Skip to content

fix(go): match HTTP routes on escaped and decoded paths - #27

Closed
PhilBot402 wants to merge 1 commit into
mainfrom
philbotgo-decoded-path-route-match-bfe6
Closed

PhilBot402 wants to merge 1 commit into
mainfrom
philbotgo-decoded-path-route-match-bfe6

Conversation

@PhilBot402

Copy link
Copy Markdown
Owner

Port of x402-foundation#3502 from Python to Go SDK.

Go HTTP resource servers matched protected routes against path only. Python now also matches decoded_path, so a literal route such as GET /api/premium cannot be reached unpaid when the framework dispatches /api%2Fpremium as /api/premium. This port adds optional HTTPRequestContext.DecodedPath and normalizeDecodedPath, and getRouteConfig requires payment if either representation matches. Gin, Echo, and net/http pass that decoded view from URL.Path. See tracking issue x402-foundation#3541. This PR does not close it because the TypeScript SDK is handled separately at x402-foundation#3542.

AI disclosure: Automated by @phdargen. Use your own judgement

Open in Web Open in Cursor 

Port Python x402-foundation#3502. getRouteConfig now requires payment if either the
escaped path or the framework decoded routing view matches a protected
route, so a literal route such as GET /api/premium cannot be reached
unpaid via /api%2Fpremium.

Co-authored-by: phdargen <phdargen@users.noreply.github.com>
@PhilBot402

Copy link
Copy Markdown
Owner Author

Closing this fork-targeted PR. The port is opened against upstream at x402-foundation#3543.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant