v12.1.1
What's Changed
Two fixes reported by an external integrator building Anchor against the SDK.
Path builders now encode caller input (#670)
apiPaths.ts interpolated slugs, addresses, token ids and transaction hashes into URL paths as bare template literals. 61 of its 88 builders take a parameter and none encoded it, so a value containing / re-targeted the request at a different endpoint once the URL was normalized, and a consumer caching by path collided with the endpoint it landed on. The segment() helper that walletAuth.ts already used is now shared and applied at all 100 interpolation sites.
segment() throws a RangeError for a value of exactly . or ... Encoding cannot neutralize those: the WHATWG URL parser decodes percent-escapes before it removes dot segments, so %2E%2E collapses the same way .. does. Encoding is a no-op for every legitimate value, so the only calls affected are ones forwarding unvalidated input.
getAgentProfileRelationships no longer encodes at its call site, which would otherwise double-encode.
Every API error carries a status code (#672)
Only the rate-limit path attached statusCode. Everything else threw a bare Error whose message was built from the response body, so a caller could not separate a retryable 503 from a permanent 400 without parsing prose, and a client that scrubs remote error text could not recover the status at all. statusCode is now present on every error thrown for a non-OK response, with responseBody alongside it when a body was parsed.
OpenSeaApiError is the type for this. OpenSeaRateLimitError remains as an alias with the identical shape, so existing rate-limit handling is unaffected.
Also
Picks up @opensea/api-types 0.9.2.
Full Changelog: v12.1.0...v12.1.1