Skip to content

fix(ts): match HTTP routes on escaped and decoded paths - #26

Closed
PhilBot402 wants to merge 1 commit into
mainfrom
philbotts-decoded-path-route-match-d0cc
Closed

PhilBot402 wants to merge 1 commit into
mainfrom
philbotts-decoded-path-route-match-d0cc

Conversation

@PhilBot402

Copy link
Copy Markdown
Owner

Port of x402-foundation#3502 from Python to TypeScript SDK.

TypeScript HTTP resource servers matched protected routes against path only. Python now also matches decoded_path, so a literal route such as GET /api/premium cannot be reached unpaid when the framework dispatches /api%2Fpremium as /api/premium. This port adds optional HTTPRequestContext.decodedPath and normalizeDecodedPath, and getRouteConfig requires payment if either representation matches. Express, Hono, Fastify, and Next pass that decoded view. See tracking issue x402-foundation#3541. This PR does not close it because the Go SDK is handled separately.

AI disclosure: Automated by @phdargen. Use your own judgement

Open in Web Open in Cursor 

Literal protected routes could be reached unpaid when a request encoded
its path separator. Adapters now pass the framework decoded view and
getRouteConfig requires payment if either representation matches.

Co-authored-by: phdargen <phdargen@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant