NetNavr v0.2.4 — Core Read-Only HTTP Contract
Highlights
- Every Core HTTP response now carries a server-generated request ID.
- Structured errors include the same request ID for local diagnosis.
- Known read-only routes return explicit 405 responses for unsupported methods.
- Core rejects request bodies while the API remains read-only.
- The HTTP parser now enforces an 8 KiB header ceiling, strict parsing, bounded timeouts, and a per-socket request cap.
- Regression tests cover request correlation, method semantics, body rejection, and oversized headers.
Compatibility
- Existing
GET /v1/healthandGET /v1/nodesuccess payloads are unchanged. - Error payloads now include a top-level
requestId. - No database schema, configuration, Shell, or Pay migration is required.
Validation
- Pull request CI: https://github.com/PM100Fun/NetNavr/actions/runs/32582223571
- Post-merge
mainCI: https://github.com/PM100Fun/NetNavr/actions/runs/32582287286 - Local: Core 18 passed / 3 Windows skips; Pay 13; Shell Server 2; Shell Desktop 5; TypeScript and production Web/Electron/preload builds passed.
- Clean Shell install audit: 0 vulnerabilities.
Security boundary
Core remains loopback-only and read-only. Request IDs are diagnostics, not authentication. Complete application-level authentication and authorization are still future work.
Full changelog: v0.2.3...v0.2.4