go-http-server-applications
Design, build, test, and review production Go HTTP servers covering inbound adapters, modern ServeMux routing, middleware, strict bounded request de…
它会碰到什么
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
Go HTTP Server Applications
Keep handlers thin, bound untrusted input, configure the server explicitly, and
make startup and shutdown part of the tested application contract.
Core Workflow
- Separate domain behavior from the inbound HTTP adapter.
- Define routes, methods, media types, limits, and error mappings.
- Build an explicit mux and ordered middleware stack.
- Decode requests strictly and within endpoint-specific byte/time budgets.
- Encode complete responses before committing headers where practical.
- Configure listener, server timeouts, header limits, and health semantics.
- Serve under a lifecycle that observes errors and drains with a deadline.
- Test handlers, routing, middleware, shared state, and real loopback behavior.
Read Next
| Task | Load |
|---|---|
| Build a server | guidelines.md, workflows/build-http-server.md |
| Test handlers or lifecycle | workflows/test-http-server.md |
| Review routing, middleware, JSON, or shutdown | references/http-server/rules.md |
| Understand server and writer contracts | references/http-server/knowledge.md |
| Review patterns | references/http-server/examples.md |
Guardrails
- Do not use
http.DefaultServeMuxfor application composition. - Do not expose a public server with zero-value timeout policy by accident.
- Do not read request bodies without an endpoint-specific bound.
- Do not assume a wrapped
ResponseWriterpreserves optional capabilities. - Do not call readiness an unconditional liveness response.
- Do not let the process exit before graceful shutdown finishes.
Source Notes
Guidance is transformed and paraphrased from Inanc Gumus, *Go by Example:
Programmer's Guide to Idiomatic and Testable Programs* (Manning, 2025),
Chapters 8-9. Examples are original.
Terminal-response control-flow and timeout guidance also incorporates
transformed material from Teiva Harsanyi, *100 Go Mistakes and How to Avoid
Them* (Manning, 2022), Chapter 10.
Book: https://www.manning.com/books/go-by-example
Verify current routing and lifecycle behavior against https://pkg.go.dev/net/http
and https://pkg.go.dev/net/http/httptest for the pinned Go version.
想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。
它属于哪个仓库
plugins/LVTD-LLC/skills/skills/go-http-server-applications/SKILL.md