Skip to content

fix(server): unknown /api/* paths and wrong methods return 200 index.html instead of a JSON 404/405 #233

Description

@dborup

Relates to #223, #231

Problem

The server registers a catch-all router.PathPrefix("/") with the SPA handler (spaHandler in cmd/server/main.go) after the API routes. Because of that, an unknown /api/* path, or a known API path called with the wrong method, is served index.html with 200:

POST /api/nonexistent  -> 200 text/html
GET  /api/nonexistent  -> 200 text/html

This was observed on staging, and it is how master behaves today. It came up in #231: once POST /api/packets is removed, the bare API router answers 405, but the production wiring answers 200 with the SPA page.

A client that calls a mistyped or removed endpoint gets a success status and an HTML body. It is easy to misread as success, and it hides integration errors.

Proposed fix

  • Before the SPA catch-all, add an /api/ handler that returns JSON errors:
    • 404 {"error":"Not found"} for unknown paths;
    • 405 with an Allow header for a known path called with the wrong method. Gorilla mux can provide this through MethodNotAllowedHandler and NotFoundHandler on an /api subrouter, or through an explicit PathPrefix("/api/") fallback.
  • Keep the WebSocket upgrade path and every existing route unchanged. Check that wsOrStatic and any /api/... paths served by other handlers, such as health and metrics, are not caught by the new fallback.
  • The SPA fallback for non-API paths (#/... deep links and static files) stays as it is.

Acceptance

  • An unknown GET /api/... returns JSON 404, not HTML.
  • A known /api path called with an unsupported method returns 405 (or JSON 404 if 405 is not feasible), never 200 HTML. A test locks POST /api/packets in particular.
  • Every existing API route, the WebSocket and the SPA deep links behave as before. Routes are checked against the served OpenAPI route list.
  • No new map[string]interface{}: use the existing error response type.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions