4 ms·
So now an unreasonable user input will crash my server instead of slowing it down by 50ms. Great DoS mitigation!
by svet_0 4y ago
So now an unreasonable user input will crash my server instead of slowing it down by 50ms. Great DoS mitigation!
- omnicognate 4y agoYour server crashes if a request fails?
- xani_ 4y agoit does with this change where it didn't before. At the very best you're still restarting the whole process instead of just wasting a bit of time
- aYsY4dDQ2NrcNzA 4y agoThen don’t upgrade Python in your container?
- progval 4y agoYou should always catch ValueError when using int() on user input, because that input may not be a valid number.
- deleted 4y ago[deleted]
- mattnewton 4y agoI should also check to see if the length is reasonable, no? But the whole point of the issue is that nobody finds that practical.
- fuckstick 4y agoWho uses a process per request for serving Python apps? That must be very uncommon. Even if you use a worker pool that isn’t going to restart a whole process just because of an errant exception in a request handler. Also as noted if your whole process crashes because of errant input to int() you are beyond fucked in other ways.
- Ukv 4y agoIn addition to omnicognate's point, calling `int` on user input would generally already expect a possible ValueError.
- aidenn0 4y agoThere are inputs that can slow it down by hours. Maybe the set the limit too low. Maybe they should have instead merged the PR that improves the speed by a huge amount. They didn't.