Makes outbound HTTP requests from app scripts, mirroring the browser XMLHttpRequest API so existing client-side knowledge carries over. A request is opened with open(method, url), configured with setRequestHeader() and event listeners, and started with send(); readystatechange, progress, load and error events are dispatched as the response arrives, both to addEventListener() listeners and to on* callback properties set directly on the instance. Concurrent requests are capped per tenant, and each instance holds its own connection until close() releases it, so scripts should let send() or abort() run to completion rather than abandoning a request.
Extends: HashMap
Properties
| Property | Returns | Description |
|---|---|---|
| allResponseHeaders | String | All response headers formatted as one CR-LF separated string of "name: value" lines, excluding Set-Cookie. |
| readyState | int | The current state of the request, one of the UNSENT, OPENED, HEADERS_RECEIVED, LOADING or DONE constants. |
| response | Response | The underlying asynchttpclient Response for this request, once one has been received. |
| responseText | String | The response body as text, for the default and "text" response types. Returns an empty string before the request has been sent, the bytes received so far while the body is still streaming in, and the full body once the response is complete. |
| responseType | XMLHttpRequestResponseType | The response type this request has been configured to expect, controlling how getResponseText() interprets the body. |
| responseUrl | String | The final URL the request was sent to, as passed to open(). |
| status | int | The HTTP status code of the response, such as 200 or 404. Only meaningful once a status has been received. |
| statusText | String | The HTTP status reason phrase of the response, such as "OK" or "Not Found". |
| tenantConnectionCount | int | |
| tenantConnections | CopyOnWriteArrayList<WeakReference<XMLHttpRequest>> | |
| timeout | Long | The number of milliseconds send() will wait for a response before timing out, if one has been set. |
| withCredentials | boolean | Whether this request is configured to send credentials such as cookies with cross-origin requests. |
Methods
open(String method, String url) · open(String method, String url, boolean async) · open(String method, String url, boolean async, String username) · open(String method, String url, boolean async, String username, String password) · setRequestHeader(String header, String value) · setClientCertificate(InputStream in, String password) · getTimeout() · setTimeout(Long timeout) · isWithCredentials() · setWithCredentials(boolean withCredentials) · send() · send(Object data) · abort() · getResponseUrl() · getStatus() · getStatusText() · getReadyState() · getResponseHeader(String name) · getAllResponseHeaders() · getResponseType() · setResponseType(String rt) · getResponse() · getResponseText() · addEventListener(String type, Value callback) · addEventListener(String type, ScriptObjectMirror callback) · removeEventListener(String type, Value callback) · removeEventListener(String type, ScriptObjectMirror callback) · dispatchEvent(String type, Object params)
open(String method, String url)
Returns: void
The XMLHttpRequest.open() method initializes a request
| Parameter | Description |
|---|---|
method | The HTTP method to use, such as "GET", "POST", "PUT", "DELETE", etc. Ignored for non-HTTP(S) URLs. |
url | A DOMString representing the URL to send the request to. |
open(String method, String url, boolean async)
Returns: void
The XMLHttpRequest.open() method initializes a request
| Parameter | Description |
|---|---|
method | The HTTP method to use, such as "GET", "POST", "PUT", "DELETE", etc. Ignored for non-HTTP(S) URLs. |
url | A DOMString representing the URL to send the request to. |
async | whether the request runs asynchronously on a background thread, dispatching readystatechange and load events as the response arrives, rather than blocking send() until the response is received |
open(String method, String url, boolean async, String username)
Returns: void
The XMLHttpRequest.open() method initializes a request
| Parameter | Description |
|---|---|
method | The HTTP method to use, such as "GET", "POST", "PUT", "DELETE", etc. Ignored for non-HTTP(S) URLs. |
url | A DOMString representing the URL to send the request to. |
async | whether the request runs asynchronously on a background thread, dispatching readystatechange and load events as the response arrives, rather than blocking send() until the response is received |
username | The optional user name to use for authentication purposes; by default, this is the null value. |
open(String method, String url, boolean async, String username, String password)
Returns: void
The XMLHttpRequest.open() method initializes a request
| Parameter | Description |
|---|---|
method | The HTTP method to use, such as "GET", "POST", "PUT", "DELETE", etc. Ignored for non-HTTP(S) URLs. |
url | A DOMString representing the URL to send the request to. |
async | whether the request runs asynchronously on a background thread, dispatching readystatechange and load events as the response arrives, rather than blocking send() until the response is received |
username | The optional user name to use for authentication purposes; by default, this is the null value. |
password | The optional password to use for authentication purposes; by default, this is the null value. |
setRequestHeader(String header, String value)
Returns: void
The XMLHttpRequest.setRequestHeader() method sets the value of an HTTP request header. You must call setRequestHeader()after open(), but before send(). If this method is called several times with the same header, the values are merged into one single request header.
| Parameter | Description |
|---|---|
header | The name of the header whose value is to be set. |
value | The value to set as the body of the header. |
setClientCertificate(InputStream in, String password)
Returns: void
Configures a PKCS12 client certificate to present for TLS client authentication. Must be called before open(); it forces this request to use a dedicated HTTP client instead of the shared one, so the request's own client can be closed independently once it completes.
| Parameter | Description |
|---|---|
in | the PKCS12 keystore contents |
password | the password protecting the keystore |
getTimeout()
Returns: Long
The number of milliseconds send() will wait for a response before timing out, if one has been set.
setTimeout(Long timeout)
Returns: void
Sets how long, in milliseconds, send() will wait for a response before timing out. A synchronous request with no timeout set defaults to a 5 second request and read timeout.
| Parameter | Description |
|---|---|
timeout | the timeout in milliseconds, or null to clear it |
isWithCredentials()
Returns: boolean
Whether this request is configured to send credentials such as cookies with cross-origin requests.
setWithCredentials(boolean withCredentials)
Returns: void
Sets whether this request should send credentials such as cookies with cross-origin requests.
| Parameter | Description |
|---|---|
withCredentials | true to send credentials, false otherwise |
send()
Returns: void
Sends the request opened by open() with no request body. Equivalent to calling send((String) null).
send(Object data)
Returns: void
Sends the request opened by open(), with the given data as the request body. FormData is sent as a multipart body, InputStream and byte array data are sent as-is, and any other value is sent as its string form. If this instance was opened asynchronously the call returns once the request has been submitted and events fire on a background thread as the response arrives; otherwise it blocks until the response is received or the configured timeout (5 seconds by default) elapses. Throws if the tenant's concurrent request limit has already been reached.
| Parameter | Description |
|---|---|
data | the request body to send, or null to send no body |
abort()
Returns: void
Aborts an in-progress asynchronous request, firing progress, loadend and abort events and releasing the request's connection. Not supported for a synchronous request; calling it on one throws.
getResponseUrl()
Returns: String
The final URL the request was sent to, as passed to open().
getStatus()
Returns: int
The HTTP status code of the response, such as 200 or 404. Only meaningful once a status has been received.
getStatusText()
Returns: String
The HTTP status reason phrase of the response, such as "OK" or "Not Found".
getReadyState()
Returns: int
The current state of the request, one of the UNSENT, OPENED, HEADERS_RECEIVED, LOADING or DONE constants.
getResponseHeader(String name)
Returns: String
Reads the value of a single response header, joining multiple values for the same header name with a comma and space.
| Parameter | Description |
|---|---|
name | the header name to look up, case-insensitive |
getAllResponseHeaders()
Returns: String
All response headers formatted as one CR-LF separated string of "name: value" lines, excluding Set-Cookie.
getResponseType()
Returns: XMLHttpRequestResponseType
The response type this request has been configured to expect, controlling how getResponseText() interprets the body.
setResponseType(String rt)
Returns: void
Sets the expected response type by name, such as "text" or "json". An unrecognised name is treated as the default type.
| Parameter | Description |
|---|---|
rt | the response type name to set |
getResponse()
Returns: Response
The underlying asynchttpclient Response for this request, once one has been received.
getResponseText()
Returns: String
The response body as text, for the default and "text" response types. Returns an empty string before the request has been sent, the bytes received so far while the body is still streaming in, and the full body once the response is complete.
addEventListener(String type, Value callback)
Returns: void
Registers a callback to run when an event of the given type is dispatched on this request, such as "load", "error", "progress" or "readystatechange". Registering the same type and callback more than once has no effect, since listeners are compared by type and callback identity.
| Parameter | Description |
|---|---|
type | the event type to listen for |
callback | a GraalJS function value to invoke when the event fires; ignored if it is not executable |
addEventListener(String type, ScriptObjectMirror callback)
Returns: void
Nashorn equivalent of addEventListener(String, Value), for scripts running on the legacy Nashorn engine.
| Parameter | Description |
|---|---|
type | the event type to listen for |
callback | a Nashorn script function to invoke when the event fires; ignored if null |
removeEventListener(String type, Value callback)
Returns: void
Removes a previously registered listener for the given event type. Has no effect if no matching listener is registered.
| Parameter | Description |
|---|---|
type | the event type the listener was registered for |
callback | the callback that was passed to addEventListener() |
removeEventListener(String type, ScriptObjectMirror callback)
Returns: void
Nashorn equivalent of removeEventListener(String, Value), for scripts running on the legacy Nashorn engine.
| Parameter | Description |
|---|---|
type | the event type the listener was registered for |
callback | the callback that was passed to addEventListener() |
dispatchEvent(String type, Object params)
Returns: void
Invokes every listener registered for the given event type, passing the given parameters through to each callback. Listeners run within this request's original root context and tenant, so they can safely access platform state even when called from an asynchronous background thread.
| Parameter | Description |
|---|---|
type | the event type to dispatch |
params | the arguments to pass to each listener |