Skip to content

Allow restore_payload to reconstruct bodies for non-POST methods - #45

Open
azhar22k wants to merge 2 commits into
localstack:mainfrom
azhar22k:fix-restore-payload-methods
Open

azhar22k wants to merge 2 commits into
localstack:mainfrom
azhar22k:fix-restore-payload-methods

Conversation

@azhar22k

Copy link
Copy Markdown

Motivation

Fixes #41.

restore_payload() previously checked if request.method != "POST": return data. For any other method that carries a form or multipart body — such as PUT and PATCH — Werkzeug consumes the body stream into request.form and request.files, leaving request.data empty (b""). Consequently, restore_payload() returned an empty bytes object, silently dropping the body when proxying requests (e.g., in LocalStack API Gateway HTTP API v2 / Lambda integrations).

Per RFC 9110, HTTP methods like PUT and PATCH can legitimately carry any representation including multipart/form-data and application/x-www-form-urlencoded.

Changes

  • Removed the request.method != "POST" early-return in restore_payload(), allowing form and multipart body reconstruction regardless of HTTP method.
  • Improved multipart boundary extraction by querying request.mimetype_params.get("boundary"), gracefully handling boundaries with quoted strings or additional parameters (such as charset).
  • Parametrized multipart and form-urlencoded payload restoration tests across POST, PUT, and PATCH in tests/test_request.py.
  • Added a test in tests/test_request.py verifying boundary parsing when the Content-Type header contains extra parameters and quotes.

Testing

@azhar22k
azhar22k requested a review from bentsku as a code owner September 26, 2026 16:11

@bentsku bentsku left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a great change! Thanks a lot for addressing the issue. I just have a question about removing the method check completely, in order to not add new regressions. Once this is addressed, I think we'd be good to go?

Comment thread rolo/request.py
@azhar22k

Copy link
Copy Markdown
Author

Addressed in 17b9064: updated restore_payload to check if request.method not in ("POST", "PUT", "PATCH"): return data, and added test coverage for non-body methods (GET, DELETE, etc.). All tests and linters pass!

@azhar22k
azhar22k requested a review from bentsku September 29, 2026 16:01

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

restore_payload drops the body of multipart/form-data and x-www-form-urlencoded PUT/PATCH requests

2 participants