Skip to content

Flowlight 0.13.1 - #28

Merged
blessdyb merged 2 commits into
mainfrom
release/0.13.1
Oct 4, 2026
Merged

blessdyb merged 2 commits into
mainfrom
release/0.13.1

Conversation

@blessdyb

@blessdyb blessdyb commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

0.13.1 — Form-body request rewriting

Request-modification rules now rewrite application/x-www-form-urlencoded bodies as well as JSON:

  • Set or remove individual form fields before forwarding upstream.
  • Preserve repeated fields and their order; setting updates the first matching field, removal deletes all matching fields.
  • Encode form values the same way a browser does and recalculate Content-Length.
  • Keep form parsing gated on the Content-Type header; lookalike bodies remain untouched.

Includes six focused regression tests for encoding, appending, removal, repeated fields, missing Content-Type, and charset parameters. Locally verified with RewriteRuleTests; generated site validates 52 pages / 0 problems.

Release metadata is bumped to 0.13.1, release notes are added, and docs/ is regenerated. This PR is ready for the release sequence: CI → immutable v0.13.1 tag → dry run → publish → merge.

🤖 Generated with Claude Code

blessdyb and others added 2 commits October 2, 2026 02:35
A request rule's body edit did nothing against a form POST. Reported with a "Set stockApi = http://localhost/admin"
rule that never fired: the request Chrome made was application/x-www-form-urlencoded —

    stockApi=http%3A%2F%2Fstock.example.net%3A8080%2Fcheck

and the body edit was gated on the body parsing as a JSON object, so a form body fell through untouched. The
dialog said as much ("Only requests with a JSON body are changed"), which made it correct behaviour and a
useless feature for the most common kind of body there is.

So a body edit now also applies to a form body. When the body is not JSON and the request carries a
Content-Type of application/x-www-form-urlencoded, the path is a field name taken whole — a form is flat, so
`a.b` is a field literally named that, not a nested one — and the value is used as typed, because a form has
no types. Fields are parsed into ordered pairs that may repeat (set edits the first, remove drops all), and
re-encoded the way a browser does: + for space, everything else percent-encoded, so http://localhost/admin
goes on the wire as http%3A%2F%2Flocalhost%2Fadmin. Content-Length is reframed to match, as for JSON.

The Content-Type header is the signal: a body that merely looks like a form, with no such header, is still
left alone. JSON is tried first and is unchanged.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Rewrite rules now support application/x-www-form-urlencoded request bodies,
so form fields can be set or removed before the request is forwarded. Preserve
repeated fields and field order, re-encode values like a browser, and reframe
Content-Length. Add form-body coverage and release metadata for 0.13.1.

Co-Authored-By: Claude Code <noreply@anthropic.com>
@blessdyb
blessdyb merged commit 55a8219 into main Oct 4, 2026
10 of 11 checks passed
@blessdyb
blessdyb deleted the release/0.13.1 branch October 4, 2026 05:05

This branch was successfully deployed

1 active deployment
release — bbecd5c7 Deployed Oct 4, 2026 by blessdyb via release #101
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant