mirror of
https://github.com/livekit/livekit.git
synced 2026-09-15 23:56:10 +00:00
The front was mounted on the API mux and served through the API middleware chain, which is shaped for handlers that buffer a request and write one response. Four consequences. negroni.NewRecovery() recovers every panic with no http.ErrAbortHandler exemption, and NewRecovery sets PrintStack. On an abort it wrote "PANIC: ..." and a goroutine stack into the already-committed body, then returned normally, so net/http terminated the chunked stream cleanly. A truncated response reached the client as complete, with a stack trace appended. Detection was already correct; delivery was not, and the x-lk- trailers that would otherwise signal it are stripped before the response leaves. A Content-Length response still failed safe, since net/http enforces the declared length itself, so the gap was the chunked and trailer paths. Endpoints.Disabled documents that it turns the front off, but only registrations were refused; the mount was unconditional. The CORS method list omits PUT, which a manifest may declare. The API body limiter capped request bodies at MaxAPIRequestBodySize, though the front streams a body through a pooled buffer and never holds one. NewHTTPHandler now routes the prefix to a chain carrying AgentRecovery, a CORS list matching the methods a manifest may declare, and the api-key auth middleware the front resolves a caller's access from. The mount is built only when endpoints are enabled, so the prefix otherwise falls through and 404s. RemoveDoubleSlashes moves above the split, so routing and both chains see one path form. Taking the front off the mux also stops ServeMux rewriting the paths it is handed: "//x", "/../" and interior "//" were answered with a redirect rather than proxied, which a byte-transparent exchange cannot do. The endpoint stack tests now build the production handler, so they run on the chain the node serves on.