Repository navigation
Add HTTP method matching to resource rules - #3704
Merged
Merged
Conversation
Blacks-Army
requested review from
miloschwartz and
oschwartz10612
as code owners
September 5, 2026 09:37
Blacks-Army
force-pushed
the
feat/http-method-rules
branch
from
September 5, 2026 09:47
b7e076c to
c3e7fa7
Compare
Blacks-Army
force-pushed
the
feat/http-method-rules
branch
from
September 5, 2026 10:25
c3e7fa7 to
cfb295a
Compare
Blacks-Army
force-pushed
the
feat/http-method-rules
branch
from
September 13, 2026 10:45
cfb295a to
565c460
Compare
Contributor
Author
|
@miloschwartz Your commit "switch to lru in memory cache and dont cache failed sessions" (c792622 here, 49292ea in pangolin-node, both 2026-09-10) moved On a clean
|
oschwartz10612
force-pushed
the
dev
branch
2 times, most recently
from
September 15, 2026 14:56
a9ac442 to
c6c12f1
Compare
Resolves #1408. A rule with match "METHOD" carries a comma-separated list of HTTP methods in its value, e.g. "POST,PUT", and applies when the request method is in that list. This makes it possible to leave GET public while sending POST and PUT to auth, which rules could not express before because both share the same path. No new columns: the methods live in the existing rule value, so this needs no migration and every existing rule keeps working unchanged. The UI offers the ten registered methods. Blueprints and the API accept any method token, so extension methods such as the WebDAV verbs can be targeted too, and the UI preserves them when a rule set that way is edited later.
Blacks-Army
force-pushed
the
feat/http-method-rules
branch
from
September 19, 2026 18:02
565c460 to
8e2f9ea
Compare
Contributor
Author
|
@oschwartz10612 Rebased onto the latest Also Rebased this PR #3705 |
oschwartz10612
approved these changes
Sep 21, 2026
Member
|
Thanks! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Resolves #1408. Supersedes #2131, following the three points @oschwartz10612 asked for there: no new columns,
verifySessionkept small, rebased ontodev.Community Contribution License Agreement
By creating this pull request, I grant the project maintainers an unlimited,
perpetual license to use, modify, and redistribute these contributions under any terms they
choose, including both the AGPLv3 and the Fossorial Commercial license terms. I
represent that I have the right to grant this license for all contributed content.
AI Disclosure
Claude Code (Opus) helped me with this one, including the implementation. I set the design constraints from your review of #2131, went through every hunk myself and verified the result before opening this.
Description
A rule with match
METHODcarries a comma-separated list of HTTP methods in its value, e.g."POST,PUT", and applies when the request method is in that list. That makes it possible to leave GET public while sending POST and PUT to auth, which rules could not express before because both share the same path.No new columns: the methods live in the existing rule value, so there is no migration and every existing rule keeps working unchanged.
verifySession: oneelse ifat the end of the existing chain incheckRulesplus one short helper next to the otherisIpIn*functions. Rule processing is not split into a new file and nothing else in the hot path is restructured.METHODis added toRESOURCE_RULE_MATCH_TYPESinserver/lib/validators.ts, so every route that validates rules picks it up from there, OpenAPI enum included. Badger already sendsmethodin the verify-session payload; the field was simply unused until now.The UI offers the ten registered methods: the eight from RFC 9110 plus PATCH (RFC 5789) and QUERY (RFC 10008). Blueprints and the API accept any method token, so extension methods such as the WebDAV verbs can be targeted too, and the UI preserves them when a rule set that way is edited later. Matching is case-insensitive on both sides.
pangolin-nodecarries its own copy ofcheckRulesand needs the same change. I will open that PR next and link it here.How to test?
ACCEPT/METHOD/GET,HEAD, priority 2PASS/METHOD/POST,PUT.curlthe resource with-X GETand confirm it is served without auth.curl -X POSTthe same URL and confirm it is sent to auth.PATHorCIDRrule on another resource still behaves as before.Blueprint variant:
npx tsc --noEmitis clean andnpx tsx server/lib/validators.test.tspasses.