Skip to content

What Framework0.13.6

Choose a tag to compare

@zvndev zvndev released this 06 Sep 03:13
· 28 commits to main since this release
e6fac2b

What Framework 0.13.6

This patch hardens the full-stack scaffolder. It does not change the framework's
rendering architecture or add runtime dependencies.

Fixed

  • A malformed percent-encoded request path now receives 400 Bad Request;
    the generated server remains available for subsequent requests.
  • Generated applications start from directories containing spaces.
  • Copy-pasted POSIX cd guidance quotes special characters and disambiguates
    relative paths beginning with a dash.
  • Invalid or missing template selections fail explicitly instead of producing
    a different template from the one requested.

Upgrade existing generated applications

create-what writes application source once; upgrading the scaffolder alone
does not update a previously generated server.js. In a separate temporary
directory, generate a fresh full-stack project with create-what@0.13.6 and
compare its server against your application's customized copy.

Port these two changes without overwriting application routes or data:

  1. Catch request URL parsing/percent-decoding failures and send HTTP 400 before
    continuing request handling. Preserve the static-file allowlist and path
    traversal protections.
  2. Use the generated entrypoint's file-URL-aware comparison instead of comparing
    import.meta.url with a raw file://${process.argv[1]} string.

Verify that a request to /%E0%A4%A receives 400 and a normal request immediately
afterward still succeeds. Also start the app from a path containing spaces.

All 13 maintained packages advance together to 0.13.6. The deprecated what-mcp
package stays at 0.12.4. Existing ISR migration guidance from 0.13.5 still applies
when upgrading from older versions.