You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit f8de24e
Browse filesBrowse the repository at this point in the historyBrowse files
Keep caller spelling of header names and match names case-insensitively (#1378)
* Keep caller spelling of header names and match names case-insensitively
HTTP.jl 2.0 through 2.7 canonicalized every header name on insertion
(`providerId` became `Providerid`) because lookups compared stored names
with `==` against a canonicalized key. HTTP.jl 1.x kept the caller's
spelling and only canonicalized when `canonicalize_headers=true`, which
was off by default. Servers that treat header names as case-sensitive
data, such as Azure Service Bus custom properties, received the rewritten
names, and 2.x offered no opt-out: `canonicalize_headers=false` only
logged a "has no effect" warning.
Fix the cause instead of the spelling: every `Headers` lookup and update
(`header`, `headers`, `haskey`, `hasheader`, `setheader`, `appendheader`,
`removeheader`, `headercontains`, `header_keys`, `merge!`) now matches
names with an ASCII case fold, so stored names no longer need to be
canonical and insertion keeps them as given. HTTP/1 sends them as
spelled; HTTP/2 still lowercases. The HTTP/1 parser already
canonicalized received names; the HTTP/2 client and server decoders now
do so explicitly, so received messages look the same as before. The few
exact-name checks outside the helpers (default Accept-Encoding, HTTP/2
Host-vs-:authority, request display) fold case too.
`canonicalize_headers=true` rewrites request header names into
`canonical_header_key` form again, as in 1.x, and the keyword no longer
warns.
Fixes#1377.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* Keep case-insensitive header enumeration linear
---------
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
- `max_decompressed_size`: cap, in bytes, on an auto-decompressed response body; reading past it throws `DecompressionLimitError`, guarding against decompression bombs. Defaults to 64 MiB; `0` disables the limit
2328
2340
- `sse_callback`: callback receiving `(event)` or `(stream, event)` for
@@ -2354,7 +2366,7 @@ Keyword arguments:
2354
2366
HTTP.jl 2.0 accepts several HTTP.jl 1.x keywords as migration shims:
2355
2367
`readtimeout` maps to `read_idle_timeout`; `pool`, `retry_delays`,
2356
2368
`retry_check`, `sslconfig`, `socket_type_tls`,
2357
-
`canonicalize_headers`, `detect_content_type`, `logerrors`, `logtag`, and
2369
+
`detect_content_type`, `logerrors`, `logtag`, and
2358
2370
`observelayers` are accepted so older call sites fail less abruptly. Prefer the
2359
2371
2.0 forms listed above for new code: `client` / `transport` for pooling,
2360
2372
`retry_if` / `retry_bucket` for retries, Reseau `Transport` TLS configuration
0 commit comments