aboutsummaryrefslogtreecommitdiffstats
path: root/internal/auth/git@git.eyesin.space:/git
diff options
context:
space:
mode:
authorgrm <grm@eyesin.space>2026-09-18 13:46:33 +0300
committergrm <grm@eyesin.space>2026-09-18 13:46:33 +0300
commit254733b0566830a46e5a44c2d3127f57bfaceb65 (patch)
tree598beea9e6e19fc43453445efaa6593b3112f9e2 /internal/auth/git@git.eyesin.space:/git
parentf8d90e3d80ec798689be5fdf792e6c1401ad748f (diff)
downloadblogspace-254733b0566830a46e5a44c2d3127f57bfaceb65.tar.gz
blogspace-254733b0566830a46e5a44c2d3127f57bfaceb65.tar.bz2
blogspace-254733b0566830a46e5a44c2d3127f57bfaceb65.zip
Security: Cap the login body and log failed logins
POST /webadmin is the one form outside guardPOST, so nothing bounded its body: a multipart login could park 32 MB in memory or temp files per request. It now reads at most 64 KB. Wrong passwords are logged with the username and client address so an attack shows up in the log (fail2ban can read it) instead of being invisible. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
Diffstat (limited to 'internal/auth/git@git.eyesin.space:/git')
0 files changed, 0 insertions, 0 deletions