What Framework0.13.6
What Framework 0.13.6
This patch hardens the full-stack scaffolder. It does not change the framework's
rendering architecture or add runtime dependencies.
Fixed
- A malformed percent-encoded request path now receives 400 Bad Request;
the generated server remains available for subsequent requests. - Generated applications start from directories containing spaces.
- Copy-pasted POSIX
cdguidance quotes special characters and disambiguates
relative paths beginning with a dash. - Invalid or missing template selections fail explicitly instead of producing
a different template from the one requested.
Upgrade existing generated applications
create-what writes application source once; upgrading the scaffolder alone
does not update a previously generated server.js. In a separate temporary
directory, generate a fresh full-stack project with create-what@0.13.6 and
compare its server against your application's customized copy.
Port these two changes without overwriting application routes or data:
- Catch request URL parsing/percent-decoding failures and send HTTP 400 before
continuing request handling. Preserve the static-file allowlist and path
traversal protections. - Use the generated entrypoint's file-URL-aware comparison instead of comparing
import.meta.urlwith a rawfile://${process.argv[1]}string.
Verify that a request to /%E0%A4%A receives 400 and a normal request immediately
afterward still succeeds. Also start the app from a path containing spaces.
All 13 maintained packages advance together to 0.13.6. The deprecated what-mcp
package stays at 0.12.4. Existing ISR migration guidance from 0.13.5 still applies
when upgrading from older versions.