fix(routing): wildcard *path params never get schema-lite type coercion - #234
Merged
Merged
Conversation
Every path param value, including a `*name` catch-all capturing an
arbitrary sub-path, went through the same int/float/bool schema-lite
coercion as a single-segment `:name` param. This broke StaticFiles
(mounted via app.mount(...) with a `*path` wildcard) on any file whose
name looked numeric or boolean: e.g. GET /static/42 arrived at the
handler as an int, and int has no .split("/"), so the route 500'd.
It also silently mistyped ownership/auth checks comparing a wildcard
path segment against a string ID.
Track which path param names come from a `*name` catch-all at route-
registration time (RouteExtra::wildcard_params) and skip coercion for
just those params at dispatch time. Single-segment `:name` coercion
(fully covered by the existing test_path_param_coercion.py suite) is
unchanged.
Closes #212
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Every path param value — including a
*namecatch-all capturing an arbitrary sub-path — went through the same int/float/bool schema-lite coercion as a single-segment:nameparam (value_for_path_param,src/params.rs).This broke
StaticFiles(mounted viaapp.mount(...), which registers a*pathwildcard route) on any file whose name looked numeric or boolean:GET /static/42arrived at the handler asint, andinthas no.split("/"), so the route 500'd. It also silently mistyped ownership/auth checks comparing a wildcard path segment against a string ID.Fix
I deliberately scoped this to the wildcard case, not a redesign of path-param coercion in general: the single-segment
:namecoercion is an existing, documented, thoroughly-tested feature (tests/test_path_param_coercion.py,docs/) with real intentional use, so changing its default behavior would be a much larger, riskier API change out of proportion to this bug.RouteExtra::wildcard_params: the set of param names captured by a*namecatch-all, computed once atadd_routetime from the path template.strunconditionally, skippingvalue_for_path_param's coercion. Single-segment:nameparams are unaffected.Testing
tests/test_path_param_coercion.py::test_wildcard_path_param_is_never_coerced— new, covers numeric/boolean/float-looking and multi-segment wildcard values.tests/test_static.py::test_static_files_numeric_filename— new, reproduces the originalStaticFiles500.cargo build --lib/cargo clippy --all-targets: clean, no warnings.cargo test --lib: 26 passed.ruff check/ruff format --check: clean.Closes #212