| 1 |
Revision history for AnyEvent::HTTP |
| 2 |
|
| 3 |
TODO: provide lwp_request function that takes an lwp http requets and returns a http response. |
| 4 |
TODO: set_proxy hook |
| 5 |
TODO: use proxy hook |
| 6 |
TODO: on_upgrade, for 101 responses? |
| 7 |
TODO: document session vs. sessionid correctly. |
| 8 |
TODO: support proxy username:password in both proxy switch and set_proxy string (dzagashev@gmail.com) |
| 9 |
TODO: remove "unexpectedly got a destructed handle" |
| 10 |
|
| 11 |
TODO: maybe read big chunks in smaller portions for chunked-encoding + on_body. |
| 12 |
TODO: callback as body (Kostirya) |
| 13 |
TODO: infinite recursion(?) (Kostirya) |
| 14 |
TODO: default rbuf_max value maybe? how about reading large chunks in small parts? |
| 15 |
TODO: servers send empty reason, which then gets mangled with linear whitespace CRLF - maybe workaround? |
| 16 |
|
| 17 |
TODO: look into http 0.9 support (Kostirya <kostirya@gmail.com>) |
| 18 |
TODO: http://appft.uspto.gov/netacgi/nph-Parser?Sect1=PTO1&Sect2=HITOFF&%23038;d=PG01&%23038;p=1&%23038;u=/netahtml/PTO/srchnum.html&%23038;r=1&%23038;f=G&%23038;l=50&%23038;s1="20110298798".PGNR.&%23038;OS=DN/20110298798&%23038;RS=DN/20110298798 |
| 19 |
TODO: cookie_jar_extract should refuse when host is an ip literal |
| 20 |
TODO: cookie_jar_et_cookie should reject cookies not matching their down server domain |
| 21 |
TODO: cookie prefixes? https://tools.ietf.org/html/draft-ietf-httpbis-cookie-prefixes-00 |
| 22 |
TODO: default rbuf_max limit for header-reading, chunk header reading etc. |
| 23 |
|
| 24 |
- too lenient stastus-line parsing caused us to mis-parse correct |
| 25 |
HTTP replies. Be less lenient by requiring literal spaces |
| 26 |
(reported by Laurent). |
| 27 |
- support invalid but real "HTTP/1.1 200\r\n" status-line |
| 28 |
(reported by Max Skorobogatov). |
| 29 |
- mark QUERY as an idempotent method. |
| 30 |
- use socks4 instead of socks4a in the AnyEvent::HTTP example when |
| 31 |
connecting to a bare ipv4 address. |
| 32 |
|
| 33 |
|
| 34 |
2.25 Mon Apr 27 14:11:40 CEST 2020 |
| 35 |
- fix incorrectly sending proxy requests to origin servers |
| 36 |
when reusing proxy connections (analyzed and testcase by Ivan Robert). |
| 37 |
- the sessionid parameter was documented as session in random |
| 38 |
places - fix docs and keep using sessionid in the code as before. |
| 39 |
- fix cookie format documentation. |
| 40 |
|
| 41 |
2.24 Thu Aug 30 03:23:03 CEST 2018 |
| 42 |
- bring cookie management more in line with RFC 6265; implement idn |
| 43 |
matching for cookie domains. |
| 44 |
- update cookie_jar version to 2, invalidate existing cookie jars. |
| 45 |
- preserve original cookie domain attribute. |
| 46 |
- also expire old cookie jars in cookie parser, just in case. |
| 47 |
- further improve relative redirection code. |
| 48 |
- comment out code that tried to detect possible bugs with persistent |
| 49 |
connection caching, but since it never triggered, it's probably |
| 50 |
working fine :) |
| 51 |
- do not call on_body callback on a response that AE::HTTP will recurse |
| 52 |
on internally (reported by Антон Онуфриев and Ruslan Zakirov). |
| 53 |
|
| 54 |
2.23 Sun Aug 28 11:30:33 CEST 2016 |
| 55 |
- relative redirects used the proxy schema instead of the request |
| 56 |
url schema to generate the new url, which is wrong (analyzed by Felix |
| 57 |
Ostmann). |
| 58 |
- fix download example (reported by Felix Ostmann). |
| 59 |
|
| 60 |
2.22 Thu May 14 04:04:03 CEST 2015 |
| 61 |
- ipv6 literals were not correctly parsed (analyzed by Raphael Geissert). |
| 62 |
- delete the body when mutating request to GET request when |
| 63 |
redirecting (reported by joe trader). |
| 64 |
- send proxy-authorization header to proxy when using CONNECT |
| 65 |
(reported by dzagashev@gmail.com). |
| 66 |
- do not send Proxy-Authroization header when not using a proxy. |
| 67 |
- when retrying a persistent request, switch persistency off. |
| 68 |
- added t/02_ip_literals.t. |
| 69 |
|
| 70 |
2.21 Mon Jun 9 01:35:54 CEST 2014 |
| 71 |
- correctly keep body when redirecting POSTs, instead of |
| 72 |
deleting them. |
| 73 |
|
| 74 |
2.2 Mon Jun 9 01:31:46 CEST 2014 |
| 75 |
- connection header was malformed (patch by Raphael Geissert). |
| 76 |
- add lots of known idempotent methods from httpbis. |
| 77 |
- implement relative location headers (rfc 7231), with fallback on URI. |
| 78 |
- add support for status code 308 from rfc 7238. |
| 79 |
- recommend URI. |
| 80 |
|
| 81 |
2.15 Wed Nov 14 23:22:07 CET 2012 |
| 82 |
- use the recurse parameter to also limit the number of retries to be |
| 83 |
done, avodiing endless loops with broken servers, as reported |
| 84 |
by Carl Chambers. |
| 85 |
|
| 86 |
2.14 Sun Apr 22 14:57:51 CEST 2012 |
| 87 |
- Time::Local::timegm croaks on out-of-range values. Don't let |
| 88 |
this disturb AnyEvent::HTTP (reported by: tell me, I forgot...). |
| 89 |
|
| 90 |
2.13 Wed Jul 27 17:53:58 CEST 2011 |
| 91 |
- garbled chunked responses caused AnyEvent::HTTP to malfunction |
| 92 |
(patch by Dmitri Melikyan). |
| 93 |
- fix GET => HEAD in one case in the documentation (James Bromberger). |
| 94 |
|
| 95 |
2.12 Tue Jun 14 07:22:54 CEST 2011 |
| 96 |
- fix a possible 'Can't call method "destroyed"' error (which would |
| 97 |
have been reported by Carl Chambers). |
| 98 |
|
| 99 |
2.11 Tue May 10 14:33:28 CEST 2011 |
| 100 |
- the keepalive session cache wouldn't take port and scheme into account |
| 101 |
when reusing connection - potentially causing information leaks |
| 102 |
(reported by Nick Kostirya). |
| 103 |
- bump AnyEvent dependency version (reported by Richard Harris). |
| 104 |
|
| 105 |
2.1 Thu Feb 24 13:11:51 CET 2011 |
| 106 |
- the keepalive and persistent parameters were actually named |
| 107 |
differently in the code - they now work as documented. |
| 108 |
- fix a bug where callbacks would sometimes never be called when |
| 109 |
the request timeout is near or below the persistent connection |
| 110 |
timeout (testcase by Cindy Wang). |
| 111 |
- destroying the guard would have no effect when a request was |
| 112 |
recursing or being retired. |
| 113 |
|
| 114 |
2.04 Sat Feb 19 07:45:24 CET 2011 |
| 115 |
- "proxy => undef" now overrides any global proxy when specified. |
| 116 |
- require scheme in urls, also use a stricter match to match urls, |
| 117 |
leading or trailing garbage is no longer tolerated. |
| 118 |
- EXPERIMENTAL: allow '=' in cookie values. |
| 119 |
|
| 120 |
2.03 Tue Jan 18 18:49:35 CET 2011 |
| 121 |
- dummy reupload, file gone from cpan somehow. |
| 122 |
|
| 123 |
2.02 Wed Jan 12 04:29:37 CET 2011 |
| 124 |
- do not lowercase cookie names, only parameter names. |
| 125 |
|
| 126 |
2.01 Tue Jan 11 07:38:15 CET 2011 |
| 127 |
- add missing dependency on common::sense. |
| 128 |
- add a resume download example. |
| 129 |
|
| 130 |
2.0 Tue Jan 4 09:16:56 CET 2011 |
| 131 |
- hopefully fully upgraded to HTTP/1.1. |
| 132 |
- support HTTP/1.1 persistent and HTTP/1.0 keep-alive connections. |
| 133 |
- drop https-proxy-connection support. seems unused and ill-specified. |
| 134 |
- use more differentiated 59x status codes. |
| 135 |
- properly use url (not proxy) hostname to verify server certificate. |
| 136 |
- much improved cookie implementation: |
| 137 |
- properly implement cookie expiry (for new cookies). |
| 138 |
- new function to expire cookies and sessions: cookie_jar_expire. |
| 139 |
- add special exception to parse broken expires= keys in |
| 140 |
set-cookie headers. |
| 141 |
- do not quote cookie values when not strictly necessary, to |
| 142 |
improve compatibility with broken servers. |
| 143 |
- accept and send lots of invalid cookie values exactly as |
| 144 |
they were received - this should not impact valid values. |
| 145 |
- lowercase cookie parameter names for improved compatibility. |
| 146 |
- support the max-age cookie parameter, overrides expires. |
| 147 |
- support cookie dates (and a few others) in parse_date. |
| 148 |
- properly support value-less parameters (e.g. secure, httponly). |
| 149 |
- do not send Host: header in a proxy CONNECT request. |
| 150 |
- use common::sense. |
| 151 |
- lowercase hostnames and schemes. |
| 152 |
- ignore leading zeroes in http version. |
| 153 |
- handle spaces in content-length headers more gracefully. |
| 154 |
|
| 155 |
1.5 Fri Dec 31 04:47:08 CET 2010 |
| 156 |
- bugfix: after headers were received, if any error occured the wrong |
| 157 |
(server-sent) Status and Reason fields would be passed to the callback. |
| 158 |
- when an error occurs during transfer, preserve status/reason. |
| 159 |
- add socks4a connect example. |
| 160 |
- new "tcp_connect" parameter. |
| 161 |
- new format_date and parse_date functions. |
| 162 |
- diagnose unexpected eof as such when the length is known. |
| 163 |
- add 205 to the responses without body. |
| 164 |
|
| 165 |
1.46 Mon Sep 6 08:29:34 CEST 2010 |
| 166 |
- some (broken) servers differentiate between empty search parts |
| 167 |
and nonexistant search parts, work around this (problem |
| 168 |
analyzed by Sergey Zasenko). |
| 169 |
- possibly increase robustness by always setting an on_error |
| 170 |
callback on the AnyEvent::Handle object (especially in case |
| 171 |
of user errors, such as nehative timeouts). |
| 172 |
- we now always follow 301/302/303 redirects and mutate POST to GET. |
| 173 |
- we now always follow 307 redirects, even for POST. |
| 174 |
- header-less responses are not parsed correctly (at a negative |
| 175 |
speed penatly :). |
| 176 |
|
| 177 |
1.45 Wed Jun 16 21:15:26 CEST 2010 |
| 178 |
- fix a bug where the handle would go away directly after a successful |
| 179 |
connect (analyzed and patch by Maxim Dounin). |
| 180 |
- due to popular demand, introduce the Redirect pseudo response header. |
| 181 |
- document URL pseudo-header better. |
| 182 |
- explain how to implement DNS caching. |
| 183 |
|
| 184 |
1.44 Sat Dec 5 16:36:20 CET 2009 |
| 185 |
- do not generate content-length on get requests (if the body is empty), |
| 186 |
as there are even more broken servers out there. |
| 187 |
- allow set_proxy to clear the proxy again. |
| 188 |
- set_proxy will now croak on invalid urls. |
| 189 |
- support overriding the Host-header (requested by Tatsuhiko Miyagawa). |
| 190 |
|
| 191 |
1.43 Fri Aug 14 17:02:02 CEST 2009 |
| 192 |
- provide on_prepare callback on common request. |
| 193 |
|
| 194 |
1.42 Wed Aug 5 18:43:01 CEST 2009 |
| 195 |
- allow suppression of auto-supplied header fields by specifying undef |
| 196 |
(requested by Mr Guest). |
| 197 |
- allow proxy scheme to be missing, as documented |
| 198 |
(reported by Mr Guest). |
| 199 |
- do not follow redirects if we do not have a location header |
| 200 |
(requested by Mr Guest). |
| 201 |
|
| 202 |
1.41 Sat Jul 25 03:27:05 CEST 2009 |
| 203 |
- correctly parse completely headerless responses (e.g. by gatling). |
| 204 |
(analysed by Robin Redeker). |
| 205 |
|
| 206 |
1.4 Tue Jul 7 02:14:53 CEST 2009 |
| 207 |
- http_request would not instantly clear the connection slot on |
| 208 |
tcp_connect failures, potentially leading to deadlocks. |
| 209 |
- fix a bug where a connection error is wrongly reported |
| 210 |
as EINPROGRESS. |
| 211 |
- new parameters: on_header, on_body, want_body_handle. |
| 212 |
- redirects will be followed when recurse is enabled whether or not |
| 213 |
the body dowload was successful or not. |
| 214 |
- include :port in Host header when given in the url (many sites break |
| 215 |
when it's always there, and many break if it's missing...). |
| 216 |
- pass the empty string, not undef, when there is no body but |
| 217 |
no error occured. |
| 218 |
- allow passing of tls_ctx, predefine two https security profiles. |
| 219 |
- ucfirst all error messages generated internally. |
| 220 |
- include "U" token in User-Agent. |
| 221 |
- document $AnyEvent::HTTP::MAX_PER_HOST. |
| 222 |
- allow empty field names in response headers (microsoft hits. microsoft |
| 223 |
hits. microsoft hits. you die). |
| 224 |
|
| 225 |
1.12 Thu Jun 11 14:45:18 CEST 2009 |
| 226 |
- $scheme wasn't optional in the proxy specification (reported by |
| 227 |
Felix Antonius Wilhelm Ostmann). |
| 228 |
|
| 229 |
1.11 Fri Nov 21 09:18:11 CET 2008 |
| 230 |
- work around a perl core bug not properly refcounting function arguments, |
| 231 |
causing "200 OK" with random body results (reported by Дмитрий Шалашов). |
| 232 |
|
| 233 |
1.1 Thu Oct 30 04:46:27 CET 2008 |
| 234 |
- work around different behaviour of AnyEvent::Handle in TLS mode. |
| 235 |
- cleanup cookie implementation, many examples and comments were |
| 236 |
provided by Дмитрий Шалашов. |
| 237 |
- document the return values of http_* functions better. |
| 238 |
- separate multiple header values by "," not "\x00" (this does not |
| 239 |
break correctly written users of the old API). |
| 240 |
- improve Set-Cookie: parsing. |
| 241 |
- add experimental https-over-http-proxy support. |
| 242 |
- downgrade https-over-https proxy to https-over-http. |
| 243 |
- ignore spurious CR characters in headers, they show up |
| 244 |
in the weirdest of places. |
| 245 |
- ucfirst the request headers, for a slightly less weird look. |
| 246 |
- work around (some) memleaks in perl regarding qr. |
| 247 |
|
| 248 |
1.05 Mon Sep 29 15:49:58 CEST 2008 |
| 249 |
- fix a regex when parsing cookie domains |
| 250 |
(patch by Дмитрий Шалашов). |
| 251 |
|
| 252 |
1.04 Thu Jul 24 08:00:46 CEST 2008 |
| 253 |
- parse reason-less http status responses. |
| 254 |
- parse more forms of broken location headers. |
| 255 |
|
| 256 |
1.03 Thu Jul 3 03:47:58 CEST 2008 |
| 257 |
- fix http_post, which was totally broken (patch by Pedro Melo). |
| 258 |
- do not recurse on POST requests, as per HTTP/1.[01] (this might |
| 259 |
change as the recommendation isn't followed by anybody else). |
| 260 |
- implement preliminary support for 303/307 redirects. |
| 261 |
|
| 262 |
1.02 Thu Jun 12 13:50:08 CEST 2008 |
| 263 |
- make the request URL available in the callback of http_request. |
| 264 |
- export http_post, http_head. |
| 265 |
|
| 266 |
1.01 Fri Jun 6 14:56:37 CEST 2008 |
| 267 |
- fixed prototypes for http_* functions |
| 268 |
|
| 269 |
1.0 Thu Jun 5 20:41:43 CEST 2008 |
| 270 |
- original version, an AnyEvent::AIO clone. |