The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →In Undertow, read query-string values with HttpServerExchange.getQueryParameters() and route-template captures with HttpServerExchange.getPathParameters(). They are separate maps of names to deques, so either can contain multiple values. In a Servlet endpoint, HttpServletRequest.getParameter* is for query and eligible form parameters—not for path-template captures.
How query and path parameters differ
A query parameter appears after the question mark in a URL. For example, /users?id=42 places id in the query string. A path parameter is a value captured from a route pattern: a template such as /users/{id} can match /users/42, with 42 captured as id. The example illustrates the distinction; an application must have a route matcher configured to perform that capture.
| Aspect | Query parameter | Path parameter |
|---|---|---|
| Where it comes from | The URL query string after ? |
A named segment captured by a route or path template |
| Low-level exchange accessor | getQueryParameters() |
getPathParameters() |
| Typical use | Optional filters, sorting, pagination, or other request controls | Identifying a route segment, such as a resource ID |
| Value shape in the exchange API | Map<String, Deque<String>> |
Map<String, Deque<String>> |
Undertow keeps the request path and parameter collections separately; a value in the path does not become a query parameter just because it has the same name. Undertow’s HttpServerExchange API documents the separate accessors and map types. For path-template matching, Undertow’s PathTemplate provides the URI-template matcher.
Read parameters in a low-level Undertow handler
Use the accessor that matches the value’s source. Each name maps to a deque because a request can supply more than one value under that name; read the first value only if that is the behavior your application intends.
#1 Best Overall
Map<String, Deque<String>> query = exchange.getQueryParameters();
Deque<String> queryIds = query.get("id");
String queryId = queryIds == null ? null : queryIds.peekFirst();
Map<String, Deque<String>> path = exchange.getPathParameters();
Deque<String> pathIds = path.get("id");
String pathId = pathIds == null ? null : pathIds.peekFirst();
Import the corresponding Java collection types (Map and Deque) as needed. A path entry is available when the handler chain or matcher has populated path parameters—for example, by matching a named template segment. Calling getPathParameters() does not itself define a route or extract arbitrary path components.
Read parameters in a Servlet endpoint
In Undertow’s Servlet implementation, HttpServletRequest.getParameter(name) first consults the exchange’s query parameters. If a matching query name is absent, Undertow may parse form data; getParameterValues(name) and getParameterMap() can combine query values with eligible form values. These methods are not a path-capture API. Obtain captures from the routing or framework mechanism that matched the request path.
That distinction matters when a query value and a route capture share a name: Servlet parameter access is not a way to ask which path segment matched. Undertow’s behavior is implemented in HttpServletRequestImpl.
Decoding, normalization, and safe path handling
Do not treat a decoded path or a captured value as automatically safe. Undertow distinguishes the original request URI, request path, relative path, resolved path, and query string. Its getRequestPath() documentation says the path is decoded and excludes the query string, but is not canonicalized by default; it cautions applications to ensure escape attacks cannot occur. Route matching, decoding configuration, canonicalization, and the eventual use of a value all affect how a path should be interpreted.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsHttpServerExchange documents the path fields and the non-canonicalization warning. Undertow’s request-path setup code describes decoding behavior controlled by options, including URL decoding, query decoding, and slash decoding; see Connectors.setExchangeRequestPath. The effective behavior depends on the Undertow version and configured handler chain, so check those settings in the deployment being secured.
- Use the route matcher’s capture for route identity; do not substitute a similarly named query parameter.
- Before using path data for authorization, filesystem access, or another sensitive operation, ensure the application’s route matching, decoding, and normalization rules align with that operation.
- Do not infer that a captured string has been validated merely because a template matched it.
Parameter-count limits
UndertowOptions.MAX_PARAMETERS limits the number of parameters parsed from query strings and POST data. Undertow documents the limit as not cumulative across those sources, so the configured maximum can apply to each source rather than to their combined total. The default is version-dependent and is not stated in the current-main-branch source reference cited here; check the documentation or source for the exact Undertow version in use. See UndertowOptions.
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

