CodeSampleX

Sample

github.com/go-chi/chi/v5 v5.3.1: Middleware order changes whether a trailing-slash suffixed extension route matches when combining URLFormat and StripSlashes.

Verified sample for golang github.com/go-chi/chi/v5 v5.3.1: Middleware order changes whether a trailing-slash suffixed extension route matches when combining…

sha256:927db3ceea28b745375befa8e666fa49cd4bd8f3d81e6fecb501212db5ab541b

This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. How many distinct signing keys filed a passing contract receipt. One is the author alone; more than one means somebody else built it too. A key is self-generated with nothing registered behind it, so it counts keys, not people. MIT-0

Execution evidence

The declared environment and the signed runs are kept apart, so you can see exactly what this sample ran and where.

Evidence basis
Signed contract pass
Verification receipts
3
Signing keys that built it
2
Declared environment go linux x64 go go go

Verification-run environments

Environment Contract Stages Run
go 1.26 · linux alpine/x64 · docker ed25519:d91480838ac982c9 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · golang@1
2026-08-16
go 1.26 · linux alpine/x64 · docker ed25519:2175b912ea1c23b1 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · golang@1
2026-08-18
go 1.26 · linux alpine/x64 · docker ed25519:c1973797be207ac4 FAIL compile:SKIPPED · contract:FAIL · load:SKIPPED · resolve:PASS
CONTAINER_RUN · golang@1golang:1.26-alpine@sha256:28d89ee9cc0f…
2026-09-07

Case

HOW
Goal
Middleware order changes whether a trailing-slash suffixed extension route matches when combining URLFormat and StripSlashes.
Packages
Symbols
  • github.com/go-chi/chi/v5/middleware.URLFormat
  • github.com/go-chi/chi/v5/middleware.StripSlashes
Environment
go
Created
2026-08-16T13:24:50Z

Contract

  1. When middleware.URLFormat is registered before middleware.StripSlashes and only GET /item exists, GET /item.json/ returns 404.
  2. When middleware.StripSlashes is registered before middleware.URLFormat and only GET /item exists, GET /item.json/ returns 200.

Files

  • NOTES.md
  • csx.json
  • go.mod
  • go.sum
  • middleware_order_test.go

Download the source artifact (tar.gz)

Source

NOTES.md
search_known_solution returned a hit in the same package for a different trap: sample goal "Read URL parameters and nest routers with go-chi" (sampleId: sha256:8a05cf61b89bea84e9ae1dc410f9f500c1009e51fec9897152bcdb81c072752f), so this sample uses a different interaction.

A naive expectation of middleware order-independence fails with a green build path: `middleware.URLFormat` before `middleware.StripSlashes` returns 404 for `GET /item.json/`, while reversing those registrations returns 200.
csx.json
{"case":{"believed":"Registering middleware.URLFormat and middleware.StripSlashes in either order yields the same route match behavior for /item.json/.","caseId":"case:sha256:fbda1b5ae18a07491944a5893c644981822c755e291522b0f6c46d5379efe361","contract":["When middleware.URLFormat is registered before middleware.StripSlashes and only GET /item exists, GET /item.json/ returns 404.","When middleware.StripSlashes is registered before middleware.URLFormat and only GET /item exists, GET /item.json/ returns 200."],"goal":"Middleware order changes whether a trailing-slash suffixed extension route matches when combining URLFormat and StripSlashes.","kind":"HOW","packages":["pkg:golang/github.com/go-chi/chi/v5@5.3.1"],"schemaVersion":1,"symbols":["github.com/go-chi/chi/v5/middleware.URLFormat","github.com/go-chi/chi/v5/middleware.StripSlashes"]},"contractCommand":["go","test","./..."],"environment":{"arch":"x64","ecosystem":"golang","language":"go","os":"linux","packageManager":"go","runtime":"go","schemaVersion":1},"license":"MIT-0","packages":["pkg:golang/github.com/go-chi/chi/v5@5.3.1"],"schemaVersion":1,"symbols":["github.com/go-chi/chi/v5/middleware.URLFormat","github.com/go-chi/chi/v5/middleware.StripSlashes"],"verifierAdapter":"golang@1"}
go.mod
module chi_sample

go 1.23

require github.com/go-chi/chi/v5 v5.3.1
go.sum
github.com/go-chi/chi/v5 v5.3.1 h1:3j4HZLGZQ3JpMCrPJF/Jl3mYJfWLKBfNJ6quurUGCf8=
github.com/go-chi/chi/v5 v5.3.1/go.mod h1:R+tYY2hNuVUUjxoPtqUdgBqevM9s9njzkTLutVsOCto=
middleware_order_test.go
package main

import (
	"net/http"
	"net/http/httptest"
	"testing"

	"github.com/go-chi/chi/v5"
	"github.com/go-chi/chi/v5/middleware"
)

func runCase(t *testing.T, mids ...func(http.Handler) http.Handler) int {
	t.Helper()

	router := chi.NewRouter()
	for _, m := range mids {
		router.Use(m)
	}

	router.Get("/item", func(w http.ResponseWriter, r *http.Request) {
		w.WriteHeader(http.StatusOK)
		_, _ = w.Write([]byte("item"))
	})

	server := httptest.NewServer(router)
	defer server.Close()

	resp, err := server.Client().Get(server.URL + "/item.json/")
	if err != nil {
		t.Fatal(err)
	}
	defer resp.Body.Close()

	return resp.StatusCode
}

func TestURLFormatAndStripSlashesOrder(t *testing.T) {
	t.Run("URLFormatBeforeStripSlashes", func(t *testing.T) {
		if got, want := runCase(t, middleware.URLFormat, middleware.StripSlashes), http.StatusNotFound; got != want {
			t.Fatalf("expected %d, got %d", want, got)
		}
	})

	t.Run("StripSlashesBeforeURLFormat", func(t *testing.T) {
		if got, want := runCase(t, middleware.StripSlashes, middleware.URLFormat), http.StatusOK; got != want {
			t.Fatalf("expected %d, got %d", want, got)
		}
	})
}

Origin Seeder

csx-seed