NetNavr v0.2.19
Pay request target validation
Unparseable request URLs now return HTTP 400 INVALID_REQUEST_TARGET and close the connection instead of HTTP 500. Incoming body data is discarded; normal relative and absolute request targets continue to work.
Workspace v0.2.19; Pay v0.1.8.
Validation
A raw HTTP regression reproduces the previous 500 response and passes with the fix. It covers malformed authorities, invalid ports, GET and POST with a body, response safety headers, valid request targets, and normal order creation afterward.
Pay: 24 passed. Full Windows workspace: 84 passed, 3 expected platform skips. Shell type checks/build passed. Clean install and npm audit: 0 vulnerabilities. Branch, PR, and main CI passed.
Scope
Seven files: Pay handler/test/version metadata, workspace version, and bilingual README. No Core, Shell, dependency, lockfile, database, or production deployment changes. Dependabot PR #17 is not included. The original local non-Git mirror remains untouched.
NetNavr remains pre-alpha; Pay is sandbox-only. Source publication is not production deployment or authorization to process real funds.