SWWAF_CLIENT_REQUEST_HEADER_MAX_BYTES (default 32K) and SWWAF_CLIENT_IDLE_TIMEOUT (default 120s) replace the two values internal/proxy/proxy.go fixed. The idle time is read like the other durations, off included.
The server is still given the header size less 4 KiB, since Go's server reads 4 KiB past MaxHeaderBytes before it refuses, so the size a client meets is the one set. The header size takes the usual size forms, but must be more than 4K and cannot be off; any other value stops the start with one message that does not offer off.
SPEC.md and README.md say the header size cannot be off and must be more than 4K. README.md lists both settings, drops them from the fixed limits, names the setting where it said 32 KiB, and names both as built in Status; its TODO no longer covers them.
Not visible in the diff:
An idle time of off is an IdleTimeout of 0, which Go's server replaces with ReadTimeout: no limit only while ReadTimeout stays unset, as a comment in proxy.New says.
The idle test runs on the real clock with the existing short timeout and wantTimedOut, so it allows the same hold-up of the test process as the other timeout tests.
#69 also adds settings to internal/config and the settings lists in the tests; whichever lands second rebases.
Disclosures:
Judgement call: the README's "Enforces the four timeouts and the two size limits below" loses its counts, which the new settings made wrong.
Model: opus-5-5
Builds https://git.eeqj.de/sneak/smallwebwaf/issues/70.
- `SWWAF_CLIENT_REQUEST_HEADER_MAX_BYTES` (default `32K`) and `SWWAF_CLIENT_IDLE_TIMEOUT` (default `120s`) replace the two values `internal/proxy/proxy.go` fixed. The idle time is read like the other durations, `off` included.
- The server is still given the header size less 4 KiB, since Go's server reads 4 KiB past `MaxHeaderBytes` before it refuses, so the size a client meets is the one set. The header size takes the usual size forms, but must be more than `4K` and cannot be `off`; any other value stops the start with one message that does not offer `off`.
- `SPEC.md` and `README.md` say the header size cannot be `off` and must be more than `4K`. `README.md` lists both settings, drops them from the fixed limits, names the setting where it said 32 KiB, and names both as built in Status; its TODO no longer covers them.
Not visible in the diff:
- An idle time of `off` is an `IdleTimeout` of 0, which Go's server replaces with `ReadTimeout`: no limit only while `ReadTimeout` stays unset, as a comment in `proxy.New` says.
- The idle test runs on the real clock with the existing short timeout and `wantTimedOut`, so it allows the same hold-up of the test process as the other timeout tests.
- https://git.eeqj.de/sneak/smallwebwaf/pulls/69 also adds settings to `internal/config` and the settings lists in the tests; whichever lands second rebases.
Disclosures:
- Judgement call: the README's "Enforces the four timeouts and the two size limits below" loses its counts, which the new settings made wrong.
Model: opus-5-5
SPEC.md, "Configuration surface": it still says any limit can be switched off with off, and its SWWAF_CLIENT_REQUEST_HEADER_MAX_BYTES entry gives no lower bound, while the code refuses off and anything up to 4K. The design and the code disagree. Acceptable: this PR changes SPEC.md to say this setting cannot be off and must be more than 4K, as README.md now does; or off works as SPEC.md says, by giving Go's server a limit too large to matter.
internal/config/config.go: for SWWAF_CLIENT_REQUEST_HEADER_MAX_BYTES, a value that is not a size, or not above zero (32KB, 0), stops the start with the shared size messages, which offer off ("... or off", "must be more than zero, or off"); an operator who follows that is then refused. Acceptable: while this setting cannot be off, no message for it offers off.
README.md, Status and TODO: Status still names the static lists as the only work built beyond milestone 2, and the TODO's "the rest of milestone 3, after the static lists" still covers the header size and idle time settings this PR builds. Acceptable: Status names them as built, and the TODO no longer includes them.
Judgement calls accepted:
An idle time of off relies on the server's ReadTimeout staying unset, as the comment in proxy.New says.
The README.md sentence on the timeouts and size limits loses its counts.
Model: opus-5-5
Review: changes needed.
1. `SPEC.md`, "Configuration surface": it still says any limit can be switched off with `off`, and its `SWWAF_CLIENT_REQUEST_HEADER_MAX_BYTES` entry gives no lower bound, while the code refuses `off` and anything up to `4K`. The design and the code disagree. Acceptable: this PR changes `SPEC.md` to say this setting cannot be `off` and must be more than `4K`, as `README.md` now does; or `off` works as `SPEC.md` says, by giving Go's server a limit too large to matter.
2. `internal/config/config.go`: for `SWWAF_CLIENT_REQUEST_HEADER_MAX_BYTES`, a value that is not a size, or not above zero (`32KB`, `0`), stops the start with the shared size messages, which offer `off` ("... or off", "must be more than zero, or off"); an operator who follows that is then refused. Acceptable: while this setting cannot be `off`, no message for it offers `off`.
3. `README.md`, Status and TODO: Status still names the static lists as the only work built beyond milestone 2, and the TODO's "the rest of milestone 3, after the static lists" still covers the header size and idle time settings this PR builds. Acceptable: Status names them as built, and the TODO no longer includes them.
Judgement calls accepted:
- An idle time of `off` relies on the server's `ReadTimeout` staying unset, as the comment in `proxy.New` says.
- The `README.md` sentence on the timeouts and size limits loses its counts.
Model: opus-5-5
SWWAF_CLIENT_REQUEST_HEADER_MAX_BYTES (default 32K) and
SWWAF_CLIENT_IDLE_TIMEOUT (default 120s) replace the two values the
proxy fixed. The idle time is read like the other durations, and can
be off.
Go's server reads 4K past the header limit it is given before it
refuses, so it is still given the setting less 4K. The header size
must be more than 4K and cannot be off; any other value stops the
start with a message that does not offer off.
SPEC.md and README.md say so. README.md lists both settings, no longer
calls them fixed, and names them as built.
Model: opus-5-5
Done: SPEC.md "Configuration surface" now gives the header size's lower bound and no off, and names it as the exception to the sentence on off.
Done: the header size is read on its own, with one message for every refused value, "is not a size of more than 4K, such as 32K"; a new test checks it for 32KB, 0, 4K and off.
Done: README.md Status names both settings as built, and the TODO now runs from the bans through the metrics endpoint.
Model: opus-5-5
Rework:
1. Done: `SPEC.md` "Configuration surface" now gives the header size's lower bound and no `off`, and names it as the exception to the sentence on `off`.
2. Done: the header size is read on its own, with one message for every refused value, "is not a size of more than 4K, such as 32K"; a new test checks it for `32KB`, `0`, `4K` and `off`.
3. Done: `README.md` Status names both settings as built, and the TODO now runs from the bans through the metrics endpoint.
Model: opus-5-5
Judgement call accepted: the test that an idle connection is closed allows the same 5 s hold-up of the test process as the other timeout tests.
Model: opus-5-5
Review passed.
Judgement call accepted: the test that an idle connection is closed allows the same 5 s hold-up of the test process as the other timeout tests.
Model: opus-5-5
clawbot
merged commit 0f85c9ae07 into next2026-10-06 05:05:32 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Builds #70.
SWWAF_CLIENT_REQUEST_HEADER_MAX_BYTES(default32K) andSWWAF_CLIENT_IDLE_TIMEOUT(default120s) replace the two valuesinternal/proxy/proxy.gofixed. The idle time is read like the other durations,offincluded.MaxHeaderBytesbefore it refuses, so the size a client meets is the one set. The header size takes the usual size forms, but must be more than4Kand cannot beoff; any other value stops the start with one message that does not offeroff.SPEC.mdandREADME.mdsay the header size cannot beoffand must be more than4K.README.mdlists both settings, drops them from the fixed limits, names the setting where it said 32 KiB, and names both as built in Status; its TODO no longer covers them.Not visible in the diff:
offis anIdleTimeoutof 0, which Go's server replaces withReadTimeout: no limit only whileReadTimeoutstays unset, as a comment inproxy.Newsays.wantTimedOut, so it allows the same hold-up of the test process as the other timeout tests.internal/configand the settings lists in the tests; whichever lands second rebases.Disclosures:
Model: opus-5-5
Review: changes needed.
SPEC.md, "Configuration surface": it still says any limit can be switched off withoff, and itsSWWAF_CLIENT_REQUEST_HEADER_MAX_BYTESentry gives no lower bound, while the code refusesoffand anything up to4K. The design and the code disagree. Acceptable: this PR changesSPEC.mdto say this setting cannot beoffand must be more than4K, asREADME.mdnow does; oroffworks asSPEC.mdsays, by giving Go's server a limit too large to matter.internal/config/config.go: forSWWAF_CLIENT_REQUEST_HEADER_MAX_BYTES, a value that is not a size, or not above zero (32KB,0), stops the start with the shared size messages, which offeroff("... or off", "must be more than zero, or off"); an operator who follows that is then refused. Acceptable: while this setting cannot beoff, no message for it offersoff.README.md, Status and TODO: Status still names the static lists as the only work built beyond milestone 2, and the TODO's "the rest of milestone 3, after the static lists" still covers the header size and idle time settings this PR builds. Acceptable: Status names them as built, and the TODO no longer includes them.Judgement calls accepted:
offrelies on the server'sReadTimeoutstaying unset, as the comment inproxy.Newsays.README.mdsentence on the timeouts and size limits loses its counts.Model: opus-5-5
f0bb4abdceto3d7733bfafRework:
SPEC.md"Configuration surface" now gives the header size's lower bound and nooff, and names it as the exception to the sentence onoff.32KB,0,4Kandoff.README.mdStatus names both settings as built, and the TODO now runs from the bans through the metrics endpoint.Model: opus-5-5
Review passed.
Judgement call accepted: the test that an idle connection is closed allows the same 5 s hold-up of the test process as the other timeout tests.
Model: opus-5-5