Skip to content

fix: fully drain request body on auth early-return to prevent connection leaks [FaaFyfxR9WAQrL7FcAgEHJvztd8cVMxvjHRS55rw1nwH] - #4

Open
waterWang wants to merge 1 commit into
madalynerlge2:mainfrom
waterWang:main
Open

fix: fully drain request body on auth early-return to prevent connection leaks [FaaFyfxR9WAQrL7FcAgEHJvztd8cVMxvjHRS55rw1nwH]#4
waterWang wants to merge 1 commit into
madalynerlge2:mainfrom
waterWang:main

Conversation

@waterWang

Copy link
Copy Markdown

Fixes connection leak on failed BasicAuth.

Problem

When the BasicAuth middleware aborts an unauthorized request, it previously drained only 4096 bytes of the request body:

_, _ = io.CopyN(io.Discard, c.Request.Body, 4096)
c.Request.Body.Close()

For requests with a body larger than 4 KiB (or chunked transfer), unread bytes remain on the socket. The HTTP server treats those leftover bytes as the start of the next request over the same keep-alive connection, breaking ("leaking") the connection.

…ion leaks

Replace io.CopyN(Discard, Body, 4096) with io.Copy(Discard, Body) so the
request body is drained to EOF before closing. A partial 4096-byte drain
leaves large/chunked request bodies unread; on HTTP keep-alive connections
the server treats those leftover bytes as belonging to the next request,
breaking ("leaking") the connection.

Also add a drain-to-EOF regression test (16 KiB body) and a nil-body safety
test, plus the minimal gin stub types needed for the repo's tests to compile.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant