fix(ploeg): bound request body reads and idle connections in ploegd #148
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "ryangr0/ploegd-http-timeouts"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
ploegd's HTTP server set only ReadHeaderTimeout. Webhook handlers cap the
body size but not the time it takes to arrive, so a client that trickles
its body could hold a connection on an unauthenticated route
indefinitely, and idle keep-alive connections were never reclaimed.
The server is now built by newHTTPServer with ReadTimeout 30s (headers
plus body; a 1 MiB webhook needs only ~35 KiB/s to arrive in time) and
IdleTimeout 120s. No route streams (no SSE, long poll or flushed
responses), but WriteTimeout stays unset because it also bounds handler
time and deploy checks and webhooks call out to forges and trackers.
Tests cover a slow-body client being disconnected within the read
budget and a 1 MiB webhook at normal speed succeeding.
ReadTimeout 30s (headers and body), IdleTimeout 120s, ReadHeaderTimeout stays 5s. No route streams, but WriteTimeout stays unset on purpose: in Go it also caps handler run time, and several handlers call forges and trackers.
Verified with
mise run verifyon the pinned toolchain (all gates passed).Ticket: https://vikunja.webgrip.dev/tasks/1725
🤖 Generated with Claude Code