fix: reject line breaks in frontmatter header values; note reference-impl limits
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
parent
864daa0bad
commit
43e4be2b8a
3 changed files with 27 additions and 1 deletions
12
smolmaild.py
12
smolmaild.py
|
|
@ -411,7 +411,13 @@ class Store:
|
|||
|
||||
|
||||
class RateLimiter:
|
||||
"""Fixed-window counter, keyed by IP address or by accept token (§10)."""
|
||||
"""Fixed-window counter, keyed by IP address or by accept token (§10).
|
||||
|
||||
A fixed window admits up to 2x the limit across a window boundary (a burst
|
||||
at the end of one window plus a burst at the start of the next). Acceptable
|
||||
for a reference server; a production limiter should use a sliding window or
|
||||
token bucket.
|
||||
"""
|
||||
|
||||
def __init__(self, limit: int, window: float = 60.0) -> None:
|
||||
self.limit = limit
|
||||
|
|
@ -776,6 +782,10 @@ def static_public(static_key: bytes) -> bytes:
|
|||
|
||||
|
||||
class MailServer(socketserver.ThreadingTCPServer):
|
||||
# One thread per connection with no concurrency cap: only conn_limiter (per
|
||||
# IP) bounds it, so a distributed connection flood can exhaust threads. The
|
||||
# Reticulum server caps links (§13.8); a production TCP server should bound
|
||||
# workers likewise, e.g. a thread pool or a max-connections gate.
|
||||
allow_reuse_address = True
|
||||
daemon_threads = True
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue