dotnet/aspnetcore

Regex Timeout are too short, not consistent, and not configurable in RewriteMiddleware

オープン

#6,003 opened on 2017/12/19

 (11 件のコメント) (0 件のリアクション) (0 人の担当者)C# (10,653 件のフォーク)batch import
affected-very-fewarea-middlewareenhancementfeature-rewrite-middlewarehelp wantedseverity-minor

Repository metrics

Stars
 (37,933 個のスター)
PR merge metrics
 (PR metrics pending)

説明

Regex timeouts that are used across UrlRewrite, ApacheModRewrite, and code rules are not consistent. The are set at 1 second or 1 millisecond in different places. Secondly, 1 millisecond is too short for a regex expression; it should be 1 second as the timeout is mostly for making sure your server isn't locked. Also if the expression timeouts, it returns a 500 server error as the exception is unhandled. Thirdly, the timeout should be configurable in RewriteOptions.

Plan of action:

  • Timeouts should be increased to 1 second across the board.
  • For 2.1, we should make Regex timeouts configurable a
  • The timeouts should be backported to 2.0 and 1.1

@Eilon @muratg this is a patch candidate. Workarounds are very difficult.

コントリビューターガイド