diff options
| author | grm <grm@eyesin.space> | 2026-09-18 13:46:33 +0300 |
|---|---|---|
| committer | grm <grm@eyesin.space> | 2026-09-18 13:46:33 +0300 |
| commit | 254733b0566830a46e5a44c2d3127f57bfaceb65 (patch) | |
| tree | 598beea9e6e19fc43453445efaa6593b3112f9e2 /AGENTS.md | |
| parent | f8d90e3d80ec798689be5fdf792e6c1401ad748f (diff) | |
| download | blogspace-254733b0566830a46e5a44c2d3127f57bfaceb65.tar.gz blogspace-254733b0566830a46e5a44c2d3127f57bfaceb65.tar.bz2 blogspace-254733b0566830a46e5a44c2d3127f57bfaceb65.zip | |
Security: Cap the login body and log failed logins
POST /webadmin is the one form outside guardPOST, so nothing bounded
its body: a multipart login could park 32 MB in memory or temp files
per request. It now reads at most 64 KB. Wrong passwords are logged
with the username and client address so an attack shows up in the log
(fail2ban can read it) instead of being invisible.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
Diffstat (limited to 'AGENTS.md')
| -rw-r--r-- | AGENTS.md | 5 |
1 files changed, 4 insertions, 1 deletions
@@ -135,7 +135,10 @@ internal/web/ server.go (host router, middleware, render helpers) - **Hardening** (`web/ratelimit.go`): a per-key token bucket throttles the anonymous endpoints worth abusing — `loginLimit` on `POST /webadmin`, keyed by client address *and* by lowercased username (10 at once, then 10 a - minute each), answered with 429 by `s.throttle` and a log line. Flood + minute each), answered with 429 by `s.throttle` and a log line; failed + logins are logged with the username and address, and the login body is + capped at `maxLoginBody` (64 KB) since it is the one POST outside + `guardPOST`. Flood control for everything else stays at the reverse proxy (`limit_req`). - **Templates**: each page file is parsed together with its layout (`layouts/dashboard.html` or `layouts/blog.html` for `blog/*`) and all |
