Pass-through proxy with timeouts, size limits and a request log #39

Merged
clawbot merged 2 commits from issue-13-pass-through-proxy into next 2026-10-03 17:24:34 +02:00
2 Commits
Author SHA1 Message Date
sneak d63465d278 Header limit of 32 KiB, upstream URL checks, build and run scripts
check / check (push) Successful in 1m46s
The request line and headers are now refused above 32 KiB exactly: Go's
server reads 4 KiB past MaxHeaderBytes, so that is set to 28 KiB, and
the tests try exactly 32 KiB and one byte more. SWWAF_UPSTREAM_URL now
needs a host, and a given port must be from 1 to 65535. make build and
make run call script/build and script/run.

Model: opus-5-5
2026-10-03 14:45:44 +00:00
sneak 545ce67f44 Pass-through proxy with timeouts, size limits and a request log (closes #13)
check / check (push) Successful in 2m9s
The repo's first code, with the layout the prompts policies ask for:
Makefile, script/ entrypoints, a Dockerfile whose lint and test phases
gate the build, the Gitea workflow, the canonical dotfiles and
REPO_POLICIES.md. smallwebwaf passes each request to the app through
httputil.ReverseProxy within the four timeouts and two size limits,
works out the client's address behind trusted proxies, and writes one
JSON line per request. The tests run against real local servers.
SPEC.md now says what Go's HTTP server does before smallwebwaf sees a
request; make fmt only rewraps EVALUATION.md.

Model: opus-5-5
2026-10-03 14:19:01 +00:00