164ac447ef5a361456a862b98ca2cdd036944422
withRequestID honored any inbound X-Request-Id verbatim, and that value is echoed on the response, embedded in the error envelope, and persisted into audit_logs.request_id. An unvalidated caller-supplied id is therefore an audit-integrity vector: an arbitrarily long value bloats the audit row, and a stray control byte (CR/LF) could smuggle a forged entry into a log sink. Accept an inbound id only when it is well-formed — non-empty, at most 64 bytes, and restricted to a log-safe charset ([A-Za-z0-9._-]) — otherwise mint a fresh server id. A rejected request loses its inbound trace link, which is strictly better than storing attacker-controlled text in the audit trail.
Languages
Go
62.7%
TypeScript
22.5%
Shell
7.4%
Java
7.1%
Dockerfile
0.2%
Other
0.1%