🦋 New version release - #121
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.
Releases
@smooai/fetch@3.7.0
Minor Changes
43ca80a: Make redirect handling configurable in all five languages
Redirects were followed unconditionally everywhere, and TypeScript went further:
merge({}, init, { redirect: 'follow' })put the literal last, so a callerpassing
redirect: 'manual'had it silently overwritten. Python hardcodedfollow_redirects=Trueinto the httpx kwargs; Rust, Go and .NET set nothing andinherited platform defaults that follow up to 10 hops.
That is a security gap, not just an ergonomic one. A caller who resolves a
hostname and checks it against an SSRF allowlist has that guard defeated by a 302
to an internal address, because the check was performed on the original host. And
RFC 8461 forbids following redirects when fetching an MTA-STS policy.
redirectis honoured (defaults first, caller last)FetchOptions.follow_redirectsRequestInit.follow_redirects: Option<bool>(Noneinherits, so aclient-level default survives a per-request
..Default::default())ClientBuilder.WithFollowRedirects, applied to a caller-supplied*http.ClienttooSmooFetchOptions.FollowRedirects/WithFollowRedirectsHonouring the option was not sufficient on its own: in TS, Rust, Go and .NET a
3xx is neither "ok" nor "redirected", so it was raised as an error and the option
was undone a line later. Each now returns a deliberately-unfollowed 3xx as an
ordinary response. Defaults are unchanged — everything still follows unless a
caller says otherwise.