From 254733b0566830a46e5a44c2d3127f57bfaceb65 Mon Sep 17 00:00:00 2001 From: grm Date: Fri, 18 Sep 2026 13:46:33 +0300 Subject: Security: Cap the login body and log failed logins POST /webadmin is the one form outside guardPOST, so nothing bounded its body: a multipart login could park 32 MB in memory or temp files per request. It now reads at most 64 KB. Wrong passwords are logged with the username and client address so an attack shows up in the log (fail2ban can read it) instead of being invisible. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A --- internal/web/handlers_auth.go | 11 +++++++++++ 1 file changed, 11 insertions(+) (limited to 'internal/web/handlers_auth.go') diff --git a/internal/web/handlers_auth.go b/internal/web/handlers_auth.go index 1545a4e..69b7b98 100644 --- a/internal/web/handlers_auth.go +++ b/internal/web/handlers_auth.go @@ -44,7 +44,16 @@ func (s *Server) handleWebadminRedirect(w http.ResponseWriter, r *http.Request) http.Redirect(w, r, s.cfg.RootURL()+"/webadmin?next="+urlQuery("/b/"+sub+"/"), http.StatusSeeOther) } +// maxLoginBody is all a login form needs; it is the one POST guardPOST does +// not cap, so it caps itself. +const maxLoginBody = 64 << 10 + func (s *Server) handleLogin(w http.ResponseWriter, r *http.Request) { + r.Body = http.MaxBytesReader(w, r.Body, maxLoginBody) + if err := r.ParseForm(); err != nil { + s.plainError(w, http.StatusBadRequest, s.tr(r, "Could not read the form.")) + return + } username := strings.TrimSpace(r.FormValue("username")) password := r.FormValue("password") next := safeNext(r.FormValue("next")) @@ -64,10 +73,12 @@ func (s *Server) handleLogin(w http.ResponseWriter, r *http.Request) { return } auth.CheckPassword("$2a$10$invalidinvalidinvalidinvalidinvalidinvalidinvalidinval", password) // constant-ish time + logf("login failed for %q from %s", username, clientIP(r)) fail() return } if u.Disabled || !auth.CheckPassword(u.PasswordHash, password) { + logf("login failed for %q from %s", username, clientIP(r)) fail() return } -- cgit v1.2.3