feat(api): 访问日志与 HTTP/运行时指标、安全响应头与面板 CSP、跨站写拦截、请求体读截止、SSE 定期重鉴权与续传、404/405/413 信封、status 按所有权裁剪、停机并发排空

This commit is contained in:
Lemon-miaow committed 2026-09-25 02:14:08 +08:00
1 parent cc85aac906
commit f8f112b8ca
24 files changed
+1453 -55

No files matched your search

+8 -1
View File
@@ -2,6 +2,7 @@ package api
import (
"encoding/json"
"errors"
"mime"
"net/http"
"strings"
@@ -31,11 +32,17 @@ func requireJSONContentType(r *http.Request) error {
}
// decodeJSON strictly decodes a small request body into v, rejecting unknown
// fields and trailing data so malformed callers fail fast with 400.
// fields and trailing data so malformed callers fail fast with 400, and a body
// past maxBodyBytes with 413.
func decodeJSON(w http.ResponseWriter, r *http.Request, v any) error {
dec := json.NewDecoder(http.MaxBytesReader(w, r.Body, maxBodyBytes))
dec.DisallowUnknownFields()
if err := dec.Decode(v); err != nil {
var tooBig *http.MaxBytesError
if errors.As(err, &tooBig) {
return newError(http.StatusRequestEntityTooLarge, "too_large",
"request body is larger than %d bytes", tooBig.Limit)
}
return newError(http.StatusBadRequest, "bad_request", "invalid request body: %v", err)
}
if dec.More() {