Skip to content

[P1] Enforce upstream timeouts and response limits while reading #51

Description

@michielbdejong

Recorded during review of main at a1eb305ccfa2f3fc8ddede4875765cf1b099bd2b. This issue records a finding only; no implementation changes were made or requested.

Finding

The shared client has no request timeout. The 10 MB proxy response limit is checked only after upstream.bytes() buffers the entire body. Slow or oversized responses can hold resources indefinitely or exhaust memory before the limit takes effect. The locally inspected reqwest defaults have no request/read timeout.

Evidence

Desired outcome

Apply bounded request/read deadlines and enforce the response limit incrementally while reading. Cover stalled and oversized upstream responses with local fixtures.

Activity

  1. michielbdejong commented on Sep 16, 2026

    @michielbdejong
    ContributorAuthor

    Fixed in #73 — the shared HTTP client now has connect/read timeouts, and the upstream response body is read incrementally via Response::chunk(), rejected as soon as the 10 MiB limit is crossed instead of after being fully buffered.


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions