Repository navigation
fix(opds): add request bounds and Argon2 concurrency limits - #154
phildenhoff wants to merge 1 commit into
Conversation
libcalibre Test Coverage ReportOverall coverage: 83.86% Coverage breakdown available in the artifacts. |
bd3c587 to
4ebc067
Compare
libcalibre Test Coverage ReportOverall coverage: 83.86% Coverage breakdown available in the artifacts. |
libcalibre Test Coverage ReportOverall coverage: 83.86% Coverage breakdown available in the artifacts. |
4ebc067 to
d8e1bcf
Compare
libcalibre Test Coverage ReportOverall coverage: 84.01% Coverage breakdown available in the artifacts. |
libcalibre Test Coverage ReportOverall coverage: 84.01% Coverage breakdown available in the artifacts. |
d8e1bcf to
4367973
Compare
libcalibre Test Coverage ReportOverall coverage: 84.01% Coverage breakdown available in the artifacts. |
libcalibre Test Coverage ReportOverall coverage: 84.01% Coverage breakdown available in the artifacts. |
4367973 to
f58bfe2
Compare
libcalibre Test Coverage ReportOverall coverage: 84.01% Coverage breakdown available in the artifacts. |
libcalibre Test Coverage ReportOverall coverage: 84.01% Coverage breakdown available in the artifacts. |
fix(opds): cap Argon2 concurrency and request pressure Merge-blocking hardening from the v1 review: - Limit concurrent password verifications to 3 permits; excess requests get 503 with Retry-After without hashing or caching the header - Bound catalog feeds with a 30s timeout, 16KiB request-body limit, and a shared 64-request permit pool; asset downloads stay untimed - Reject link-local explicit listener addresses in the headless server and assert advertised URLs are IPv4-first without link-local entries - Note in the Sharing pane that generated passwords are shown once and travel unencrypted
f58bfe2 to
03f2fc1
Compare
libcalibre Test Coverage ReportOverall coverage: 84.01% Coverage breakdown available in the artifacts. |
libcalibre Test Coverage ReportOverall coverage: 84.01% Coverage breakdown available in the artifacts. |
Why
The v1 server had no limits. Every Basic-auth attempt ran a fresh Argon2 hash, requests had no size or time bounds, and nothing capped concurrent work — one busy or hostile client could pin the CPU or pile up connections indefinitely.
What changed
Retry-Afterinstead of stacking up.Retry-Afterwithout hashing — covered by a test that drains the permits and asserts no hash runs and no result is cached...%2f,%2e%2e%2f…must not escape the book directory), and bind failures mapPermissionDeniedto its own error code instead of a generic unexpected.Honest note: all of these guards engage after headers arrive, so slowloris-style slow-header connections are a known, deferred gap.
Validation: the stack tip runs 62 citadel-opds tests + 348 workspace tests, all green.
Stack: #146 → #147 → #148 → #149 → #150 → #151 → #152 → #153 → #154 (this) → #155