docs: clarify that MAX_PAGES_PER_CHAPTER=0 relies on the body-size backstop
Make explicit (config.rs + .env.example) that disabling the per-chapter page cap leaves MAX_REQUEST_BYTES as the sole bound (audit footgun). No behavior change; the thumbnail-source read is already bounded by MAX_FILE_BYTES + decode limits. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -118,8 +118,10 @@ MAX_REQUEST_BYTES=209715200
|
|||||||
MAX_FILE_BYTES=20971520
|
MAX_FILE_BYTES=20971520
|
||||||
# Max page images accepted in one chapter upload. Bounds how many parts
|
# Max page images accepted in one chapter upload. Bounds how many parts
|
||||||
# the handler will stage before rejecting the request with 413, so a
|
# the handler will stage before rejecting the request with 413, so a
|
||||||
# client can't pin a worker with an unbounded page count. 0 disables the
|
# client can't pin a worker with an unbounded page count. Default 2000.
|
||||||
# cap. Default 2000.
|
# Setting 0 disables THIS cap — the total is then bounded only by
|
||||||
|
# MAX_REQUEST_BYTES (the whole-request body limit above), so leave 0 only
|
||||||
|
# if you intend that body limit to be the sole backstop.
|
||||||
MAX_PAGES_PER_CHAPTER=2000
|
MAX_PAGES_PER_CHAPTER=2000
|
||||||
|
|
||||||
# ----- Crawler download safety -----
|
# ----- Crawler download safety -----
|
||||||
|
|||||||
@@ -66,8 +66,10 @@ pub struct UploadConfig {
|
|||||||
pub max_file_bytes: usize,
|
pub max_file_bytes: usize,
|
||||||
/// Max page images accepted in one chapter upload. Bounds how many
|
/// Max page images accepted in one chapter upload. Bounds how many
|
||||||
/// parts the handler will stage before giving up, so a client can't
|
/// parts the handler will stage before giving up, so a client can't
|
||||||
/// pin a worker streaming an unbounded page count. `0` disables the
|
/// pin a worker streaming an unbounded page count. `0` disables THIS
|
||||||
/// cap. Defaults to 2000. `MAX_PAGES_PER_CHAPTER`.
|
/// cap — the total is then bounded only by `max_request_bytes` (the
|
||||||
|
/// whole-request body limit), which stays the backstop either way.
|
||||||
|
/// Defaults to 2000. `MAX_PAGES_PER_CHAPTER`.
|
||||||
pub max_pages_per_chapter: usize,
|
pub max_pages_per_chapter: usize,
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user