404PrivacyDocs

HTTP/1.1

HTTP/1.1 is one of STATIC’s client-facing request paths. It is selected for plain HTTP proxy requests or when client-facing TLS does not negotiate h2. An HTTP CONNECT is a way to establish the client-facing TLS tunnel; it does not mean the origin sees the browser’s original handshake.

Three entry points

Input on listenerNext step
CONNECT host:443Reply 200, terminate the browser’s TLS inside the tunnel, then use negotiated ALPN.
Direct TLSTerminate TLS immediately, then use negotiated ALPN.
Plain HTTP proxy requestParse and process as an HTTP/1.1 request without TLS interception.

For the HTTP/1.1 session, STATIC parses the request line, headers, and body into RequestParts within configured limits. It creates a Flow, runs request stages, and sends a separate request to the origin through the fetcher in HTTP/1.1-only mode. The normal origin response is buffered, passes through response-header, body, and finalization hooks, then receives a corrected Content-Length before delivery.

Response changes

If the response is eligible HTML, the injection stage can decompress and insert the local runtime script. A request for /__static/runtime.js is served locally. Cache-sensitive handling is applied to script/bootstrap assets. The header stage also changes navigation request headers before the origin fetch.

Large bodies and request heads are subject to configured limits. Ordinary HTTP/1.1 processing is buffered; the HTTP/2 path has a distinct streaming branch for responses that do not need body mutation. Read HTTP/2 for the difference.

WebSockets

An HTTP/1.1 WebSocket upgrade is detected after request stages and takes a special path: STATIC opens raw upstream TLS, forwards the upgrade handshake, and, after a 101 Switching Protocols, copies bytes in both directions. Its frames do not pass through HTML injection or the normal profile-driven wreq fetcher. See the connection handler.