Skip to content

fix: deduplicate HTTP methods in 405 Allow header - #1040

Closed
nathannewyen wants to merge 1 commit into
go-chi:masterfrom
nathannewyen:fix-duplicate-allow-header
Closed

nathannewyen wants to merge 1 commit into
go-chi:masterfrom
nathannewyen:fix-duplicate-allow-header

Conversation

@nathannewyen

@nathannewyen nathannewyen commented Dec 19, 2025 •

Copy link
Copy Markdown

Summary

  • Fixes duplicate HTTP methods appearing in the Allow header of 405 responses
  • When multiple overlapping wildcard routes match a path, each matching node was adding its methods to the Allow header, causing duplicates like Allow: POST POST POST POST
  • This fix uses a map to track seen methods and only adds each unique method once

Reproduction

As described in the issue, when routes overlap due to wildcards:

r.Post("/article/1-2-3", handler)
r.Post("/article/{a}", handler)
r.Post("/article/{b}-{c}", handler)
r.Post("/article/{b}-{c}-{d}", handler)

A GET request to /article/1-2-3 previously returned:

Allow: POST POST POST POST

Now correctly returns:

Allow: POST

Test plan

  • Added TestMethodNotAllowedDuplicateMethods test case
  • All existing tests pass

Fixes #996

When multiple overlapping wildcard routes match the same path, the Allow
header in 405 responses was containing duplicate HTTP methods (e.g.,
"POST POST POST POST" instead of just "POST").

This fix uses a map to track seen methods and only adds each method once
to the Allow header.

Fixes go-chi#996
@VojtechVitek

Copy link
Copy Markdown
Contributor

Thanks everyone. I confirmed the issue and reviewed these competing PRs:

PR Age Approach
#1029 Oct 2025 Dedupe at the source in tree.go (slices.Contains before append)
#1040, #1096, #1124 Dec 2025 – Jul 2026 Near-identical: seen-map inside methodNotAllowedHandler
#1047 Feb 2026 slices.Sort + Compact in the handler
#1112 Jun 2026 Refactor methodsAllowed to a bitmask

Let's go with #1029, which looks like the cleanest zero-allocation fix.

Closing the other PRs as duplicates — thanks for the contributions, the approaches were all reasonable.

Thank you for your contribution!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Duplicate HTTP methods in 405 Allow header

2 participants