Restrict /s/* to GET and HEAD (closes #169) #335

Merged
clawbot merged 2 commits from issue-169-static-get-head into next 2026-09-29 11:10:27 +02:00
2 Commits
Author SHA1 Message Date
clawbot 3a4f3625e8 Document and test that unrouted methods get 405 without Allow on /s/*
check / check (push) Successful in 3m19s
A method chi does not route, such as PROPFIND, is refused by the
top-level router before it reaches the /s group, so it gets 405
without an Allow header. The README row and the test's doc comment
now say so, and TestStaticServesOnlyGetAndHead checks PROPFIND.

Model: opus-5-5
2026-09-29 08:34:01 +00:00
clawbot 205539cde7 Restrict /s/* to GET and HEAD (closes #169)
The static file server was attached with Mount, which registers every
method, so POST, PUT and DELETE on an asset were answered 200 with the
file. It is now registered for GET and HEAD only, inside a /s group
whose method-not-allowed handler answers 405 with Allow: GET, HEAD
(chi's default 405 sends no Allow header).

TestStaticServesEveryMethod is inverted and renamed
TestStaticServesOnlyGetAndHead, and the README route table row for
/s/* now says the same.

Model: opus-5-5
2026-09-29 08:34:01 +00:00