From 90578f02d851ab4e28a066404fbcf4be6a0ed9a7 Mon Sep 17 00:00:00 2001 From: grm Date: Fri, 18 Sep 2026 13:45:16 +0300 Subject: Security: Serve /media single-range only http.ServeContent honours any number of comma-separated ranges and chunkReader caches one 512 KiB slice, so a Range header alternating between two chunks costs a substring() query per range: one 1 MB header could make Postgres read tens of gigabytes for a single anonymous request. Browsers and download managers only ever send one range, so a multi-range header is dropped and the file served whole. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A --- AGENTS.md | 2 ++ 1 file changed, 2 insertions(+) (limited to 'AGENTS.md') diff --git a/AGENTS.md b/AGENTS.md index 1cc12fd..6d7b355 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -294,6 +294,8 @@ internal/web/ server.go (host router, middleware, render helpers) is. The bytes are streamed by `BlogStore.FileReader` (a `chunkReader` over `substring()`, 512 KiB per query, Range requests included), which is why the per-blog limit is capped at 1024 MB (`maxUploadMB`: int4 offsets). + Only a single range is honoured (`singleRangeOnly` drops multi-range + headers): ServeContent's multipart answer would cost a query per range. Ids are immutable, so a renamed file keeps its old download name in browsers that cached it. Markdown keeps the relative `/media/…` form because post bodies render on the blog host; `fileMarkdown` writes -- cgit v1.2.3