Files
cloudflare__vinext/tests/pages-page-method.test.ts
T
James Anderson 35bb1a2250 fix(pages-router): return 405 with Allow: GET, HEAD on POST to static pages (#1631)
Pages Router previously rendered HTML for any HTTP method, including
POST/PUT/DELETE, on static (no `getServerSideProps`) pages — masking
client bugs that Next.js surfaces as 405.

Mirrors Next.js's behavior in `base-server.ts` (the
`(typeof components.Component === 'string' || isSSG)` gate), which
rejects non-GET/HEAD methods on static pages with
`Allow: GET, HEAD` and a `Method Not Allowed` body. Pages with
`getServerSideProps` continue to accept any method, since user code
may legitimately read `req.method` inside gSSP.

The new `resolvePagesPageMethodResponse` helper is wired into both
the dev-server SSR handler and the prod-server pages-server-entry, and
skips `/_error`, `/404`, `/500`, data requests, and explicit status
overrides — matching the upstream carve-outs.

Refs #1463. The `res.revalidate()` portion of #1463 is left for a
follow-up.
2026-05-28 14:05:30 +01:00

48 lines
1.4 KiB
TypeScript

import { describe, expect, it } from "vite-plus/test";
import { resolvePagesPageMethodResponse } from "../packages/vinext/src/server/pages-page-method.js";
describe("pages page method policy", () => {
it("returns 405 with Allow for POST to a static (no gSSP) page", async () => {
const response = resolvePagesPageMethodResponse({
hasGetServerSideProps: false,
method: "POST",
});
if (!response) {
throw new Error("Expected a Method Not Allowed response");
}
expect(response.status).toBe(405);
expect(response.headers.get("allow")).toBe("GET, HEAD");
await expect(response.text()).resolves.toBe("Method Not Allowed");
});
it.each(["PUT", "DELETE", "PATCH", "OPTIONS"])(
"returns 405 for %s on a static page",
(method) => {
const response = resolvePagesPageMethodResponse({
hasGetServerSideProps: false,
method,
});
expect(response?.status).toBe(405);
},
);
it.each(["GET", "HEAD", "get", "head"])("returns null for %s requests", (method) => {
expect(
resolvePagesPageMethodResponse({
hasGetServerSideProps: false,
method,
}),
).toBeNull();
});
it("returns null when the page has getServerSideProps (SSR is allowed any method)", () => {
expect(
resolvePagesPageMethodResponse({
hasGetServerSideProps: true,
method: "POST",
}),
).toBeNull();
});
});