Compare commits

...
2 Commits
Author SHA1 Message Date
bircniandGitHub 300331313b docs: Adjust Changelog to include all Security relevant details (#38876)
Signed-off-by: bircni <bircni@icloud.com>
2026-08-12 11:56:51 +00:00
silverwindandGitHub f8d2d79394 fix(server): set ReadHeaderTimeout on HTTP servers (#38878)
Add `ReadHeaderTimeout` which limits how long a client can take to send HTTP headers.
2026-08-12 10:42:26 +00:00
3 changed files with 10 additions and 5 deletions
+3 -1
View File
@@ -7,7 +7,9 @@ been added to each release, please refer to the [blog](https://blog.gitea.com).
## [1.27.1](https://github.com/go-gitea/gitea/releases/tag/v1.27.1) - 2026-07-27
* SECURITY
* fix(oauth2): enforce mandatory 2FA policy on OAuth2 authorize/grant endpoints (#38591) (#38606)
* Fix: orgmode render include path (#38642) (#38645)
* Fix: git patch apply (#38637) (#38638)
* Fix(oauth2): enforce mandatory 2FA policy on OAuth2 authorize/grant endpoints (#38591) (#38606)
* API
* fix(api): align Swagger schemas for UserSettings and TopicListResponse (#38590) (#38592)
+2 -1
View File
@@ -244,7 +244,8 @@ func servePprof() {
_, _, finished := process.GetManager().AddTypedContext(context.TODO(), "Web: PProf Server", process.SystemProcessType, true)
// The pprof server is for debug purpose only, it shouldn't be exposed on public network. At the moment, it's not worth introducing a configurable option for it.
log.Info("Starting pprof server on localhost:6060")
log.Info("Stopped pprof server: %v", http.ListenAndServe("localhost:6060", mux))
server := &http.Server{Addr: "localhost:6060", Handler: mux, ReadHeaderTimeout: 10 * time.Second}
log.Info("Stopped pprof server: %v", server.ListenAndServe())
finished()
}
+5 -3
View File
@@ -8,6 +8,7 @@ import (
"crypto/tls"
"net"
"net/http"
"time"
)
func newHTTPServer(network, address, name string, handler http.Handler) (*Server, ServeFunction) {
@@ -17,9 +18,10 @@ func newHTTPServer(network, address, name string, handler http.Handler) (*Server
protocols.SetHTTP2(true) // HTTP/2 can only be used when Gitea is configured to use TLS
protocols.SetUnencryptedHTTP2(true) // Allow HTTP/2 without TLS, in case Gitea is behind a reverse proxy
httpServer := http.Server{
Protocols: &protocols,
Handler: handler,
BaseContext: func(net.Listener) context.Context { return GetManager().HammerContext() },
Protocols: &protocols,
Handler: handler,
BaseContext: func(net.Listener) context.Context { return GetManager().HammerContext() },
ReadHeaderTimeout: 10 * time.Second,
}
server.OnShutdown = func() {
httpServer.SetKeepAlivesEnabled(false)