Current boundaries
import { Aside } from ‘@astrojs/starlight/components’;
The current release deliberately keeps these boundaries visible:
- HTTP/1.0 and HTTP/1.1 requests with validated
Content-Lengthframing are supported. Transfer encodings, including chunked request bodies, are rejected. - Request-line, total-header, header-count, and body limits plus idle and absolute head/body deadlines are enforced.
- Request targets must use origin form (
/path?query). Absolute-form proxy targets are rejected. - The optional native request-head parser is experimental and separately installed. Python remains the reference and fallback.
- Routing distinguishes 404 from 405, returns
Allow, percent-decodes UTF-8 paths safely, and treats duplicate or trailing slashes as distinct paths. - Query strings and headers are parsed internally but are not yet injectable handler parameters.
- There is no middleware, OpenAPI generation, authentication, TLS termination, streaming, WebSocket support, or proxy-header policy.
response=selects an encoder but does not validate the handler’s return type.- Uncaught handler exceptions produce a stable public 500 body while the traceback is logged server-side. Structured logging and request IDs remain roadmap work.
- Multiprocess serving is POSIX-only. Windows uses one process in the current release.
These are roadmap items, not hidden features. See the project roadmap for implementation order and non-goals.