Releases: h3js/h3
Releases · h3js/h3
Release list
v2.0.1-rc.31
v2.0.1-rc.30
🩹 Fixes
- session: Do not persist a session that is only read (#1541)
- cli: Resolve docs directory to file system path with fileURLToPath (#1540, 04a78a0)
💅 Refactors
- core: Compose route middleware in the dispatcher (#1533)
🌊 Types
- handler: Expose validated query/headers on validated hander type (#1538)
🏡 Chore
- Update srvx to v1 (81440ec)
✅ Tests
- cli: Assert docs command spawns without a shell (07273db)
❤️ Contributors
- Pooya Parsa (@pi0)
- Dương Ngọc Anh (@koding88)
- Liang Xu (@lx3133584)
- Daniel Roe (@danielroe)
v2.0.1-rc.29
v2.0.1-rc.28
🩹 Fixes
- static: Keep a leading separator run from bypassing a route guard (f3e4c46)
- proxy: Strip tab/LF/CR from internal proxy targets (ffd9620)
- proxy: Do not include upstream failure message in gateway error (936f14b)
- response: Normalize values thrown from the
onErrorhook (2d6a10a) - response: Detect
HTTPResponseby brand instead ofconstructor.name(0bbcbc4) - fromNodeHandler: Don't hang the event when a piped client disconnects (373e32a)
- handler: Run middleware for object syntax with fetch (cf7e585)
- response: Call the
onErrorhook again (f176b35) - static: Refuse a non-canonical pathname instead of resolving it (baef4b9)
📖 Documentation
v2.0.1-rc.27
🚀 Enhancements
- New route rules engine (#1524) (docs)
- session: Add opt-in
idleTimeoutfor sliding expiration (#1513)
🩹 Fixes
- session: Encode large payloads outside node-compatible runtimes (#1515)
- event:
⚠️ Decode only needless escapes in the pathname (#1526) - middleware: Match
use()route filters with rou3 (d9d3124) - response: Sanitize
statusandstatusText(8e69593) - Normalize route patterns as pathnames (cbd5c73)
- middleware: Compare method scopes case-insensitively (850f25c)
- request: Compare methods case-insensitively in isMethod (#1528)
- proxy: Keep internal targets on the app origin (07d22ec)
- json-rpc:
⚠️ Require JSON content-type, validate origin and cap batch size (72d8e05) - fingerprint:
⚠️ Default toSHA-256and disambiguate components (51e68cd) - cookie: Keep unparseable set-cookie headers when merging (175ba5c)
- static: Keep encoded backslashes opaque in the asset id (ab3f23c)
- request: Keep the request proxy cache from shadowing real properties (c71f5c0)
- proxy:
⚠️ xfwd must not let clientx-forwarded-*headers win (0c7429e) - response: Keep prepared headers from accumulating on reused Responses (9f766d9)
- request: Keep a malformed
x-forwarded-hostfrom stripping the real port (429b994) - request:
⚠️ Keep the host header from steering the synthesized URL (2b59a3a) - rules: Keep a route-scoped cache rule from deadlocking the request (484ec58)
- route: Keep
removeRoutefrom unregistering sibling routes (94d0edd)
📖 Documentation
- Clarify getRouterParams decode is a single pass (44621f3)
- rules: Cache rule ends the global middleware chain on misses too (9f3eea3)
📦 Build
- Prevent malformed pathname guard from being tree-shaken (fa00775)
❤️ Contributors
- Shree Bohara (@ShreeBohara)
- Pooya Parsa (@pi0 @pi0x)
- Vijay Misal (@vjymisal0)
- Jayesh Bhade (@Jaybhade)
v2.0.1-rc.26
🚀 Enhancements
- resolveDotSegments: Add
mergeSlashesoption (9581407) - session: Default session cookie to
SameSite=Lax(acf8d77) ⚠️ Escape interpolated values in html tagged template (#1459)- readValidatedBody: Support readBody options (#1476)
- Add
onDisposehook (#1488) - defineValidatedHandler: Support async validation (#1491)
- sse: Allow returning EventStream directly from handlers (#1508)
🔥 Performance
- Single-scan fast-path guard for
resolveDotSegments(#1458) - cookie: Avoid quadratic chunked cookie parsing and header rebuilds (#1472)
- middleware: Precompose middleware chains (#1475)
- body-limit: Stream enforcement instead of pre-buffering (#1500)
🩹 Fixes
- resolveDotSegments: Preserve trailing slash on trailing dot segments (ca7de07)
- cookie: Dedup cookies with leading-dot / mixed-case domains (#1462)
- cors: Warn on credentials with null origin (#1464)
- Decode Basic-auth credentials as UTF-8 (#1463)
- proxy: forwardHeaders must not override framing headers (#1467)
- cookie: Cap chunk count in
setChunkedCookie(#1469) - cors: Set single-valued CORS headers instead of appending (#1466)
- auth: Harden basic-auth realm handling and credential timing (#1468)
- validate: Convert malformed JSON to 400 in validated-handler path (#1465)
- base: Collapse leading-slash run in all base-stripping sites (#1471)
- html: Make
raw()trust marker unforgeable and hoist escape map (#1473) - json-rpc: Use
-32600for valid-JSON non-object bodies (#1483) - Only discard prepared headers for error responses (#1486)
- event-stream: Correct stream teardown on close and client disconnect (#1484)
- deprecated: Correct v1 signatures in the compat shim (#1492)
- response: Do not render non-Error throws as successful responses (#1485)
- event: Keep
event.contextandreq.contextas one reference (#1499) - response: Absorb errors thrown in
onResponsehook (4a32c1b) - response: Route synchronous
prepareResponsethrows through the error pipeline (#1503) - response: Keep
content-lengthheader forUint8Arrayresponses (#1504) - response: Strip
HEADbody when merging prepared headers into a mutable Response (#1490) - response: Allow status and headers staged during the first stream chunk (#1512)
💅 Refactors
- request:
⚠️ Makex-forwarded-prototrust opt-in (#1461) - event-stream:
⚠️ Drop autoclose option (#1495) - sse: Promote EventStream to public API, deprecate
createEventStream(#1509)
📖 Documentation
- Security caveats for cors, proxy, redirect, host and static utils (#1470)
- Explain
event.url.pathnamedecoding (3f8b5bc)
🌊 Types
🏡 Chore
- Update srvx to 0.12 (5eb0a01) (release notes)
- Update undocs (ba42947)
❤️ Contributors
- Pooya Parsa (@pi0)
- N0liu (@n0liu)
- G1mn
- Sandro Circi (@sandros94)
- Max (@onmax)
v2.0.1-rc.25
v2.0.1-rc.24
🚀 Enhancements
- Add QUERY method support (#1445)
- Add
requireContentTypeandappendAcceptQueryutils (#1446) - Automatically match GET routes for HEAD requests (#1452)
🩹 Fixes
- json-rpc: Do not leak internal exception messages to clients (ea2f2a3)
- request: Prevent
decode:truefrom reintroducing path separators (cd03d41) - handleCacheHeaders: Correct conditional-request precedence and Cache-Control default (#1454)
📖 Documentation
- Fix typos in response and handler guides (#1444)
- Add QUERY method docs (#1447)
- Remove non-existent sendEventStream from createEventStream example (#1450)
❤️ Contributors
- Pooya Parsa (@pi0)
- Sueun Cho (@sueun-dev)
- Prateek Anand (@bizprat)
- Max (@maxtaran2010)
v2.0.1-rc.23
🚀 Enhancements
- proxy: Support client aborts (#1417)
- ws: Allow optional HTTP handling in
defineWebSocketHandler(#1425) - Export
resolveDotSegmentsas a public path utility (#1428, #1430) - readBody: Support
formdatatype (#1164)
🩹 Fixes
- sanitizeStatusCode: Return default for non-numeric input instead of
NaN(#1420) - auth: Reject Basic credentials with no colon separator (#1393)
- sse: Ignore pushes after stream close (#1411)
- proxy: Ignore incoming accept-encoding header (#1423)
- cache:
handleCacheHeadersignores multi-valueIf-None-Matchheader (#1395) - serve-static: Compare if-modified-since at whole-second precision (#1394)
- request: Parse first entry of comma-list
x-forwarded-protoheader (#1413) - serve-static: Check the response (not request) for an existing content-length (#1391)
- cors: Merge Vary headers when both origin and allow-headers emit vary (#1396)
- writeEarlyHints: Normalize Link key to prevent hanging with Node.js (#1385)
- event: Return 400 for malformed percent-encoded request URLs (#1424)
- mount: Restore pathname on error with try/finally (#1319)
- serve-static: Decode the resolved id before lookup (#1431)
- request: Shadow parsed
_urlinrequestWithURLproxy (d21d93c) - event: Clone URL for pathname normalization instead of mutating shared
_url(a1cf066) - adapters: Sync raw node
req.urlwithevent.urlinfromNodeHandler(#1433)
💅 Refactors
- validate: Drop always-true
if (validate.body)guard in body proxy (#1392)
📖 Documentation
- proxy: Add note about reading body (7eb018e)
- Fix decode function name in router param helpers (#1419)
- session: Note secure cookie limitation over local HTTP (#1409)
- Document the session name option for multiple sessions (#1405)
- Add arkstack framework to community section (#1382)
- ws: Use zero-config crossws server plugin (#1427)
🌊 Types
- Expose
.crosswsondefineWebSocketHandlerreturn type (#1435)
✅ Tests
- Cover zod schema query validation types (#1404)
- Cover cloned pipeable node responses (#1414)
- iron-crypto: Accept getRandomValues length error for invalid salt bits (dae12fe)
- event: Cover shared
\_urlnormalization semantics (4a218a8) - event: Assert
req.urlreflects normalization per runtime (8410ec9)
❤️ Contributors
- Pooya Parsa (@pi0)
- Huseeiin (@huseeiin)
- M.M (@momomuchu)
- Wind (@productdevbook)
- Iain Sproat (@iainsproat)
- Frank Johnston
- Mixelburg (@mixelburg)
- Legacy (@3m1n3nc3)
- Shaurya Singh (@LeSingh1)
- Pupuking723
- Harsh Agarwal
- Aimee (@Aimee1608)
- Alan747271363-art
- Greymoth
- Patrick Wehbe (@patrickwehbe)
- Shawn
- Alexander Kireyev (@chatman-media)