It does not check the upper bound. Valid TCP/UDP port numbers must be ≤ 65535. Passing values like 99999 would be stored in the database and later cause Docker container creation to fail with a confusing error.
## Bug
**File:** `internal/handlers/app.go`, `parsePortValues()`
**Severity:** LOW-MEDIUM — Input validation gap
### Description
The port validation only checks that ports are positive:
```go
if hostErr != nil || containerErr != nil || hostPort <= 0 || containerPort <= 0 {
return 0, 0, false
}
```
It does not check the upper bound. Valid TCP/UDP port numbers must be ≤ 65535. Passing values like 99999 would be stored in the database and later cause Docker container creation to fail with a confusing error.
### Suggested Fix
```go
const maxPort = 65535
if hostErr != nil || containerErr != nil || hostPort <= 0 || containerPort <= 0 || hostPort > maxPort || containerPort > maxPort {
return 0, 0, false
}
```
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Bug
File:
internal/handlers/app.go,parsePortValues()Severity: LOW-MEDIUM — Input validation gap
Description
The port validation only checks that ports are positive:
It does not check the upper bound. Valid TCP/UDP port numbers must be ≤ 65535. Passing values like 99999 would be stored in the database and later cause Docker container creation to fail with a confusing error.
Suggested Fix
yes, please fix this and give me a PR