Skip to content

Current boundaries

import { Aside } from ‘@astrojs/starlight/components’;

The current release deliberately keeps these boundaries visible:

  • HTTP/1.0 and HTTP/1.1 requests with validated Content-Length framing are supported. Transfer encodings, including chunked request bodies, are rejected.
  • Request-line, total-header, header-count, and body limits plus idle and absolute head/body deadlines are enforced.
  • Request targets must use origin form (/path?query). Absolute-form proxy targets are rejected.
  • The optional native request-head parser is experimental and separately installed. Python remains the reference and fallback.
  • Routing distinguishes 404 from 405, returns Allow, percent-decodes UTF-8 paths safely, and treats duplicate or trailing slashes as distinct paths.
  • Query strings and headers are parsed internally but are not yet injectable handler parameters.
  • There is no middleware, OpenAPI generation, authentication, TLS termination, streaming, WebSocket support, or proxy-header policy.
  • response= selects an encoder but does not validate the handler’s return type.
  • Uncaught handler exceptions produce a stable public 500 body while the traceback is logged server-side. Structured logging and request IDs remain roadmap work.
  • Multiprocess serving is POSIX-only. Windows uses one process in the current release.

These are roadmap items, not hidden features. See the project roadmap for implementation order and non-goals.