fix: cap request bodies, link login error, add book-form retry, guard double add
Limit request bodies to 1 MiB (413 JSON), wire aria-describedby on the login form, add Retry and cancellation to the book form load, disable Add entry while a note POST is in flight, and poll pg_isready in README. Claude-Session: https://claude.ai/code/session_01M9MLit5Ko3X4s7rzC5Kv7X
This commit is contained in:
@@ -18,6 +18,9 @@ MUTATING_METHODS = {"POST", "PUT", "PATCH", "DELETE"}
|
||||
def create_app() -> Flask:
|
||||
logging.basicConfig(level=logging.INFO, format="%(asctime)s %(levelname)s %(name)s: %(message)s")
|
||||
app = Flask(__name__)
|
||||
# Werkzeug buffers and parses the whole body before our validation runs, so unauthenticated
|
||||
# callers could exhaust memory; 1 MiB is far above the largest legitimate payload (10,000-char note).
|
||||
app.config["MAX_CONTENT_LENGTH"] = 1024 * 1024
|
||||
db.init_app(app)
|
||||
auth.init_app(app)
|
||||
app.register_blueprint(books.bp)
|
||||
|
||||
Reference in New Issue
Block a user