mirror of
https://github.com/go-gitea/gitea.git
synced 2026-08-13 11:01:01 +00:00
f8d2d79394
Add `ReadHeaderTimeout` which limits how long a client can take to send HTTP headers.
45 lines
1.7 KiB
Go
45 lines
1.7 KiB
Go
// Copyright 2019 The Gitea Authors. All rights reserved.
|
|
// SPDX-License-Identifier: MIT
|
|
|
|
package graceful
|
|
|
|
import (
|
|
"context"
|
|
"crypto/tls"
|
|
"net"
|
|
"net/http"
|
|
"time"
|
|
)
|
|
|
|
func newHTTPServer(network, address, name string, handler http.Handler) (*Server, ServeFunction) {
|
|
server := NewServer(network, address, name)
|
|
protocols := http.Protocols{}
|
|
protocols.SetHTTP1(true)
|
|
protocols.SetHTTP2(true) // HTTP/2 can only be used when Gitea is configured to use TLS
|
|
protocols.SetUnencryptedHTTP2(true) // Allow HTTP/2 without TLS, in case Gitea is behind a reverse proxy
|
|
httpServer := http.Server{
|
|
Protocols: &protocols,
|
|
Handler: handler,
|
|
BaseContext: func(net.Listener) context.Context { return GetManager().HammerContext() },
|
|
ReadHeaderTimeout: 10 * time.Second,
|
|
}
|
|
server.OnShutdown = func() {
|
|
httpServer.SetKeepAlivesEnabled(false)
|
|
}
|
|
return server, httpServer.Serve
|
|
}
|
|
|
|
// HTTPListenAndServe listens on the provided network address and then calls Serve
|
|
// to handle requests on incoming connections.
|
|
func HTTPListenAndServe(network, address, name string, handler http.Handler, useProxyProtocol bool) error {
|
|
server, lHandler := newHTTPServer(network, address, name, handler)
|
|
return server.ListenAndServe(lHandler, useProxyProtocol)
|
|
}
|
|
|
|
// HTTPListenAndServeTLSConfig listens on the provided network address and then calls Serve
|
|
// to handle requests on incoming connections.
|
|
func HTTPListenAndServeTLSConfig(network, address, name string, tlsConfig *tls.Config, handler http.Handler, useProxyProtocol, proxyProtocolTLSBridging bool) error {
|
|
server, lHandler := newHTTPServer(network, address, name, handler)
|
|
return server.ListenAndServeTLSConfig(tlsConfig, lHandler, useProxyProtocol, proxyProtocolTLSBridging)
|
|
}
|