genie-server
genie-server copied to clipboard
Bump ws from 7.5.6 to 8.8.1
Bumps ws from 7.5.6 to 8.8.1.
Release notes
Sourced from ws's releases.
8.8.1
Bug fixes
- The
AuthorizationandCookieheaders are no longer sent if the original request for the opening handshake is sent to an IPC server and the client is redirected to another IPC server (bc8bd34e).8.8.0
Features
- Added the
WS_NO_BUFFER_UTILandWS_NO_UTF_8_VALIDATEenvironment variables (becf237c).8.7.0
Features
- Added the ability to inspect the invalid handshake requests and respond to them with a custom HTTP response. (6e5a5ce3).
Bug fixes
- The handshake is now aborted if the
Upgradeheader field value in the HTTP response is not a case-insensitive match for the value "websocket" (0fdcc0af).- The
AuthorizationandCookieheaders are no longer sent when following an insecure redirect (wss: to ws:) to the same host (d68ba9e1).8.6.0
Features
- Added the ability to remove confidential headers on a per-redirect basis (#2030).
8.5.0
Features
- Added the ability to use a custom
WebSocketclass on the server (#2007).Bug fixes
- When following redirects, the
AuthorizationandCookieheaders are no longer sent if the redirect host is different from the original host (#2013).8.4.2
Bug fixes
- Fixed a data framing issue introduced in version 8.4.1 (#2004).
8.4.1
Notable changes
- To improve performance, strings sent via
websocket.ping(),
... (truncated)
Commits
9753821[dist] 8.8.1bc8bd34[security] Fix same host check for ws+unix: redirects0ae302a[test] Fix nits1117af6[doc] Fix typo (#2062)3b6af82[minor] Prevent opening handshake headers from being overridden982b782[dist] 8.8.0becf237[feature] Add theWS_NO_{BUFFER_UTIL, UTF_8_VALIDATE}variables0792742[doc] Fix nitc1a126f[doc] Rename WS Error Codes section to Error codesa6dbd1c[ci] Set permissions explicitly (#2051)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)