feat(OXICLOUD_DIRECT_PUT_MAX_BYTES): add a security limit on direct PUT

ensure files does not exeed OXICLOUD_MAX_UPLOAD_SIZE, prefer to deny from header rather consuming bandwidth
    add OXICLOUD_DIRECT_PUT_MAX_BYTES for direct PUT (non chunked), admins can fine tune their prefered values
This commit is contained in:
Edouard Vanbelle
2026-06-09 11:00:51 +02:00
parent 4e36de49eb
commit 50ea406719
11 changed files with 282 additions and 44 deletions
+8
View File
@@ -27,6 +27,14 @@ RUST_LOG="warn,audit=info"
# under the cap, while the cap test sends a 5 MiB fixture to trigger 413.
OXICLOUD_CHUNK_MAX_BYTES=4194304
# Direct-PUT (non-chunked) cap, exercised by chunked_upload_cap.hurl.
# 4 MiB: same threshold as the chunked cap so the existing 5 MiB
# fixture (chunk-over-cap-5mb.bin) can prove BOTH caps with one
# generated file. All existing direct-PUT tests
# (test_dedup_webdav_multichunk.sh = 2.76 MB, _ref_count = ~66 KB,
# _nextcloud_put_blake3 = 32 B) stay safely under this cap.
OXICLOUD_DIRECT_PUT_MAX_BYTES=4194304
# grow up limits for tests
OXICLOUD_RATE_LIMIT_REFRESH_MAX=360
OXICLOUD_RATE_LIMIT_LOGIN_MAX=360