A request that takes longer than eight seconds gets no answer, because the server's write timeout runs out before the request timeout #208
Open
opened 2026-10-09 16:03:03 +00:00 by cgalo5758
·
0 comments
Labels
Clear labels
accessibility
area/billing
area/catalog
area/discourse
area/domains
area/entitlements
area/fedwiki
area/identity
area/integrations
area/licensing
area/member-ui
area/meta
area/operator-ui
area/ops
area/testing
duplicate
good-first-issue
invalid
privacy
security
upstream
wontfix
A barrier for people using assistive technology or a keyboard alone.
The Stripe mirror, checkout, subscriptions, invoices, fulfillment.
Products, prices, plan ladders, purchasability.
The Discourse integration.
The domains registry, claims, placements, the certificate ask.
Entitlement sets, rules, grants, pools, provisioning.
The Federated Wiki integration and farm sync.
Sign-in, sessions, persons, organizations, workspaces, roles.
The provider registry, outbox and webhooks in general.
Licenses, the contributor agreement, SPDX headers.
Member pages.
The repository itself, its contributing guide, CI, the tracker and the workflow.
Operator pages, forms, lists, the design system.
Deployment, configuration, migrations, workflows, instance settings.
The test stack, screens, lint, walkthroughs.
Closed because another issue already covers it.
Small, self-contained, and explained enough to be a first contribution.
Closed because it is not a ticket for this repository.
Touches what a person's data reveals.
Touches authentication, authorization, secrets or data exposure.
Waits on another repository or project before it can move.
Closed because it will not be done, with the reason in the last comment.
kind
bug
The software does something other than what it promises; closed when it again does what it promises.
kind
debt
Code, tests or tooling to clean up with nothing visible changing; closed when they are cleaner.
kind
design
A question to settle before work can be defined; closed when the decision is written down.
kind
docs
Documentation that is wrong or missing; closed when it says the right thing.
kind
enhancement
Something the software does not do yet; closed when it does.
priority
critical
Blocks the active milestone or harms members now.
priority
high
Next in line inside the active milestone.
priority
low
Inside the active milestone, when nothing else is left.
priority
medium
Inside the active milestone, after the high ones.
Milestone
No items
No Milestone
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: wiki-cafe/member-console#208
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
What happens
Startininternal/server/server.gobuilds thehttp.ServerwithWriteTimeout: 8 * time.Secondand puts every request throughmiddleware.Timeout(32*time.Second). Go sets the connection's write deadline eight seconds after it reads the request's headers. The request timeout ishttp.TimeoutHandler. It holds the handler's response in a buffer and writes it only when the handler returns, or it writes its own 503 "Request timed out" at 32 seconds.So when a handler runs past eight seconds, its work still finishes, but writing its answer fails and the server closes the connection. The person waits the whole time and gets no response from the console. Instead, the proxy in front shows its own gateway error, or the browser reports a dropped connection. The 503 that the request timeout writes at 32 seconds runs into the same expired deadline, so it never reaches anyone either. Nothing stops the handler at eight seconds: it keeps running until it returns, and its context is cancelled only at 32 seconds.
Two kinds of handler can run past eight seconds today:
internal/fulfillment/plan_change.go). Each call uses the Stripe library's defaults: an 80-second timeout and two retries. When Stripe is slow, the change can go through while the member sees an error.workflowStartTimeoutininternal/integrations/fedwiki/web/requests.go). When Temporal is slow, the console records the request and starts the workflow, but the member never gets the answer.Timeout's doc comment says the client gets a 503 once the deadline passes, andopenspec/specs/http-security-headers/spec.mdrequires that 503 to carry the security headers. The test of that 503 ininternal/middleware/tests/security_headers_test.gowrites to a recorder that has no write deadline, so it passes.What should happen
The request timeout fires before the write timeout. A request that runs too long gets the 503 "Request timed out" with the security headers, and the write timeout only catches a client that is too slow to read the answer. Either the request timeout comes down below eight seconds, or the write timeout goes above 32 with room left to write the 503.
Where
internal/server/server.go(Start: thehttp.ServerandpreAuthStack);internal/middleware/timeout.go(Timeout).Steps
Add
time.Sleep(9 * time.Second)to any handler, run the console, and request that path directly withcurl -v. After nine seconds curl reports "Empty reply from server". With a 40-second sleep you get the same empty reply at 32 seconds, which is when the 503 should arrive.Why it matters
When Stripe, Temporal or the database slows a request past eight seconds, the console sends no answer at all, even if the work was done, and its "Request timed out" response is never seen.