Repository navigation
chore(release): v1.6.0 - #43
Merged
Merged
Conversation
Minor, not patch. #36 and #37 both changed behaviour callers can observe. Until this tag exists, `go get` installs v1.5.2 -- the version that sends `Authorization: Token <key>` to an attacker-controlled host. Merging #36 protected nobody. Breaking: * POST/PUT/PATCH/DELETE are no longer retried. CreateWebhook was observed sending four POSTs on a single 503. * A path without a leading `/` is rejected rather than concatenated. Raw("v1/prices") previously produced the host api.oilpriceapi.comv1. Version constant and CHANGELOG heading moved together, as release_contract_test.go requires. go test ./... ok (16.496s), gofmt and go vet clean. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015ao5paex73xXvuM424Libo
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Cuts the release that actually delivers #36 and #37 to users.
Until this tag exists,
go getinstalls v1.5.2 — the version that sendsAuthorization: Token <key>to an attacker-controlled host. Merging #36 protected nobody. Same lesson as the MCP server this morning, in a different package manager.Why minor, not patch
Both merged changes alter observable behaviour:
POST,PUT,PATCH,DELETEare no longer retried.CreateWebhookwas measured sending four POSTs on a single 503 — a duplicated write is worse than a failed one.GET/HEAD/OPTIONSunchanged./is rejected rather than concatenated.Raw("v1/prices")previously produced the hostapi.oilpriceapi.comv1.What ships
Security (#36). Six probe forms previously reached a foreign host still carrying the customer's key, including a host-suffix append where
.evil.invalidresolved toapi.oilpriceapi.com.evil.invalid— a fully attacker-controlled domain that reads as ours. An expert review brute-forced 168,420 hostile path forms through the gate: 5,796 passed validation, 0 escaped origin.Retry safety (#37). A real production response carried
retry-after: 28197— 7h50m — honoured uncapped oncontext.Background(). Measured: still blocked at the 10s cutoff before, 961µs after. Also fixes zero/negativeRetry-Aftercollapsing into a hot retry loop (four requests in ~1ms), amath.MaxInt64value wrapping int64 nanoseconds into the same loop, and context cancellation being ignored during retry waits.Typed errors.
*InvalidPathErrorreplaces an untyped*url.Errorindistinguishable from a transport failure;*ConfigurationErrorreplacesrequest failed after -1 retries: %!w(<nil>).Verification
Version constant and CHANGELOG heading moved together, as
release_contract_test.gorequires.Known, not in this release
WithTimeoutmutates the caller's*http.Client— a confirmed data race under-racethat also silently changes the timeout of any other client sharing it. Pre-existing, filed as #38, deliberately not bundled into a release PR.🤖 Generated with Claude Code
https://claude.ai/code/session_015ao5paex73xXvuM424Libo