Class HttpServerCodec

All Implemented Interfaces:
ChannelHandler, ChannelInboundHandler, ChannelOutboundHandler, HttpServerUpgradeHandler.SourceCodec

A combination of HttpRequestDecoder and HttpResponseEncoder which enables easier server side HTTP implementation.

Header Validation

It is recommended to always enable header validation.

Without header validation, your system can become vulnerable to CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') .

This recommendation stands even when both peers in the HTTP exchange are trusted, as it helps with defence-in-depth.

See Also:
  • Field Details

    • DEFAULT_MAX_PIPELINE_DEPTH

      static final int DEFAULT_MAX_PIPELINE_DEPTH
      The maximum number of pipelined requests we allow to be awaiting a response by default, before decoding of further requests is rejected. This bounds the memory a single connection can force us to hold onto if the peer pipelines requests without reading the corresponding responses.
      See Also:
    • queue

      private final Queue<HttpMethod> queue
      A queue that is used for correlating a request and a response.
    • maxPipelineDepth

      private final int maxPipelineDepth
    • mustCloseAfterResponse

      private boolean mustCloseAfterResponse
      When set, the connection will be closed after the next response is written.
  • Constructor Details

    • HttpServerCodec

      public HttpServerCodec()
      Creates a new instance with the default decoder options (maxInitialLineLength (4096), maxHeaderSize (8192), and maxChunkSize (8192)).
    • HttpServerCodec

      public HttpServerCodec(int maxInitialLineLength, int maxHeaderSize, int maxChunkSize)
      Creates a new instance with the specified decoder options.
    • HttpServerCodec

      @Deprecated public HttpServerCodec(int maxInitialLineLength, int maxHeaderSize, int maxChunkSize, boolean validateHeaders)
      Deprecated.
      Prefer the HttpServerCodec(HttpDecoderConfig) constructor, to always enable header validation.
      Creates a new instance with the specified decoder options.
    • HttpServerCodec

      @Deprecated public HttpServerCodec(int maxInitialLineLength, int maxHeaderSize, int maxChunkSize, boolean validateHeaders, int initialBufferSize)
      Deprecated.
      Prefer the HttpServerCodec(HttpDecoderConfig) constructor, to always enable header validation.
      Creates a new instance with the specified decoder options.
    • HttpServerCodec

      @Deprecated public HttpServerCodec(int maxInitialLineLength, int maxHeaderSize, int maxChunkSize, boolean validateHeaders, int initialBufferSize, boolean allowDuplicateContentLengths)
      Deprecated.
      Prefer the HttpServerCodec(HttpDecoderConfig) constructor, to always enable header validation.
      Creates a new instance with the specified decoder options.
    • HttpServerCodec

      @Deprecated public HttpServerCodec(int maxInitialLineLength, int maxHeaderSize, int maxChunkSize, boolean validateHeaders, int initialBufferSize, boolean allowDuplicateContentLengths, boolean allowPartialChunks)
      Deprecated.
      Prefer the HttpServerCodec(HttpDecoderConfig) constructor, to always enable header validation.
      Creates a new instance with the specified decoder options.
    • HttpServerCodec

      public HttpServerCodec(HttpDecoderConfig config)
      Creates a new instance with the specified decoder configuration.
    • HttpServerCodec

      public HttpServerCodec(HttpDecoderConfig config, int maxPipelineDepth)
      Creates a new instance with the specified decoder configuration.
      Parameters:
      config - the decoder configuration.
      maxPipelineDepth - the maximum number of requests that may be decoded while awaiting the corresponding responses to be written, before decoding of further requests is rejected with an IllegalStateException.
  • Method Details