dotnet/aspnetcore

Regex Timeout are too short, not consistent, and not configurable in RewriteMiddleware

开放

#6,003 创建于 2017年12月19日

 (11 条评论) (0 个反应) (0 位负责人)C# (10,653 个派生)batch import
affected-very-fewarea-middlewareenhancementfeature-rewrite-middlewarehelp wantedseverity-minor

仓库指标

星标
 (37,933 个星标)
PR 合并指标
 (PR 指标待抓取)

描述

Regex timeouts that are used across UrlRewrite, ApacheModRewrite, and code rules are not consistent. The are set at 1 second or 1 millisecond in different places. Secondly, 1 millisecond is too short for a regex expression; it should be 1 second as the timeout is mostly for making sure your server isn't locked. Also if the expression timeouts, it returns a 500 server error as the exception is unhandled. Thirdly, the timeout should be configurable in RewriteOptions.

Plan of action:

  • Timeouts should be increased to 1 second across the board.
  • For 2.1, we should make Regex timeouts configurable a
  • The timeouts should be backported to 2.0 and 1.1

@Eilon @muratg this is a patch candidate. Workarounds are very difficult.

贡献者指南