Bound title and language at create time (#86)
CI / test (pull_request) Successful in 21s
CI / docker (pull_request) Skipped

Titles are trimmed and truncated to 200 characters; language must be
blank or match ^[a-zA-Z0-9+#-]{1,40}$ (max 40 chars) or the create is
rejected with a clear 400. Regression tests cover truncation, malformed
and oversized language values, valid identifiers, and blank metadata.
This commit is contained in:
fen
2026-09-09 10:58:34 -05:00
parent 7ca1b58362
commit 389e4d333f
3 changed files with 217 additions and 0 deletions
+44
View File
@@ -4,6 +4,7 @@ import (
"errors"
"fmt"
"net/http"
"regexp"
"strconv"
"strings"
)
@@ -90,3 +91,46 @@ func parseBurnAfterReads(n int) error {
}
return nil
}
// #86: bounds for free-form metadata fields on create.
const (
maxTitleLen = 200
maxLanguageLen = 40
)
// languageRe restricts language to identifiers like go, c#, f#, c++, objc.
var languageRe = regexp.MustCompile(`^[a-zA-Z0-9+#-]{1,40}$`)
// checkTitle validates the paste title (#86): over-max titles are truncated
// to 200 characters so a bloated listing entry can't be stored; whitespace
// is trimmed first.
func checkTitle(title string) (string, error) {
title = strings.TrimSpace(title)
if len(title) > maxTitleLen {
return truncateRunes(title, maxTitleLen), nil
}
return title, nil
}
// checkLanguage validates the language field (#86): optional, max 40 chars,
// and must match ^[a-zA-Z0-9+#-]{1,40}$. Returns "" for absent/blank values.
// Anything else malformed is a 400.
func checkLanguage(lang string) (string, error) {
lang = strings.TrimSpace(lang)
if lang == "" {
return "", nil
}
if len(lang) > maxLanguageLen || !languageRe.MatchString(lang) {
return "", fmt.Errorf("language must match ^[a-zA-Z0-9+#-]{1,40}$ (max %d chars)", maxLanguageLen)
}
return lang, nil
}
// truncateRunes cuts s to at most max runes, keeping the prefix intact.
func truncateRunes(s string, max int) string {
runes := []rune(s)
if len(runes) <= max {
return s
}
return string(runes[:max])
}