Skip to content

docs: a Host carrying a slash is not refused - #164

Merged
KyleJune merged 1 commit into
mainfrom
docs/host-slash-not-refused
Sep 25, 2026
Merged

KyleJune merged 1 commit into
mainfrom
docs/host-slash-not-refused

Conversation

@KyleJune

Copy link
Copy Markdown
Member

Summary

This corrects the claim that #163 added to the createServer JSDoc, the isUnresolvedPath JSDoc and docs/middleware.md. A Host header carrying / is not refused. Deno.serve builds a URL such as http://localhost/docs/identity, whose raw path and URL.pathname agree, so both routers route the same path. Only a Host carrying ? or \ shifts the parsed path and is refused.

This was measured from udibo over a raw socket. Host: localhost/docs with GET /identity returned 200 from /docs/identity, while Host: localhost?x and Host: localhost\x returned 400 (pinned in udibo's routes/path-normalization.test.ts, udibo/udibo#1540).

Changes

  • src/server.tsx: both JSDoc blocks now say "? or \" and state that a Host carrying / is not refused.
  • docs/middleware.md: the same correction.

Testing

Documentation only. deno task check passes (doc-lint clean), and deno task test --parallel --reporter=dot gives 60 passed, 0 failed.

Closes

Nothing.

🤖 Generated with Claude Code

The path check compares the raw path in request.url with URL.pathname.
When Host carries "/", Deno.serve builds a URL such as
http://localhost/docs/identity whose raw and parsed paths agree, so the
request is not refused and both routers route the same path. Only a
Host carrying "?" or "\" shifts the path and is refused.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@KyleJune
KyleJune merged commit aced4f2 into main Sep 25, 2026
10 checks passed
@KyleJune
KyleJune deleted the docs/host-slash-not-refused branch September 25, 2026 06:12
@github-actions

Copy link
Copy Markdown

🎉 This PR is included in version 0.17.2 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant