hscontrol: limit /verify request body size
Wrap req.Body with io.LimitReader bounded to 4 KiB before io.ReadAll. The DERP verify payload is a few hundred bytes.
This commit is contained in:
parent
a3c4ad2ca3
commit
42b8c779a0
2 changed files with 66 additions and 1 deletions
|
|
@ -80,13 +80,19 @@ func parseCapabilityVersion(req *http.Request) (tailcfg.CapabilityVersion, error
|
|||
return tailcfg.CapabilityVersion(clientCapabilityVersion), nil
|
||||
}
|
||||
|
||||
// verifyBodyLimit caps the request body for /verify. The DERP verify
|
||||
// protocol payload (tailcfg.DERPAdmitClientRequest) is a few hundred
|
||||
// bytes; 4 KiB is generous and prevents an unauthenticated client from
|
||||
// OOMing the public router with arbitrarily large POSTs.
|
||||
const verifyBodyLimit int64 = 4 * 1024
|
||||
|
||||
func (h *Headscale) handleVerifyRequest(
|
||||
req *http.Request,
|
||||
writer io.Writer,
|
||||
) error {
|
||||
body, err := io.ReadAll(req.Body)
|
||||
if err != nil {
|
||||
return fmt.Errorf("reading request body: %w", err)
|
||||
return NewHTTPError(http.StatusRequestEntityTooLarge, "request body too large", fmt.Errorf("reading request body: %w", err))
|
||||
}
|
||||
|
||||
var derpAdmitClientRequest tailcfg.DERPAdmitClientRequest
|
||||
|
|
@ -124,6 +130,8 @@ func (h *Headscale) VerifyHandler(
|
|||
return
|
||||
}
|
||||
|
||||
req.Body = http.MaxBytesReader(writer, req.Body, verifyBodyLimit)
|
||||
|
||||
err := h.handleVerifyRequest(req, writer)
|
||||
if err != nil {
|
||||
httpError(writer, err)
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue