fix: OOM protection, lock-free thumbnail cache, OIDC JWKS TTL
- Streaming WebDAV PUT: body spooled to tempfile with incremental SHA-256, peak RAM ~64KB regardless of file size (Solution 2) - RequestBodyLimitLayer (1MB) on CalDAV/CardDAV routers (Solution 3) - All body::to_bytes(body, usize::MAX) replaced with explicit limits: PROPFIND/PROPPATCH/LOCK → 1MB, MKCOL → 4KB - Added AppError::payload_too_large (HTTP 413) - Added max_upload_size to StorageConfig (default 10GB, env override) - New streaming update chain: FileWritePort::update_file_content_from_temp → FileUploadUseCase::update_file_streaming - ThumbnailService: migrated from RwLock<LruCache> to moka::future::Cache with weight-based eviction — eliminates lock contention on read hot-path - OIDC: discovery + JWKS caches now expire after 1 hour (Cached<T> wrapper) so IdP key rotation no longer requires server restart
This commit is contained in:
@@ -5,6 +5,7 @@ use std::sync::Arc;
|
||||
use axum::Router;
|
||||
use axum::extract::DefaultBodyLimit;
|
||||
use tower_http::trace::TraceLayer;
|
||||
use tower_http::limit::RequestBodyLimitLayer;
|
||||
use tracing_subscriber::{layer::SubscriberExt, util::SubscriberInitExt};
|
||||
|
||||
/// OxiCloud - Cloud Storage Platform
|
||||
@@ -106,6 +107,13 @@ async fn main() -> Result<(), Box<dyn std::error::Error>> {
|
||||
let carddav_router = carddav_handler::carddav_routes();
|
||||
let webdav_router = webdav_handler::webdav_routes();
|
||||
|
||||
// CalDAV/CardDAV only carry XML payloads — cap at 1 MB at the transport
|
||||
// level so `body::to_bytes()` cannot be abused to OOM the server.
|
||||
// WebDAV is excluded: its streaming PUT handler enforces its own per-upload
|
||||
// limit from StorageConfig::max_upload_size.
|
||||
let caldav_router = caldav_router.layer(RequestBodyLimitLayer::new(1_048_576));
|
||||
let carddav_router = carddav_router.layer(RequestBodyLimitLayer::new(1_048_576));
|
||||
|
||||
// Build WOPI routes if enabled
|
||||
use oxicloud::interfaces::api::handlers::wopi_handler;
|
||||
let wopi_routes = if config.wopi.enabled {
|
||||
|
||||
Reference in New Issue
Block a user