Skip to content

Add explicit zero-body POST transport - #16

Merged
nicodes merged 2 commits into
mainfrom
feat/revik-zero-body-post
Sep 27, 2026
Merged

nicodes merged 2 commits into
mainfrom
feat/revik-zero-body-post

Conversation

@nicodes

@nicodes nicodes commented Sep 27, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Add public HttpClientModule.post_zero_body(endpoint, callback, headers) so a POST can send exactly zero body bytes. post_json({}) still serializes and sends {}.
  • Native empty POST sets Content-Length: 0 only on the Godot HTTPRequest path. Web POST omits fetch body and does not set Content-Length, which browsers forbid. Authorization stays a request header. Timeout and error callbacks are unchanged.
  • Web fetch uses redirect: 'manual'. A conforming browser exposes an opaque redirect, so the bridge does not follow it. A visible cross-origin Location is also rejected. Native GET still follows redirects through Godot HTTPRequest and can resend Authorization, including to another host; this change does not alter that pre-existing behavior.
  • Addon version is 0.0.4.

Tests

  • Native TCP capture asserts zero body bytes and exactly one Content-Length: 0. post_json({}) remains 2 bytes.
  • Real browser export asserts bearer only in Authorization, zero POST bytes, {} for post_json({}), callback success, and no sink hit for a cross-origin redirect.

post_json({}) still serializes "{}". post_zero_body sends an empty
string through the existing header, timeout, native, and web paths.
Native empty POST sets Content-Length: 0 only on the Godot path. Web fetch still omits the body, fails closed on opaque and cross-origin redirects, and documents the pre-existing native GET bearer redirect risk.
@nicodes
nicodes marked this pull request as ready for review September 27, 2026 01:56
@nicodes
nicodes merged commit 5db6b7f into main Sep 27, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant