Class HttpServerCodec

All Implemented Interfaces:
ChannelHandler, ChannelInboundHandler, ChannelOutboundHandler, HttpServerUpgradeHandler.SourceCodec

A combination of HttpRequestDecoder and HttpResponseEncoder which enables easier server side HTTP implementation.

Header Validation

It is recommended to always enable header validation.

Without header validation, your system can become vulnerable to CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') .

This recommendation stands even when both peers in the HTTP exchange are trusted, as it helps with defence-in-depth.

See Also:
  • Field Details

    • DEFAULT_MAX_PIPELINE_DEPTH

      static final int DEFAULT_MAX_PIPELINE_DEPTH
      The maximum number of pipelined requests we allow to be awaiting a response by default, before decoding of further requests is rejected. This bounds the memory a single connection can force us to hold onto if the peer pipelines requests without reading the corresponding responses.
      See Also:
    • METHOD_FLAG_HEAD

      private static final byte METHOD_FLAG_HEAD
      See Also:
    • METHOD_FLAG_CONNECT

      private static final byte METHOD_FLAG_CONNECT
      See Also:
    • METHOD_FLAG_OTHER

      private static final byte METHOD_FLAG_OTHER
      See Also:
    • METHOD_FLAG_BITS

      private static final int METHOD_FLAG_BITS
      See Also:
    • INLINE_QUEUE_CAPACITY

      private static final int INLINE_QUEUE_CAPACITY
      See Also:
    • methodQueue

      private long methodQueue
      FIFO of request method flags. The oldest entry is stored in the least-significant bits so poll is just a mask + unsigned shift. This avoids allocation for the common case of invalid input: '<'= 32 outstanding requests. Once more than INLINE_QUEUE_CAPACITY requests are queued, additional entries are appended to methodOverflowQueue. Order is preserved by always draining the inline queue first.
    • methodQueueSize

      private int methodQueueSize
    • methodOverflowQueue

      private Queue<Byte> methodOverflowQueue
    • maxPipelineDepth

      private final int maxPipelineDepth
    • mustCloseAfterResponse

      private boolean mustCloseAfterResponse
      When set, the connection will be closed after the next response is written.
  • Constructor Details

    • HttpServerCodec

      public HttpServerCodec()
      Creates a new instance with the default decoder options (maxInitialLineLength (4096), maxHeaderSize (8192), and maxChunkSize (8192)).
    • HttpServerCodec

      public HttpServerCodec(int maxInitialLineLength, int maxHeaderSize, int maxChunkSize)
      Creates a new instance with the specified decoder options.
    • HttpServerCodec

      @Deprecated public HttpServerCodec(int maxInitialLineLength, int maxHeaderSize, int maxChunkSize, boolean validateHeaders)
      Deprecated.
      Prefer the HttpServerCodec(HttpDecoderConfig) constructor, to always enable header validation.
      Creates a new instance with the specified decoder options.
    • HttpServerCodec

      @Deprecated public HttpServerCodec(int maxInitialLineLength, int maxHeaderSize, int maxChunkSize, boolean validateHeaders, int initialBufferSize)
      Deprecated.
      Prefer the HttpServerCodec(HttpDecoderConfig) constructor, to always enable header validation.
      Creates a new instance with the specified decoder options.
    • HttpServerCodec

      @Deprecated public HttpServerCodec(int maxInitialLineLength, int maxHeaderSize, int maxChunkSize, boolean validateHeaders, int initialBufferSize, boolean allowDuplicateContentLengths)
      Deprecated.
      Prefer the HttpServerCodec(HttpDecoderConfig) constructor, to always enable header validation.
      Creates a new instance with the specified decoder options.
    • HttpServerCodec

      @Deprecated public HttpServerCodec(int maxInitialLineLength, int maxHeaderSize, int maxChunkSize, boolean validateHeaders, int initialBufferSize, boolean allowDuplicateContentLengths, boolean allowPartialChunks)
      Deprecated.
      Prefer the HttpServerCodec(HttpDecoderConfig) constructor, to always enable header validation.
      Creates a new instance with the specified decoder options.
    • HttpServerCodec

      public HttpServerCodec(HttpDecoderConfig config)
      Creates a new instance with the specified decoder configuration.
    • HttpServerCodec

      public HttpServerCodec(HttpDecoderConfig config, int maxPipelineDepth)
      Creates a new instance with the specified decoder configuration.
      Parameters:
      config - the decoder configuration.
      maxPipelineDepth - the maximum number of requests that may be decoded while awaiting the corresponding responses to be written, before decoding of further requests is rejected with an IllegalStateException.
  • Method Details