You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/how-it-works/policies/schema.mdx
+27-5Lines changed: 27 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -446,12 +446,34 @@ network_middlewares:
446
446
447
447
## Matcher Semantics
448
448
449
-
| Matcher | Case-sensitive | Wildcards |
449
+
Glob patterns follow one set of rules. Each matcher splits values at a
450
+
separator:
451
+
452
+
| Matcher | Separator | Case-sensitive |
450
453
|---|---|---|
451
-
| Endpoint `host` and middleware hosts | No | `*` matches characters within one DNS label, and `**` matches one or more labels. |
452
-
| Binary `path` | Yes | `*` matches within one path segment, and `**` matches across segments. |
453
-
| REST and WebSocket `path` | Yes | `*` matches within one path segment, and `**` matches across segments. `?` matches one character, and bracket classes such as `[0-9]` are supported. `/repos/**` does not match `/repos`. |
454
-
| Query values and MCP tool names | Yes | `*` matches any characters except `.`, and `**` matches any characters. |
454
+
| Endpoint `host` and middleware hosts | `.` | No |
455
+
| Binary `path` | `/` | Yes |
456
+
| REST and WebSocket rule `path` | `/` | Yes |
457
+
| Query values and MCP tool names | `.` | Yes |
458
+
459
+
- `*`matches any characters except the separator.
460
+
- `**`matches across separators only when it is a whole segment, as in
461
+
`/repos/**`, `**.example.com`, or `github.**`. Next to other characters, as in
462
+
`**secret**`, it behaves like `*`. A whole-segment `**` needs at least one
463
+
segment, so `/repos/**` does not match `/repos`.
464
+
- `?`matches one character except the separator, and bracket classes such as
465
+
`[0-9]`match one character from a set. Endpoint hosts accept only `*` and
466
+
`**`, as described in [Destination Fields](#destination-fields).
467
+
468
+
Because query values and MCP tool names use `.` as the separator, `*` does not
469
+
match a value that contains a dot. For example, `1.*` matches `1.2` but not
470
+
`1.2.3`, and `github.*` matches `github.search` but not `github.search.code`.
471
+
Use `**` to match any value.
472
+
473
+
The endpoint `path` field, which selects among endpoints on the same host and
474
+
port, uses different rules. An empty path, `**`, or `/**` matches every path,
475
+
`/v1/**`matches `/v1` and every path under it, and in other patterns `*` also
0 commit comments