Say at the receiver route where its 1 MB body cap lives (closes #173)
check / check (push) Successful in 3m15s

/h/{uuid} has no MaxBodySize middleware, unlike the page route
groups; its cap is in the handler, which owns the 413 senders get.
A comment at the route registration now says so, and the handler's
read function notes it is the receiver's only body cap.

A new routing test sends a body exactly at the cap and one byte over
it through the production router, and checks the second is refused
with the handler's 413 and message.

Model: opus-5-5
This commit is contained in:
2026-10-02 10:11:22 +00:00
parent 8b5541734e
commit 3c1991d2ae
3 changed files with 56 additions and 1 deletions
+3 -1
View File
@@ -150,7 +150,9 @@ func (h *Handlers) lookupEntrypoint(
return entrypoint, true
}
// readWebhookBody reads and validates the request body size.
// readWebhookBody reads and validates the request body size. This is
// the receiver's only body cap: /h/{uuid} has no MaxBodySize
// middleware (see Server.setupWebhookRoutes).
func (h *Handlers) readWebhookBody(
w http.ResponseWriter,
r *http.Request,