// SPDX-License-Identifier: Apache-2.0
// Copyright (c) 2024 Praxis Contributors
//! Pingora HTTP/2 server option builders.
//!
//! Constructs `HttpServerOptions` and `H2Options` with security
//! hardening (HPACK limits, concurrent stream bounds). Extracted from
//! `mod.rs` to keep the handler module focused on lifecycle hooks.
use ;
/// Build [`HttpServerOptions`] with h2c enabled.
///
/// [`HttpServerOptions`]: pingora_core::apps::HttpServerOptions
pub
/// Build [`H2Options`] with limits to mitigate HPACK amplification attacks
/// (CWE-409).
///
/// Without explicit limits the `h2` crate defaults allow unbounded header
/// list sizes and concurrent streams, enabling a small compressed request
/// to allocate hundreds of megabytes on the server.
///
/// [`H2Options`]: pingora_core::protocols::http::v2::server::H2Options
pub