Skip to content

Honor HTTP methods in make_asgi_app like make_wsgi_app - #1211

Open
00200200 wants to merge 1 commit into
prometheus:masterfrom
00200200:fix/asgi-honor-http-methods
Open

00200200 wants to merge 1 commit into
prometheus:masterfrom
00200200:fix/asgi-honor-http-methods

Conversation

@00200200

Copy link
Copy Markdown

make_wsgi_app already rejects non-GET requests (405) and answers OPTIONS with Allow. make_asgi_app ignored scope["method"] and always scraped.

That means a POST/PUT/HEAD to the ASGI metrics app currently returns 200 plus a full exposition, and OPTIONS never advertises the allowed methods.

@csmarchbanks this matches the existing WSGI behavior rather than inventing a new contract.

Reproduction

from prometheus_client import CollectorRegistry, make_asgi_app, make_wsgi_app

registry = CollectorRegistry()
wsgi = make_wsgi_app(registry)

def start_response(status, headers, exc_info=None):
    print("WSGI", status)

list(wsgi({"REQUEST_METHOD": "POST", "PATH_INFO": "/metrics", "QUERY_STRING": ""}, start_response))
# WSGI 405 Method Not Allowed

ASGI before this change returns 200 for the same POST.

Tests

tests/test_asgi.py:

  • OPTIONS → 200, Allow: OPTIONS,GET, no scrape
  • POST → 405, Allow: OPTIONS,GET, no scrape
  • /favicon.ico → empty 200, no scrape (same as WSGI)

python -m pytest tests/test_asgi.py tests/test_wsgi.py tests/test_exposition.py tests/test_core.py — 224 passed, 1 skipped.

POST currently scrapes and returns 200; OPTIONS never advertised Allow.
Match the WSGI app so only GET exposes metrics.

Signed-off-by: Michał Furgała <83299832+00200200@users.noreply.github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant