Say at the receiver route where its 1 MB body cap lives (closes #173)
check / check (push) Successful in 3m22s

The receiver route /h/{uuid} has no MaxBodySize middleware, unlike the page route groups; its 1 MB cap is enforced in the handler, which owns the response senders see. Nothing at the route said so, so a reader could take the receiver for uncapped or remove the only bound on the one unauthenticated endpoint. The route registration and the handler's body-reading function now say where the cap lives and why. A routing test sends a body of exactly 1 MB and one a byte over through the production router and pins that only the second is refused, with the handler's 413 and message.

Model: opus-5-5
This commit was merged in pull request #429.
This commit is contained in:
2026-10-02 13:40:00 +02:00
parent fd036774f9
commit 5551f75251
3 changed files with 56 additions and 1 deletions
+3 -1
View File
@@ -150,7 +150,9 @@ func (h *Handlers) lookupEntrypoint(
return entrypoint, true
}
// readWebhookBody reads and validates the request body size.
// readWebhookBody reads and validates the request body size. This is
// the receiver's only body cap: /h/{uuid} has no MaxBodySize
// middleware (see Server.setupWebhookRoutes).
func (h *Handlers) readWebhookBody(
w http.ResponseWriter,
r *http.Request,