Skip to content

match_suffix emits non-HTTP methods (WEBSOCKET) into http_methods #213

Description

@rahlk

Is your feature request related to a problem? Please describe.

_methods_of in codeanalyzer/entrypoints/matching.py returns the matched suffix unconditionally:

if source == "match_suffix":
    verb = (qualified or dec.qualified_name or "").rsplit(".", 1)[-1]
    return [verb.upper()]

_HTTP_VERBS exists in the same module (line 29) and is applied on the other method path (line 207), but not here. The shipped heuristic.http-verb rule matches {*,*.*}.{get,post,put,patch,delete,head,options,websocket}, so @app.websocket("/ws") produces http_methods: ["WEBSOCKET"].

WEBSOCKET is not an HTTP method. http_methods is a field consumers filter on to separate routes from non-route entrypoints, so a junk value there is worse than an empty list — a query for "all POST endpoints" is unaffected, but a query that enumerates distinct methods now reports a method that does not exist.

The framework rules using match_suffix (flask.bp-verb, fastapi.verb, fastapi.router-verb) list only real verbs and are unaffected today; the heuristic tier is the live case, and any future rule with a non-verb suffix inherits the same gap.

Describe the solution you'd like

  • _methods_of's match_suffix branch returns [verb.upper()] only when verb.lower() in _HTTP_VERBS, else [].
  • Test: a @app.websocket("/ws") fixture registers an entrypoint with http_methods == [], and a @app.get fixture still yields ["GET"].

Describe alternatives you've considered

Not stated in the original issue.

Additional context

Scope boundary

  • The fix is one filter, matching what line 207 already does. No rule change and no schema change: http_methods shrinks in the affected case, gains nothing new.
  • fastapi.websocket (a separate rule with no methods: spec) already yields [] and is not the case here.

Caveats and known risks

  • This is a behaviour change for anyone reading WEBSOCKET out of http_methods today. The entrypoint record is still produced — only the method list changes — and rule (heuristic.http-verb) remains the way to identify the shape.

Definition of done

http_methods contains only members of _HTTP_VERBS for every entrypoint the shipped ruleset produces, asserted by a test over a websocket-decorated fixture; existing entrypoint tests unchanged.

Cross-language note

Found while adding JS/TS framework rules in codeanalyzer-typescript#206, which fixed the same bug class on its own export_name path (Astro's ALL export). TypeScript's match_suffix branch already filtered; this one does not.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions