diff options
| author | grm <grm@eyesin.space> | 2026-09-18 13:45:16 +0300 |
|---|---|---|
| committer | grm <grm@eyesin.space> | 2026-09-18 13:45:16 +0300 |
| commit | 90578f02d851ab4e28a066404fbcf4be6a0ed9a7 (patch) | |
| tree | d8e5f5fea70c0e8f11a93eebaa3d3add79b6c14a /AGENTS.md | |
| parent | 19353a51c869f4b24ef2253d856084b6e6728048 (diff) | |
| download | blogspace-90578f02d851ab4e28a066404fbcf4be6a0ed9a7.tar.gz blogspace-90578f02d851ab4e28a066404fbcf4be6a0ed9a7.tar.bz2 blogspace-90578f02d851ab4e28a066404fbcf4be6a0ed9a7.zip | |
Security: Serve /media single-range only
http.ServeContent honours any number of comma-separated ranges and
chunkReader caches one 512 KiB slice, so a Range header alternating
between two chunks costs a substring() query per range: one 1 MB header
could make Postgres read tens of gigabytes for a single anonymous
request. Browsers and download managers only ever send one range, so a
multi-range header is dropped and the file served whole.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
Diffstat (limited to 'AGENTS.md')
| -rw-r--r-- | AGENTS.md | 2 |
1 files changed, 2 insertions, 0 deletions
@@ -294,6 +294,8 @@ internal/web/ server.go (host router, middleware, render helpers) is. The bytes are streamed by `BlogStore.FileReader` (a `chunkReader` over `substring()`, 512 KiB per query, Range requests included), which is why the per-blog limit is capped at 1024 MB (`maxUploadMB`: int4 offsets). + Only a single range is honoured (`singleRangeOnly` drops multi-range + headers): ServeContent's multipart answer would cost a query per range. Ids are immutable, so a renamed file keeps its old download name in browsers that cached it. Markdown keeps the relative `/media/…` form because post bodies render on the blog host; `fileMarkdown` writes |
