c6c0772a7a028100fd85641bdd62e30c7980acc3
The three felis-api http.Servers (internal, external, https) were built with only Addr and Handler, leaving ReadHeaderTimeout, IdleTimeout, and ReadTimeout at zero. A zero ReadHeaderTimeout is a Slowloris hole — a client trickling header bytes pins a connection indefinitely — and a zero IdleTimeout lets kept-alive connections accumulate (gosec G112). Route all three listeners through a newAPIServer factory that sets a 10s ReadHeaderTimeout and a 120s IdleTimeout. WriteTimeout and ReadTimeout are left unset on purpose: the external and https faces stream Server-Sent Events (console / build logs) for the lifetime of a client attachment, and a WriteTimeout would sever a healthy long-lived stream. Slowloris is closed by ReadHeaderTimeout, which bounds only the header phase.
Languages
Go
62.7%
TypeScript
22.5%
Shell
7.4%
Java
7.1%
Dockerfile
0.2%
Other
0.1%