Repository navigation
5.0.0: instance-based App, POST defaults to 200, JUnit 5 - #53
Merged
Merged
Conversation
Security: - Exact routes were looked up by the decoded path, so /admin%2Fsecret reached the /admin/secret route. Skip exact lookup (and Allow reporting) when the raw path contains an encoded slash. Multipart: - Rewrite MultipartParser: read the body as it arrives up to the limit instead of reserving Content-Length bytes up front, parse part headers properly (any order/case, extra headers, missing Content-Type, preamble, transport padding, quoted params), accept chunked uploads. - Oversized bodies throw the new ContentTooLargeException; a missing boundary or unsupported charset is a ParseException instead of an IllegalArgumentException. MultipartFilter answers 413 / 400 rather than a 500. - Default charset is now UTF-8, matching what browsers send. Router and server: - Log unhandled handler errors via System.Logger before sending 500. - Add Server.stop(Duration) / Turismo.stop(Duration) for graceful stop. - Validate route() arguments (non-null, path starts with '/') and notFound(null). - toJson supports Character, enums, records and every array type. - PathPattern returns unmodifiable maps as documented. Servlet resolvers: - ListResolver/MapResolver serve HEAD from GET routes and answer wrong-method requests with 405 + Allow, like the embedded server. Adds tests for all of the above, including the first multipart tests. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Leqha458EwWbRT5xWiVuyg
App: - Routes, the not-found handler and the embedded server now live in an App instance, so several route sets can coexist in one JVM and tests can use a fresh app instead of resetting shared state. - Turismo's static registration and server methods delegate to a shared default app (Turismo.app()), so existing code is unchanged. Request and response helpers stay static and work for whichever app serves the request; nested dispatch restores the outer request context. - Server gains a Server(App, int) constructor; Server(int) serves the default app. POST status (breaking): - post() and @post no longer force 201; every route defaults to 200 and handlers call status(201) when they create something. Tests: - Migrate from JUnit 4.13.2 to JUnit Jupiter 6.1.3 (the current JUnit 5 programming model): lifecycle annotations, assertThrows instead of @test(expected), message-last assertion arguments. - Add AppTest covering isolation, per-app not-found/reset, nested dispatch and two apps serving on separate ports. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Leqha458EwWbRT5xWiVuyg
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Leqha458EwWbRT5xWiVuyg
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Leqha458EwWbRT5xWiVuyg
ghosthack
pushed a commit
that referenced
this pull request
Sep 27, 2026
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Leqha458EwWbRT5xWiVuyg
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #52. Breaking release: bumps the version to 5.0.0.
Summary
Instance-based
AppAppinstance. Several apps can run in one JVM, and a test can build a fresh app instead of resetting global state.Turismo.get()/start()/ … API delegates to a shared default app (Turismo.app()), so existing code compiles and behaves as before.param(),print(),json(), …) stay static and work inside any app's handlers. When one app dispatches to another from inside a handler, the outer request context is restored afterwards.Server(App, int)constructor;Server(int)serves the default app.POST defaults to 200 (breaking)
post()and@POSTno longer force201; every route defaults to200. Handlers callstatus(201)when they create something.Tests: JUnit 4 → JUnit Jupiter 6.1.3
assertThrowsinstead of@Test(expected), and assertion messages moved to the last argument.AppTest: isolation between apps and the default app, per-app not-found and reset, nested dispatch, two apps serving on separate ports.Version 5.0.0
pom.xmland README install snippets bumped to5.0.0.Notes
masterbecause Refactor multipart parser and improve routing/JSON serialization #52 was squash-merged. The squashed commit's tree is identical to the original, so the diff againstmastercontains only the changes above.v5.0.0onmaster; the release workflow checks the tag againstpom.xml.Testing
mvn verify: 190 tests pass, javadoc builds, and 5.0.0 artifacts are produced.🤖 Generated with Claude Code
https://claude.ai/code/session_01Leqha458EwWbRT5xWiVuyg
Generated by Claude Code