Repository navigation
Fix/limit forwarded ip count - #126
Open
PascalMinder wants to merge 3 commits into
Open
PascalMinder wants to merge 3 commits into
PascalMinder wants to merge 3 commits into
Conversation
Theoretically an attacker could forge the X-Forwared-For or X-Real-IP header content with a long number of IP addresses. This would lead to a sequential look-up via the API. Each request can so take up to len(chain) * apiTimeoutMs time to resolve. Requests with more than 10 IPs across both headers are now denied with the same log-and-403 handling as unparsable addresses.
A failed lookup cached nothing, so every subsequent request from that IP re-attempted the API and waited out up to apiTimeoutMs again. Failed lookups are now also cached as ipEntries for a short time (30s). Depending on the configuration they are allowed or denied. ipEntry gained a String method so cache log lines stay readable and distinguish negative entries.
- Use on shared client per middleware, and the requests use NewRequestWithContext with the incoming request's context. - Fix issue with non-200 early return requests. Defer Body.Close(). - Bound request body read to a fixed size. - The shared transport raises MaxIdleConnsPerHost from the default 2 to 16.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Contains enhancements for the usage of the geolocation API.