Conversation
bentsku
reviewed
Sep 28, 2026
bentsku
left a comment
Collaborator
There was a problem hiding this comment.
This is a great change! Thanks a lot for addressing the issue. I just have a question about removing the method check completely, in order to not add new regressions. Once this is addressed, I think we'd be good to go?
Author
|
Addressed in 17b9064: updated |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
Fixes #41.
restore_payload()previously checkedif request.method != "POST": return data. For any other method that carries a form or multipart body — such asPUTandPATCH— Werkzeug consumes the body stream intorequest.formandrequest.files, leavingrequest.dataempty (b""). Consequently,restore_payload()returned an empty bytes object, silently dropping the body when proxying requests (e.g., in LocalStack API Gateway HTTP API v2 / Lambda integrations).Per RFC 9110, HTTP methods like
PUTandPATCHcan legitimately carry any representation includingmultipart/form-dataandapplication/x-www-form-urlencoded.Changes
request.method != "POST"early-return inrestore_payload(), allowing form and multipart body reconstruction regardless of HTTP method.request.mimetype_params.get("boundary"), gracefully handling boundaries with quoted strings or additional parameters (such ascharset).POST,PUT, andPATCHintests/test_request.py.tests/test_request.pyverifying boundary parsing when the Content-Type header contains extra parameters and quotes.Testing
PUTandPATCHrequests withmultipart/form-dataandapplication/x-www-form-urlencodednow properly reconstruct the payload instead of returning empty bytes.make test).make formatandmake lint.