Files
Oxicloud/.gitignore
T
Edouard Vanbelle 5e638691ad security(upload): cap upload size to prevent memody/disk consumption
add OXICLOUD_CHUNK_MAX_BYTES which correspond to the max upload chunk allowed
    (differs from OXICLOUD_MAX_UPLOAD_SIZE which is the max total size of a file)
    hurl test validate the change

    Streams the request body straight to the chunk file with peak heap of
    ~one HTTP frame, regardless of chunk size or the configured cap. The
    `storage.chunk_max_bytes` config (env `OXICLOUD_CHUNK_MAX_BYTES`,
    default 100 MB) bounds a single PUT — separate from `max_upload_size`
    which governs whole-file uploads. Without this separation, a client
    could submit a chunk up to the whole-file cap (10 GB default) and
    monopolise server memory.
2026-06-09 09:26:33 +02:00

103 lines
1.7 KiB
Plaintext

# Generated by Cargo
/target/
**/target/
# Processed static assets (generated by build.rs in release mode)
/static-dist/
# Remove Cargo.lock from gitignore if creating an executable, leave it for libraries
# More information here https://doc.rust-lang.org/cargo/guide/cargo-toml-vs-cargo-lock.html
# Cargo.lock
# These are backup files generated by rustfmt
**/*.rs.bk
# MSVC Windows builds of rustc generate these, which store debugging information
*.pdb
# Rust debug symbols
*.dSYM/
*.su
*.idb
# Build cache (keep .cargo/config.toml for project build settings, keep audit config)
.cargo/*
!.cargo/config.toml
!.cargo/audit.toml
# temporary file to tools
tmp/
# Visual Studio Code directory
.vscode/
# JetBrains IDEs
.idea/
# MacOS specific
.DS_Store
.AppleDouble
.LSOverride
# Linux specific
*~
.directory
.Trash-*
# Windows specific
Thumbs.db
ehthumbs.db
Desktop.ini
# Node.js (if used for frontend)
node_modules/
npm-debug.log
# Environment variables
.env
.env.local
.env.development.local
.env.test.local
.env.production.local
# Docker Compose local overrides (e.g. dev-only bind mounts)
docker-compose.override.yml
# Log files
*.log
logs/
# Storage data (user files, blobs — never commit)
storage/
# TLS certificates and private keys — NEVER commit
*.pem
*.key
*.p12
*.pfx
*.crt
*.csr
# Temporary files
*.tmp
*.bak
*.swp
*.swo
nohup.out
# Generated files (OpenAPI spec, etc.)
resources/gen/
# Helm chart dependencies
charts/*/charts/*
# Playwright
tests/e2e/node_modules/
tests/e2e/test-results/
tests/e2e/blob-report/
tests/e2e/playwright/.cache/
tests/e2e/playwright/.auth/
# Test fixtures generated on-the-fly by tests/api/run.sh
tests/fixtures/chunk-over-cap-*.bin