Say at the receiver route where its 1 MB body cap lives (closes #173)
check / check (push) Successful in 3m15s

/h/{uuid} has no MaxBodySize middleware, unlike the page route
groups; its cap is in the handler, which owns the 413 senders get.
A comment at the route registration now says so, and the handler's
read function notes it is the receiver's only body cap.

A new routing test sends a body exactly at the cap and one byte over
it through the production router, and checks the second is refused
with the handler's 413 and message.

Model: opus-5-5
This commit is contained in:
2026-10-02 10:11:22 +00:00
parent 8b5541734e
commit 3c1991d2ae
3 changed files with 56 additions and 1 deletions
+6
View File
@@ -304,6 +304,12 @@ func (s *Server) setupSourceRoutes() {
}
func (s *Server) setupWebhookRoutes() {
// No MaxBodySize here, unlike the page groups. The receiver's 1 MB
// body cap is in Handlers.readWebhookBody, because the handler
// owns the response a sender gets for an oversized body and
// MaxBodySize would change it. That cap is the only bound on this
// unauthenticated endpoint's body; TestReceiver_OversizeBodyRefused
// pins it.
s.router.With(s.mw.ReceiverRateLimit()).HandleFunc(
"/h/{uuid}",
s.h.HandleWebhook(),