Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Allow header accuracy: advertise OPTIONS, and 405 instead of 404 on single-verb routes

オープン
#318 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
3/5
見積もり時間
1〜2日
初心者へのやさしさ
74/100
issue の種類
バグ
明瞭さ
おおむね明確
活発さ
活発
技術スタック
javascript
領域
api, backend, testing

調査の方向性

Start with rest.sendMethodNotAllowed(), rest.createPatchOverrideMiddleware(), and getAllowedMethods() in routes/tests/route_wrappers.test.js to understand the current Allow derivation. Then inspect the route definitions in routes/api-routes.js, routes/compatability.js, and routes/static.js, including the static middleware ordering. Done means OPTIONS is included in emitted Allow values and the listed wrong-method requests return 405 with the expected headers, with the /v1/ decision resolved.

索引モデルが issue の本文から書いたものです。

説明

Follow-up to #296, which was resolved by #295. Two small Allow accuracy gaps remain. Both sit outside the scope of #296, which covered only routes that already return a 405.

OPTIONS is never listed in Allow

rest.sendMethodNotAllowed() emits only the verbs registered on the route, so no 405 response advertises OPTIONS. The cors middleware in app.js answers OPTIONS at every path with a 204, even with no Origin header present:

OPTIONS /v1/api/create  ->  HTTP/1.1 204 No Content
OPTIONS /v1/api/query   ->  HTTP/1.1 204 No Content
OPTIONS /v1/id/:_id     ->  HTTP/1.1 204 No Content

RFC 9110 §10.2.1 defines Allow as the set of methods supported by the target resource, so OPTIONS belongs in every value we emit.

Suggested approach: append OPTIONS inside rest.sendMethodNotAllowed() and rest.createPatchOverrideMiddleware() rather than editing all 20 call sites, then update getAllowedMethods() in routes/__tests__/route_wrappers.test.js so the derived expectation still matches.

Single-verb routes 404 where a 405 fits better

These routes register one verb with no .all() fallback, so a wrong method falls through to the app's 404 handler with no Allow header at all.

Request Current Expected
POST /v1/api 404 405 with Allow: GET,HEAD,OPTIONS
GET /v1/api/accessToken 404 405 with Allow: POST,OPTIONS
GET /v1/api/refreshToken 404 405 with Allow: POST,OPTIONS
POST /v1/ 404 405 with Allow: GET,HEAD,OPTIONS

Sources: router.get('/api', ...) in routes/api-routes.js, /accessToken and /refreshToken in routes/compatability.js, and router.get('/', ...) in routes/static.js.

Worth deciding whether /v1/ is wanted here. That router also serves the static public directory, so an .all() fallback has to sit after the static middleware or it will shadow real files.

主要言語
JavaScript
スター
3
フォーク
6
平均マージ
4日 9時間
マージ済み PR(30日)
5

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

CenterForDigitalHumanities/rerum_server_nodejs のほかの issue

CenterForDigitalHumanities/rerum_server_nodejs の issue をすべて見る

似ている issue

JavaScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。