Skip to content

fix: 并发上限、注入与请求竞态加固 - #24

Merged
hstarorg merged 1 commit into
mainfrom
dev
Jun 10, 2026
Merged

hstarorg merged 1 commit into
mainfrom
dev

Conversation

@hstarorg

@hstarorg hstarorg commented Jun 10, 2026 •

Copy link
Copy Markdown
Contributor

Code-review 修复,共 4 处:

  • ci: inputs.tag 改走 env 传入 shell,消除 workflow_dispatch 脚本注入
  • registry: TagDetails 的子 manifest 抓取加独立信号量,总并发封顶 12+12(原为 12 × 推送者可控的条目数)
  • webhook: 请求体加 1 MiB 上限,超限按 400 处理
  • auth: /me 加请求序号守卫,晚到的响应不再覆盖 login/logout 后的状态

验证:go build/vet/test -race、tsc、eslint、vitest 23/23、actionlint 全绿。

- Prevent command injection in CI tag input via env indirection
- Add separate child semaphore to avoid deadlock in TagDetails
- Cap webhook body reads at 1 MiB to prevent unbounded allocation
- Add request-sequence token to CurrentUserViewModel to prevent stale /me from overwriting fresher auth state
@hstarorg hstarorg changed the title Dev fix: 并发上限、注入与请求竞态加固 Jun 10, 2026
@hstarorg
hstarorg merged commit 9817079 into main Jun 10, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant