fix: harden HTTP server and request handling - #144
Merged
joachimschmidt557 merged 1 commit intoAug 19, 2026
Merged
joachimschmidt557 merged 1 commit into
joachimschmidt557 merged 1 commit into
Conversation
Contributor
Author
|
sorry, this was a mistake |
joachimschmidt557
merged commit Aug 19, 2026
c95c7ff
into
timewarrior-synchronize:main
3 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR hardens the HTTP server against common abuse scenarios and tightens request handling on the sync endpoint.
Changes
main.go): Replace the barehttp.ListenAndServecall with anhttp.Serverconfigured withReadHeaderTimeout(10s),ReadTimeout(30s),WriteTimeout(60s), andIdleTimeout(120s). This mitigates Slowloris-style attacks and prevents connections from exhausting server resources by staying open indefinitely./api/syncto POST (sync/handle.go): The sync handler now rejects non-POST requests with405 Method Not Allowedinstead of attempting to parse them as sync payloads.sync/user_management.go): Drop the explicitdestFile.Close()in the error path ofAddKey;log.Fatalfterminates the process anyway, and the file handle is already managed by the deferred close.vardeclarations, fixed import ordering, and corrected indentation of the health handler.Motivation
Running with Go's default
http.Serversettings means no timeouts at all, leaving the server vulnerable to slow-client resource exhaustion. Additionally, the sync endpoint accepted any HTTP method, which made request handling less strict than necessary. These changes improve robustness without altering the sync protocol or API behavior for legitimate clients.Testing
/api/healthas before.GET /api/syncnow returns405 Method Not Allowed, while well-formedPOSTrequests continue to sync successfully.