Commit d219e10
committed
Add payload and timeout limits to HTTP/SSE servers
Addresses security audit issue #3: Unbounded request body parsing
- Set 10MB max payload length to prevent memory exhaustion
- Add 30 second read/write timeouts to prevent slowloris attacks
- Applied to both HttpServerWrapper and SseServerWrapper
This prevents DoS attacks via large request bodies or slow clients.1 parent b2b2772 commit d219e10
2 files changed
Lines changed: 11 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
24 | 24 | | |
25 | 25 | | |
26 | 26 | | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
27 | 33 | | |
28 | 34 | | |
29 | 35 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
136 | 136 | | |
137 | 137 | | |
138 | 138 | | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
139 | 144 | | |
140 | 145 | | |
141 | 146 | | |
| |||
0 commit comments