tree b5c39fbb7d66ad9134a4f0fcecaa12c9346c5752
parent e7808c93f01081ca12e1b4769691b5ae673f9017
author James Feist <james.feist@linux.intel.com> 1585936735 -0700
committer James Feist <james.feist@linux.intel.com> 1594861375 +0000

Rework Authorization flow

Currently we parse the whole message before authenticating,
allowing an attacker the ability to upload a large image,
or keep a connection open for the max amount of time easier
than it should be. This moves the authentication to the
earliest point possible, and restricts unauthenticated users
timeouts and max upload sizes. It also makes it so that
unauthenticated users cannot keep the connection alive
forever by refusing to close the connection.

Tested:
- login/logout
- firmware update
- large POST when unauthenticated
- timeouts when unauthenticated
- slowhttptest

Change-Id: Ifa02d8db04eac1821e8950eb85e71634a9e6d265
Signed-off-by: James Feist <james.feist@linux.intel.com>
