Skip to content

chore(release): v1.6.0 - #43

Merged
karlwaldman merged 1 commit into
mainfrom
release/v1.6.0
Sep 13, 2026
Merged

karlwaldman merged 1 commit into
mainfrom
release/v1.6.0

Conversation

@karlwaldman

Copy link
Copy Markdown
Member

Cuts the release that actually delivers #36 and #37 to users.

Until this tag exists, go get installs v1.5.2 — the version that sends Authorization: Token <key> to an attacker-controlled host. Merging #36 protected nobody. Same lesson as the MCP server this morning, in a different package manager.

Why minor, not patch

Both merged changes alter observable behaviour:

  • POST, PUT, PATCH, DELETE are no longer retried. CreateWebhook was measured sending four POSTs on a single 503 — a duplicated write is worse than a failed one. GET/HEAD/OPTIONS unchanged.
  • A path without a leading / is rejected rather than concatenated. Raw("v1/prices") previously produced the host api.oilpriceapi.comv1.

What ships

Security (#36). Six probe forms previously reached a foreign host still carrying the customer's key, including a host-suffix append where .evil.invalid resolved to api.oilpriceapi.com.evil.invalid — a fully attacker-controlled domain that reads as ours. An expert review brute-forced 168,420 hostile path forms through the gate: 5,796 passed validation, 0 escaped origin.

Retry safety (#37). A real production response carried retry-after: 28197 — 7h50m — honoured uncapped on context.Background(). Measured: still blocked at the 10s cutoff before, 961µs after. Also fixes zero/negative Retry-After collapsing into a hot retry loop (four requests in ~1ms), a math.MaxInt64 value wrapping int64 nanoseconds into the same loop, and context cancellation being ignored during retry waits.

Typed errors. *InvalidPathError replaces an untyped *url.Error indistinguishable from a transport failure; *ConfigurationError replaces request failed after -1 retries: %!w(<nil>).

Verification

go test ./...   ok  16.496s
gofmt -l        clean
go vet ./...    clean

Version constant and CHANGELOG heading moved together, as release_contract_test.go requires.

Known, not in this release

WithTimeout mutates the caller's *http.Client — a confirmed data race under -race that also silently changes the timeout of any other client sharing it. Pre-existing, filed as #38, deliberately not bundled into a release PR.

🤖 Generated with Claude Code

https://claude.ai/code/session_015ao5paex73xXvuM424Libo

Minor, not patch. #36 and #37 both changed behaviour callers can observe.

Until this tag exists, `go get` installs v1.5.2 -- the version that sends
`Authorization: Token <key>` to an attacker-controlled host. Merging #36
protected nobody.

Breaking:
  * POST/PUT/PATCH/DELETE are no longer retried. CreateWebhook was observed
    sending four POSTs on a single 503.
  * A path without a leading `/` is rejected rather than concatenated.
    Raw("v1/prices") previously produced the host api.oilpriceapi.comv1.

Version constant and CHANGELOG heading moved together, as
release_contract_test.go requires.

go test ./... ok (16.496s), gofmt and go vet clean.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015ao5paex73xXvuM424Libo
@coderabbitai

coderabbitai Bot commented Sep 13, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: b1463164-6ccc-444d-933d-23dadda98cd3


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@karlwaldman
karlwaldman merged commit cd51e3a into main Sep 13, 2026
9 checks passed
@karlwaldman
karlwaldman deleted the release/v1.6.0 branch September 13, 2026 16:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant