- Blocker 1: move publishLocked inside job.mu to eliminate SSE duplicate-event
race between replay and live subscription
- Blocker 2: add http.MaxBytesReader (1 MB) to startTraversal to prevent
memory exhaustion from large request bodies
- Should Fix 1: thread context.Context into newHandler() and cancel it on
Server.Shutdown() to stop the ticker goroutine cleanly
- Should Fix 2: add unsubscribe() method and defer it in streamTraversal
so disconnected SSE clients don't accumulate stale channels
- Suggestion: add ReadHeaderTimeout: 10s to http.Server to mitigate Slowloris
All tests pass: go test -race ./... and go vet ./... both clean.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: multica-agent <github@multica.ai>