chg: some sec fixes

This commit is contained in:
marcello33 2024-10-31 10:56:34 +01:00
parent 63460bd20e
commit f08f2ead42
No known key found for this signature in database
GPG key ID: 06128777E3C36B16

View file

@ -31,9 +31,10 @@ var (
) )
const ( const (
stateFetchLimit = 50 heimdallAPIBodyLimit = 128 * 1024 * 1024 // 128 MB
apiHeimdallTimeout = 5 * time.Second stateFetchLimit = 50
retryCall = 5 * time.Second apiHeimdallTimeout = 5 * time.Second
retryCall = 5 * time.Second
) )
type StateSyncEventsResponse struct { type StateSyncEventsResponse struct {
@ -455,8 +456,11 @@ func internalFetch(ctx context.Context, client http.Client, u *url.URL) ([]byte,
return nil, nil return nil, nil
} }
// Limit the number of bytes read from the response body
limitedBody := http.MaxBytesReader(nil, res.Body, heimdallAPIBodyLimit)
// get response // get response
body, err := io.ReadAll(res.Body) body, err := io.ReadAll(limitedBody)
if err != nil { if err != nil {
return nil, err return nil, err
} }