impit-python@0.13.0
Changelog
All notable changes to this project will be documented in this file.
py-0.13.0 - 2026-06-19
Bug Fixes
-
Decode non-ASCII response header values as ISO-8859-1 (#434)
-
Use browser-matching multipart boundary format (#435)
- Moves multipart boundary generation from JS to Rust where the browser fingerprint is available. Each browser profile now produces boundaries matching the real browser format: - Chrome:
----WebKitFormBoundary+ 16 alphanumeric chars - Firefox:----geckoformboundary+ two random uint64 hex values - OkHttp: UUID v4 (xxxxxxxx-xxxx-4xxx-yxxx-xxxxxxxxxxxx) - No fingerprint:----formdata-impit-*(default, unchanged) The boundary is generated lazily — the NAPI call only happens when the body is actually aFormDatainstance. The method is not exposed in public types.
- Moves multipart boundary generation from JS to Rust where the browser fingerprint is available. Each browser profile now produces boundaries matching the real browser format: - Chrome:
-
Migrate
http3DNS lookup fromhickory-clienttohickory-resolver(#454)impit/src/http3.rsonly used hickory to fire a single HTTPS-record DNS query against a hard-coded8.8.8.8:53for h3 discovery. Migrated that tohickory-resolver 0.26.1, which: - pulls in the patchedhickory-proto 0.26.1, - uses the system DNS config instead of hard-coding Google's resolver, - drops the manual background-task plumbing andDropimpl since the resolver manages its own connections. API shifts handled along the way:Record::data()→Record.data(now a public field),SVCB::svc_params()→SVCB.svc_params(public field).
-
Share browser-string resolution across sync and async clients (#481)
- The sync and async Python clients each hand-maintained their own
browserstring → fingerprint match, and the two had drifted. The async client mappedchrome124to thechrome_125fingerprint (mislabeled, even though a realchrome_124fingerprint exists in the core database), while the sync client didn't recognizechrome124at all and fell back topanic!("Unsupported browser"), aborting across the FFI boundary instead of raising a catchable Python exception. The barechromealias is intentionally left atchrome_125in both clients to preserve current behavior and the pinned JA4 test.
- The sync and async Python clients each hand-maintained their own
-
Raise on mid-stream body errors instead of silent EOF (#482)
- Mid-stream body errors (connection reset, truncated chunked transfer) were mapped to
StopIteration/StopAsyncIteration, which signal normal end-of-iteration — sofor/async forended silently and callers processed partial bodies as complete (a silent data-integrity bug, #475). Both sync and async iterators now propagate the classifiedImpitErroras a real exception and set the consumed/closed flags consistently with the clean-EOF branch. Streamed truncation surfaces in reqwest as aDecode-kinded error rather thanBody, so the existing unexpected-EOF classification missed it and fell through to the catch-allHTTPError. The guard is widened to coveris_decode(), so truncated streams now raiseRemoteProtocolError, matching httpx. Verified against a vanilla server that truncates the body mid-response; added sync + async regression tests.
- Mid-stream body errors (connection reset, truncated chunked transfer) were mapped to
Features
-
Add new OkHTTP fingerprints (#416)
- Adds profiles for emulating the fingerprints of the OkHTTP library (JVM / Android HTTP client).
-
Return the
vanillaFallbackoption as an alternative for failing requests (#441)- The
vanillaFallbackoption has been noop in a few of the latest versions ofimpit. The changes from this PR return this feature to support, e.g., servers with old TLS stacks that uncover some of the emulation discrepancies and cause the requests to fail.
- The
-
Add iOS 18 system TLS fingerprint (#465)
- Adds an iOS 18 system TLS fingerprint as
Browser::Ios18(string:"ios18").
- Adds an iOS 18 system TLS fingerprint as