{"record":{"id":"753dbb15c044aed5","repo":"aio-libs/aiohttp","slug":"method-is-not-allowed-http-method","errorCode":null,"errorMessage":"{method} is not allowed HTTP method","messagePattern":"(.+?) is not allowed HTTP method","errorType":"exception","errorClass":"ValueError","httpStatus":null,"severity":"error","filePath":"aiohttp/web_urldispatcher.py","lineNumber":166,"sourceCode":"class AbstractRoute(abc.ABC):\n    def __init__(\n        self,\n        method: str,\n        handler: Handler | type[AbstractView],\n        *,\n        expect_handler: _ExpectHandler | None = None,\n        resource: AbstractResource | None = None,\n    ) -> None:\n        if expect_handler is None:\n            expect_handler = _default_expect_handler\n\n        assert inspect.iscoroutinefunction(expect_handler) or (\n            sys.version_info < (3, 14) and asyncio.iscoroutinefunction(expect_handler)  # type: ignore[deprecated]\n        ), f\"Coroutine is expected, got {expect_handler!r}\"\n\n        method = method.upper()\n        if not HTTP_METHOD_RE.match(method):\n            raise ValueError(f\"{method} is not allowed HTTP method\")\n\n        if inspect.iscoroutinefunction(handler) or (\n            sys.version_info < (3, 14) and asyncio.iscoroutinefunction(handler)  # type: ignore[deprecated]\n        ):\n            pass\n        elif isinstance(handler, type) and issubclass(handler, AbstractView):\n            pass\n        else:\n            raise TypeError(\n                f\"Only async functions are allowed as web-handlers, got {handler!r}\"\n            )\n\n        self._method = method\n        self._handler = handler\n        self._expect_handler = expect_handler\n        self._resource = resource\n\n    @property","sourceCodeStart":148,"sourceCodeEnd":184,"githubUrl":"https://github.com/aio-libs/aiohttp/blob/d041d4d0fd48c3f0832084d33be16cf1c4835f85/aiohttp/web_urldispatcher.py#L148-L184","documentation":"When registering a route, aiohttp uppercases the method and validates it against HTTP_METHOD_RE (RFC 7230 token characters: alphanumerics and a subset of symbols). A method that does not match — e.g. contains spaces, lowercase handled fine by upper(), but embedded slashes, colons, or empty strings — raises ValueError. This protects the router from registering routes that can never match a real HTTP request line.","triggerScenarios":"Calling resource.add_route() or app.router.add_route() / app.router.add_get() with a malformed method string: empty string, a string containing spaces or commas (e.g. 'GET, POST'), a method with invalid characters like 'GET/' or 'GET\\n'. Also passing a method already containing a custom verb with disallowed punctuation.","commonSituations":"Typos; splitting a comma-separated method list instead of registering each separately; passing the full HTTP request line ('GET /path'); using a method name with a hyphen that includes an invalid symbol; test code that passes arbitrary strings.","solutions":["Pass a single, valid HTTP method token as a string: 'GET', 'POST', 'PUT', 'DELETE', 'PATCH', 'HEAD', 'OPTIONS', or a custom token matching [A-Za-z0-9!#$%&'*+-.^_`|~].","If you have a comma-separated list, split and register each method individually.","Strip whitespace and verify there are no newline/control characters before registering."],"exampleFix":"// before\nresource.add_route('GET, POST', handler)\n// after\nresource.add_route('GET', handler)\nresource.add_route('POST', handler)","handlingStrategy":"validation","validationCode":"import re\nfrom aiohttp.web_urldispatcher import HTTP_METHOD_RE\n\ndef validate_method(method: str) -> str:\n    method = method.upper()\n    if not HTTP_METHOD_RE.match(method):\n        raise ValueError(f'Invalid HTTP method: {method!r}')\n    return method","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Use the named helpers (add_get, add_post, add_put, add_delete, add_patch, add_head, add_options) instead of add_route for standard verbs.","Never pass comma-separated method lists; register each verb separately.","Unit-test route registration to catch malformed methods at test time."],"tags":["routing","validation","http-method"],"backgroundTag":null,"analyzedSha":"d041d4d0fd48c3f0832084d33be16cf1c4835f85","analyzedAt":"2026-08-11T20:44:15.550Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}