Bound every slog line against client-chosen text (closes #176)
All checks were successful
check / check (push) Successful in 2m55s
All checks were successful
check / check (push) Successful in 2m55s
This commit was merged in pull request #180.
This commit is contained in:
@@ -5,6 +5,7 @@ import (
|
||||
"strconv"
|
||||
|
||||
"sneak.berlin/go/webhooker/internal/database"
|
||||
"sneak.berlin/go/webhooker/internal/logfield"
|
||||
)
|
||||
|
||||
// HandleLoginPage returns a handler for the login page (GET)
|
||||
@@ -70,7 +71,9 @@ func (h *Handlers) HandleLoginSubmit() http.HandlerFunc {
|
||||
|
||||
h.log.Info(
|
||||
"user logged in",
|
||||
"username", username,
|
||||
"username", logfield.Truncate(
|
||||
username, logfield.MaxBytes,
|
||||
),
|
||||
"user_id", user.ID,
|
||||
)
|
||||
|
||||
@@ -117,7 +120,9 @@ func (h *Handlers) authenticateUser(
|
||||
if !ok {
|
||||
h.log.Warn(
|
||||
"password verification capacity exhausted",
|
||||
"path", r.URL.Path,
|
||||
"path", logfield.Truncate(
|
||||
r.URL.Path, logfield.MaxBytes,
|
||||
),
|
||||
)
|
||||
h.renderLoginError(
|
||||
w, r,
|
||||
@@ -142,7 +147,17 @@ func (h *Handlers) authenticateUser(
|
||||
h.dummyVerifications.Add(1)
|
||||
database.VerifyDummyPassword(password)
|
||||
|
||||
h.log.Debug("user not found", "username", username)
|
||||
// Login is unauthenticated, and the submitted username is
|
||||
// a form field the client fills to any length the 1 MB
|
||||
// body cap allows. On this branch it matched no row, so
|
||||
// nothing else bounds it. The rate limiter caps how often
|
||||
// the line is written, not how wide it is.
|
||||
h.log.Debug(
|
||||
"user not found",
|
||||
"username", logfield.Truncate(
|
||||
username, logfield.MaxBytes,
|
||||
),
|
||||
)
|
||||
h.rejectLogin(w, r, username)
|
||||
|
||||
return user, err
|
||||
@@ -160,7 +175,17 @@ func (h *Handlers) authenticateUser(
|
||||
}
|
||||
|
||||
if !valid {
|
||||
h.log.Debug("invalid password", "username", username)
|
||||
// Reached only once the username matched a stored row, so
|
||||
// it is bounded by the operator's own data. Capped anyway,
|
||||
// so that every username this unauthenticated endpoint
|
||||
// logs is capped and no reader has to work out which
|
||||
// branch narrowed it.
|
||||
h.log.Debug(
|
||||
"invalid password",
|
||||
"username", logfield.Truncate(
|
||||
username, logfield.MaxBytes,
|
||||
),
|
||||
)
|
||||
h.rejectLogin(w, r, username)
|
||||
|
||||
return user, errInvalidPassword
|
||||
|
||||
Reference in New Issue
Block a user