Repository navigation
Refactor multipart parser and improve routing/JSON serialization - #52
Merged
Merged
Conversation
Security: - Exact routes were looked up by the decoded path, so /admin%2Fsecret reached the /admin/secret route. Skip exact lookup (and Allow reporting) when the raw path contains an encoded slash. Multipart: - Rewrite MultipartParser: read the body as it arrives up to the limit instead of reserving Content-Length bytes up front, parse part headers properly (any order/case, extra headers, missing Content-Type, preamble, transport padding, quoted params), accept chunked uploads. - Oversized bodies throw the new ContentTooLargeException; a missing boundary or unsupported charset is a ParseException instead of an IllegalArgumentException. MultipartFilter answers 413 / 400 rather than a 500. - Default charset is now UTF-8, matching what browsers send. Router and server: - Log unhandled handler errors via System.Logger before sending 500. - Add Server.stop(Duration) / Turismo.stop(Duration) for graceful stop. - Validate route() arguments (non-null, path starts with '/') and notFound(null). - toJson supports Character, enums, records and every array type. - PathPattern returns unmodifiable maps as documented. Servlet resolvers: - ListResolver/MapResolver serve HEAD from GET routes and answer wrong-method requests with 405 + Allow, like the embedded server. Adds tests for all of the above, including the first multipart tests. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Leqha458EwWbRT5xWiVuyg
ghosthack
pushed a commit
that referenced
this pull request
Sep 27, 2026
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Leqha458EwWbRT5xWiVuyg
This was referenced Sep 27, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR significantly refactors the multipart form data parser for better correctness and maintainability, improves HTTP routing with proper 405 Method Not Allowed responses, enhances JSON serialization to support records and enums, and adds graceful server shutdown.
Key Changes
Multipart Parser Refactoring
Complete rewrite of
MultipartParserto use a simpler, more correct algorithm:maxContentSize) instead of streaming with complex buffer managementByteBufferandCharsetDecoderin favor of straightforward byte array operationsContentTooLargeExceptionfor bodies exceeding the size limitHeader parsing improvements:
Content-DispositionandContent-TypeheadersComprehensive test suite added (
MultipartParserTest) covering:HTTP Routing Improvements
Allowheader instead of 404%2F(encoded slash) doesn't match path segments in exact routes (e.g.,/admin%2Fsecretwon't match/admin/secret)PathPattern.match()now returns unmodifiable maps to prevent accidental mutationsJSON Serialization Enhancements
Charactertype is now serialized as a JSON stringArray.get()for all primitive and object arrays, eliminating code duplicationServer Improvements
stop(Duration grace)method that:Documentation Updates
Implementation Details
dispatch()method inMethodPathResolverprovides a reusable pattern for implementing 405 responses and HEAD fallbackhttps://claude.ai/code/session_01Leqha458EwWbRT5xWiVuyg