From 90578f02d851ab4e28a066404fbcf4be6a0ed9a7 Mon Sep 17 00:00:00 2001 From: grm Date: Fri, 18 Sep 2026 13:45:16 +0300 Subject: Security: Serve /media single-range only http.ServeContent honours any number of comma-separated ranges and chunkReader caches one 512 KiB slice, so a Range header alternating between two chunks costs a substring() query per range: one 1 MB header could make Postgres read tens of gigabytes for a single anonymous request. Browsers and download managers only ever send one range, so a multi-range header is dropped and the file served whole. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A --- internal/web/web_test.go | 13 +++++++++++++ 1 file changed, 13 insertions(+) (limited to 'internal/web/web_test.go') diff --git a/internal/web/web_test.go b/internal/web/web_test.go index fc38536..1d4db4c 100644 --- a/internal/web/web_test.go +++ b/internal/web/web_test.go @@ -907,3 +907,16 @@ func TestImagePickKeepsOlderChoice(t *testing.T) { } } } + +func TestSingleRangeOnly(t *testing.T) { + for in, want := range map[string]string{"bytes=0-9": "bytes=0-9", "bytes=0-0,1-1": "", "": ""} { + req := httptest.NewRequest("GET", "/media/x", nil) + if in != "" { + req.Header.Set("Range", in) + } + singleRangeOnly(req) + if got := req.Header.Get("Range"); got != want { + t.Errorf("Range %q: kept %q, want %q", in, got, want) + } + } +} -- cgit v1.2.3