dotnet/aspnetcore

Regex Timeout are too short, not consistent, and not configurable in RewriteMiddleware

Aperta

#6003 aperta il 19 dic 2017

 (11 commenti) (0 reazioni) (0 assegnatari)C# (10.653 fork)batch import
affected-very-fewarea-middlewareenhancementfeature-rewrite-middlewarehelp wantedseverity-minor

Metriche repository

Star
 (37.933 stelle)
Metriche merge PR
 (Metriche PR in attesa)

Descrizione

Regex timeouts that are used across UrlRewrite, ApacheModRewrite, and code rules are not consistent. The are set at 1 second or 1 millisecond in different places. Secondly, 1 millisecond is too short for a regex expression; it should be 1 second as the timeout is mostly for making sure your server isn't locked. Also if the expression timeouts, it returns a 500 server error as the exception is unhandled. Thirdly, the timeout should be configurable in RewriteOptions.

Plan of action:

  • Timeouts should be increased to 1 second across the board.
  • For 2.1, we should make Regex timeouts configurable a
  • The timeouts should be backported to 2.0 and 1.1

@Eilon @muratg this is a patch candidate. Workarounds are very difficult.

Guida contributor