Relates to #223, #231
Problem
The server registers a catch-all router.PathPrefix("/") with the SPA handler (spaHandler in cmd/server/main.go) after the API routes. Because of that, an unknown /api/* path, or a known API path called with the wrong method, is served index.html with 200:
POST /api/nonexistent -> 200 text/html
GET /api/nonexistent -> 200 text/html
This was observed on staging, and it is how master behaves today. It came up in #231: once POST /api/packets is removed, the bare API router answers 405, but the production wiring answers 200 with the SPA page.
A client that calls a mistyped or removed endpoint gets a success status and an HTML body. It is easy to misread as success, and it hides integration errors.
Proposed fix
- Before the SPA catch-all, add an
/api/ handler that returns JSON errors:
404 {"error":"Not found"} for unknown paths;
405 with an Allow header for a known path called with the wrong method. Gorilla mux can provide this through MethodNotAllowedHandler and NotFoundHandler on an /api subrouter, or through an explicit PathPrefix("/api/") fallback.
- Keep the WebSocket upgrade path and every existing route unchanged. Check that
wsOrStatic and any /api/... paths served by other handlers, such as health and metrics, are not caught by the new fallback.
- The SPA fallback for non-API paths (
#/... deep links and static files) stays as it is.
Acceptance
Relates to #223, #231
Problem
The server registers a catch-all
router.PathPrefix("/")with the SPA handler (spaHandlerincmd/server/main.go) after the API routes. Because of that, an unknown/api/*path, or a known API path called with the wrong method, is servedindex.htmlwith 200:This was observed on staging, and it is how master behaves today. It came up in #231: once
POST /api/packetsis removed, the bare API router answers 405, but the production wiring answers 200 with the SPA page.A client that calls a mistyped or removed endpoint gets a success status and an HTML body. It is easy to misread as success, and it hides integration errors.
Proposed fix
/api/handler that returns JSON errors:404 {"error":"Not found"}for unknown paths;405with anAllowheader for a known path called with the wrong method. Gorilla mux can provide this throughMethodNotAllowedHandlerandNotFoundHandleron an/apisubrouter, or through an explicitPathPrefix("/api/")fallback.wsOrStaticand any/api/...paths served by other handlers, such as health and metrics, are not caught by the new fallback.#/...deep links and static files) stays as it is.Acceptance
GET /api/...returns JSON 404, not HTML./apipath called with an unsupported method returns 405 (or JSON 404 if 405 is not feasible), never 200 HTML. A test locksPOST /api/packetsin particular.map[string]interface{}: use the existing error response type.