fix(server): set ReadHeaderTimeout on HTTP servers (#38878)

Add `ReadHeaderTimeout` which limits how long a client can take to send HTTP headers.
This commit is contained in:
silverwind
2026-08-12 12:42:26 +02:00
committed by GitHub
parent 9b24e8c76d
commit f8d2d79394
2 changed files with 7 additions and 4 deletions
+2 -1
View File
@@ -244,7 +244,8 @@ func servePprof() {
_, _, finished := process.GetManager().AddTypedContext(context.TODO(), "Web: PProf Server", process.SystemProcessType, true)
// The pprof server is for debug purpose only, it shouldn't be exposed on public network. At the moment, it's not worth introducing a configurable option for it.
log.Info("Starting pprof server on localhost:6060")
log.Info("Stopped pprof server: %v", http.ListenAndServe("localhost:6060", mux))
server := &http.Server{Addr: "localhost:6060", Handler: mux, ReadHeaderTimeout: 10 * time.Second}
log.Info("Stopped pprof server: %v", server.ListenAndServe())
finished()
}
+5 -3
View File
@@ -8,6 +8,7 @@ import (
"crypto/tls"
"net"
"net/http"
"time"
)
func newHTTPServer(network, address, name string, handler http.Handler) (*Server, ServeFunction) {
@@ -17,9 +18,10 @@ func newHTTPServer(network, address, name string, handler http.Handler) (*Server
protocols.SetHTTP2(true) // HTTP/2 can only be used when Gitea is configured to use TLS
protocols.SetUnencryptedHTTP2(true) // Allow HTTP/2 without TLS, in case Gitea is behind a reverse proxy
httpServer := http.Server{
Protocols: &protocols,
Handler: handler,
BaseContext: func(net.Listener) context.Context { return GetManager().HammerContext() },
Protocols: &protocols,
Handler: handler,
BaseContext: func(net.Listener) context.Context { return GetManager().HammerContext() },
ReadHeaderTimeout: 10 * time.Second,
}
server.OnShutdown = func() {
httpServer.SetKeepAlivesEnabled(false)