feat(api): 单次上传上限改为 context_max_bytes 可配,Cloudflare 边缘后默认 95Mi,新增 GET /me/submissions/limits 供面板预检
This commit is contained in:
10 files changed
+158
-2
No files matched your search
@@ -235,6 +235,11 @@ func cmdAPI(args []string, stdout, stderr io.Writer) int {
|
||||
submissions.MaxStoredBytesTotal = n
|
||||
}
|
||||
}
|
||||
if n, err := contextMaxBytes(cfg); err != nil {
|
||||
fmt.Fprintf(stderr, "felis api: [registry] context_max_bytes %q is not a positive size such as 95Mi; keeping the default\n", cfg.Registry.ContextMaxBytes)
|
||||
} else {
|
||||
submissions.MaxContextBytes = n
|
||||
}
|
||||
|
||||
// Restore subsystem (spec §7): the weak-SA restore Job mounts the target
|
||||
// world PVC + the backup PVC and runs `felis restore`. It needs deployment-
|
||||
@@ -876,3 +881,27 @@ func startServerCache(ctx context.Context, cfg *rest.Config, scheme *runtime.Sch
|
||||
}()
|
||||
return c, inf.HasSynced, nil
|
||||
}
|
||||
|
||||
// cloudflareContextMaxBytes is the per-upload cap behind the Cloudflare edge,
|
||||
// which refuses request bodies over 100 MB (the Free and Pro plan limit) with
|
||||
// its own 413 page before they reach the API. 95Mi leaves headroom under it, so
|
||||
// an oversized context meets the API's own JSON refusal instead.
|
||||
const cloudflareContextMaxBytes = "95Mi"
|
||||
|
||||
// contextMaxBytes resolves [registry] context_max_bytes, defaulting to
|
||||
// cloudflareContextMaxBytes behind the Cloudflare edge. 0 keeps the submit
|
||||
// package's own default (1 GiB).
|
||||
func contextMaxBytes(cfg *config.Config) (int64, error) {
|
||||
v := cfg.Registry.ContextMaxBytes
|
||||
if v == "" && cfg.Auth.BehindCloudflare() {
|
||||
v = cloudflareContextMaxBytes
|
||||
}
|
||||
if v == "" {
|
||||
return 0, nil
|
||||
}
|
||||
n, err := parseByteSize(v)
|
||||
if err != nil || n <= 0 {
|
||||
return 0, fmt.Errorf("not a positive size: %q", v)
|
||||
}
|
||||
return n, nil
|
||||
}
|
||||
@@ -0,0 +1,37 @@
|
||||
package main
|
||||
|
||||
import (
|
||||
"testing"
|
||||
|
||||
"felis.lolicon.best/internal/config"
|
||||
)
|
||||
|
||||
func TestContextMaxBytesFollowsTheEdge(t *testing.T) {
|
||||
cases := []struct {
|
||||
name string
|
||||
reg config.RegistryConfig
|
||||
auth config.AuthConfig
|
||||
want int64
|
||||
wantErr bool
|
||||
}{
|
||||
{name: "direct install keeps the package default", want: 0},
|
||||
{name: "access audience means the Cloudflare edge", auth: config.AuthConfig{AccessJWTAud: "aud-1"}, want: 99614720},
|
||||
{name: "CF-Connecting-IP header means the Cloudflare edge", auth: config.AuthConfig{ClientIPHeader: "cf-connecting-ip"}, want: 99614720},
|
||||
{name: "an operator proxy keeps the package default", auth: config.AuthConfig{ClientIPHeader: "X-Forwarded-For"}, want: 0},
|
||||
{name: "explicit value wins over the edge default", reg: config.RegistryConfig{ContextMaxBytes: "50Mi"}, auth: config.AuthConfig{AccessJWTAud: "aud-1"}, want: 52428800},
|
||||
{name: "explicit value on a direct install", reg: config.RegistryConfig{ContextMaxBytes: "2Gi"}, want: 2147483648},
|
||||
{name: "garbage is refused", reg: config.RegistryConfig{ContextMaxBytes: "lots"}, wantErr: true},
|
||||
{name: "zero is refused", reg: config.RegistryConfig{ContextMaxBytes: "0"}, wantErr: true},
|
||||
}
|
||||
for _, tc := range cases {
|
||||
t.Run(tc.name, func(t *testing.T) {
|
||||
got, err := contextMaxBytes(&config.Config{Registry: tc.reg, Auth: tc.auth})
|
||||
if (err != nil) != tc.wantErr {
|
||||
t.Fatalf("err = %v, wantErr %v", err, tc.wantErr)
|
||||
}
|
||||
if got != tc.want {
|
||||
t.Fatalf("contextMaxBytes = %d, want %d", got, tc.want)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
Reference in new issue
Block a user