Skip to content

🦋 New version release - #121

Merged
brentrager merged 1 commit into
mainfrom
changeset-release/main
Aug 28, 2026
Merged

🦋 New version release#121
brentrager merged 1 commit into
mainfrom
changeset-release/main

Conversation

@brentrager

Copy link
Copy Markdown
Contributor

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@smooai/fetch@3.7.0

Minor Changes

  • 43ca80a: Make redirect handling configurable in all five languages

    Redirects were followed unconditionally everywhere, and TypeScript went further:
    merge({}, init, { redirect: 'follow' }) put the literal last, so a caller
    passing redirect: 'manual' had it silently overwritten. Python hardcoded
    follow_redirects=True into the httpx kwargs; Rust, Go and .NET set nothing and
    inherited platform defaults that follow up to 10 hops.

    That is a security gap, not just an ergonomic one. A caller who resolves a
    hostname and checks it against an SSRF allowlist has that guard defeated by a 302
    to an internal address, because the check was performed on the original host. And
    RFC 8461 forbids following redirects when fetching an MTA-STS policy.

    • TypeScriptredirect is honoured (defaults first, caller last)
    • PythonFetchOptions.follow_redirects
    • RustRequestInit.follow_redirects: Option<bool> (None inherits, so a
      client-level default survives a per-request ..Default::default())
    • GoClientBuilder.WithFollowRedirects, applied to a caller-supplied
      *http.Client too
    • .NETSmooFetchOptions.FollowRedirects / WithFollowRedirects

    Honouring the option was not sufficient on its own: in TS, Rust, Go and .NET a
    3xx is neither "ok" nor "redirected", so it was raised as an error and the option
    was undone a line later. Each now returns a deliberately-unfollowed 3xx as an
    ordinary response. Defaults are unchanged — everything still follows unless a
    caller says otherwise.

@brentrager
brentrager merged commit 1fcfb64 into main Aug 28, 2026
@brentrager
brentrager deleted the changeset-release/main branch August 28, 2026 00:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant