestone 2 stays as it is, since it describes milestone 2. ## Definition of done - Tests show each setting's default, a set value taking effect (a request just over the set header size is refused with `431`, one just under it reaches the app; an idle connection is closed after the set time), and the start refused for invalid values. - `make check` green; one PR to `next`, passed by a reviewer who did not write it. Model: opus-5-5
clawbot self-assigned this 2026-10-06 03:53:13 +02:00
Author
Collaborator

Built in #71; the header size cannot be off (see the PR).

Model: opus-5-5

Built in https://git.eeqj.de/sneak/smallwebwaf/pulls/71; the header size cannot be `off` (see the PR). Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/smallwebwaf#70