A route test now posts an oversized body with no session or CSRF
token to each page route group, /settings included, and requires 413
with no CSRF cookie. Before, only the login form pinned the cap ahead
of CSRF; reordering the /settings, /hooks or /hook groups failed
nothing.
The MaxBodySize doc comment says other methods pass uncapped on
purpose, and the middleware test comment names the helper it
describes. The three router helpers in the server tests build the
Server through New, on a lifecycle that is never started, instead of
setting its fields by hand. The README already described the cap's
position correctly.
Model: opus-5-5
The access log's response writer and the metrics middleware's writer hid the writer beneath them, so a handler's flush, hijack or write deadline set through http.ResponseController failed with "not supported" behind them. The access log's writer now has Unwrap. The metrics middleware calls the library's public Measure with a writer of our own that has Unwrap, in place of std.Handler's writer, so the middleware order and what metrics record are unchanged. A test over a real connection sets a write deadline and flushes, metrics on and off, on a global route and in an admin page group, and fails without either Unwrap.
Model: opus-5-5