Skip to content

NetNavr v0.2.4 — Core Read-Only HTTP Contract

Choose a tag to compare

@PM100Fun PM100Fun released this 22 Aug 15:39
a22e243

Highlights

  • Every Core HTTP response now carries a server-generated request ID.
  • Structured errors include the same request ID for local diagnosis.
  • Known read-only routes return explicit 405 responses for unsupported methods.
  • Core rejects request bodies while the API remains read-only.
  • The HTTP parser now enforces an 8 KiB header ceiling, strict parsing, bounded timeouts, and a per-socket request cap.
  • Regression tests cover request correlation, method semantics, body rejection, and oversized headers.

Compatibility

  • Existing GET /v1/health and GET /v1/node success payloads are unchanged.
  • Error payloads now include a top-level requestId.
  • No database schema, configuration, Shell, or Pay migration is required.

Validation

Security boundary

Core remains loopback-only and read-only. Request IDs are diagnostics, not authentication. Complete application-level authentication and authorization are still future work.

Full changelog: v0.2.3...v0.2.4