Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In Undertow, read query-string values with HttpServerExchange.getQueryParameters() and route-template captures with HttpServerExchange.getPathParameters(). They are separate maps of names to deques, so either can contain multiple values. In a Servlet endpoint, HttpServletRequest.getParameter* is for query and eligible form parameters—not for path-template captures.

How query and path parameters differ

A query parameter appears after the question mark in a URL. For example, /users?id=42 places id in the query string. A path parameter is a value captured from a route pattern: a template such as /users/{id} can match /users/42, with 42 captured as id. The example illustrates the distinction; an application must have a route matcher configured to perform that capture.

Aspect Query parameter Path parameter
Where it comes from The URL query string after ? A named segment captured by a route or path template
Low-level exchange accessor getQueryParameters() getPathParameters()
Typical use Optional filters, sorting, pagination, or other request controls Identifying a route segment, such as a resource ID
Value shape in the exchange API Map<String, Deque<String>> Map<String, Deque<String>>

Undertow keeps the request path and parameter collections separately; a value in the path does not become a query parameter just because it has the same name. Undertow’s HttpServerExchange API documents the separate accessors and map types. For path-template matching, Undertow’s PathTemplate provides the URI-template matcher.

Read parameters in a low-level Undertow handler

Use the accessor that matches the value’s source. Each name maps to a deque because a request can supply more than one value under that name; read the first value only if that is the behavior your application intends.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Map<String, Deque<String>> query = exchange.getQueryParameters();
Deque<String> queryIds = query.get("id");
String queryId = queryIds == null ? null : queryIds.peekFirst();

Map<String, Deque<String>> path = exchange.getPathParameters();
Deque<String> pathIds = path.get("id");
String pathId = pathIds == null ? null : pathIds.peekFirst();

Import the corresponding Java collection types (Map and Deque) as needed. A path entry is available when the handler chain or matcher has populated path parameters—for example, by matching a named template segment. Calling getPathParameters() does not itself define a route or extract arbitrary path components.

Read parameters in a Servlet endpoint

In Undertow’s Servlet implementation, HttpServletRequest.getParameter(name) first consults the exchange’s query parameters. If a matching query name is absent, Undertow may parse form data; getParameterValues(name) and getParameterMap() can combine query values with eligible form values. These methods are not a path-capture API. Obtain captures from the routing or framework mechanism that matched the request path.

That distinction matters when a query value and a route capture share a name: Servlet parameter access is not a way to ask which path segment matched. Undertow’s behavior is implemented in HttpServletRequestImpl.

Decoding, normalization, and safe path handling

Do not treat a decoded path or a captured value as automatically safe. Undertow distinguishes the original request URI, request path, relative path, resolved path, and query string. Its getRequestPath() documentation says the path is decoded and excludes the query string, but is not canonicalized by default; it cautions applications to ensure escape attacks cannot occur. Route matching, decoding configuration, canonicalization, and the eventual use of a value all affect how a path should be interpreted.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

HttpServerExchange documents the path fields and the non-canonicalization warning. Undertow’s request-path setup code describes decoding behavior controlled by options, including URL decoding, query decoding, and slash decoding; see Connectors.setExchangeRequestPath. The effective behavior depends on the Undertow version and configured handler chain, so check those settings in the deployment being secured.

  • Use the route matcher’s capture for route identity; do not substitute a similarly named query parameter.
  • Before using path data for authorization, filesystem access, or another sensitive operation, ensure the application’s route matching, decoding, and normalization rules align with that operation.
  • Do not infer that a captured string has been validated merely because a template matched it.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Parameter-count limits

UndertowOptions.MAX_PARAMETERS limits the number of parameters parsed from query strings and POST data. Undertow documents the limit as not cumulative across those sources, so the configured maximum can apply to each source rather than to their combined total. The default is version-dependent and is not stated in the current-main-branch source reference cited here; check the documentation or source for the exact Undertow version in use. See UndertowOptions.

Rank #4
Sale
HTTP: The Definitive Guide
  • Used Book in Good Condition

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.