security: harden first preview boundaries
verify / verify (push) Successful in 3m1s

Sanitized snapshot of private source 13a965dd6ea705dd92499f7dbeaa00c25c15247d. Require same-origin evidence for unsafe methods, fail closed on invalid authentication middleware configuration, and bound untrusted request metadata.

AI-Assistance: OpenAI Codex assisted implementation, testing, and security review.
Signed-off-by: Cole Speelman <crspeelman@gmail.com>
This commit is contained in:
2026-08-16 19:20:14 -04:00
parent df946d888e
commit a18f1dd22a
13 changed files with 181 additions and 12 deletions
+6 -1
View File
@@ -16,6 +16,11 @@ import (
const RecordVersion = 1
const (
maxRecordBytes int64 = 1 << 40
maxRecordDurationMicros int64 = int64((7 * 24 * time.Hour) / time.Microsecond)
)
// Record is deliberately stable and append-log friendly. Sensitive fields are
// populated only when explicitly enabled by Policy.
type Record struct {
@@ -38,7 +43,7 @@ type Record struct {
// Validate rejects records that cannot have been produced by this package's
// bounded middleware contract.
func (record Record) Validate() error {
if record.Version != RecordVersion || record.Timestamp.IsZero() || !boundedField(record.Method, 16, false) || !boundedField(record.Route, 256, false) || record.Status < 100 || record.Status > 999 || record.Bytes < 0 || record.DurationMicros < 0 {
if record.Version != RecordVersion || record.Timestamp.IsZero() || !boundedField(record.Method, 16, false) || !boundedField(record.Route, 256, false) || record.Status < 100 || record.Status > 999 || record.Bytes < 0 || record.Bytes > maxRecordBytes || record.DurationMicros < 0 || record.DurationMicros > maxRecordDurationMicros {
return errors.New("requestlog: invalid record")
}
fields := []struct {