Escape HTTP error responses as valid JSON - #46
Merged
Merged
Conversation
O6lvl4
marked this pull request as ready for review
October 4, 2026 01:11
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The HTTP bridge already escapes successful response bodies, but its four error paths interpolate text directly into JSON. An unsupported method such as
BAD"METHODproduces invalid JSON; the Almide parser can return a truncated error instead of the original text.Reuse
escape_json_texton every error path and add a regression inwasm_rt_test.almdcovering quotes, backslashes, control characters (including NUL), and Unicode. Unsupported methods are rejected before any request is sent.Verification on Linux, using the pinned Almide v0.63.0-rc1 binary (reports 0.63.0), Rust 1.99.0, Wasmtime 47.0.2, and codopsy 2.2.0:
almide test src/wasm_rt_test.almd --ci --run wt_http_request: 2 tests passed, 50 filtered out.almide checkfor main and the changed test file, native Porta build, and the no-OpenSSL link check pass.almide test --ci: 6 WASM files pass; 3 native file runs reach the same existing Unix-socket test and fail with EPERM. An independent Python AF_UNIX socket creation reproduces the executor restriction.The full local suite is therefore not green. Platform enforcement needs the normal CI runners. No permission-policy changes are included; #45 is separate.