0.20.1
What's Changed
- fix: keep multi-step auth responses under the response body cap by @lesnik512 in #153
Body cap fix
Before this release, an auth= that takes more than one step got around max_response_body_bytes: httpx2 reads every intermediate auth response without a limit. That covers the 401 challenge of httpx2.DigestAuth and custom flows such as a token refresh that calls a token endpoint and retries. With a cap set, httpware now runs the auth flow itself. Intermediate auth responses are closed without reading their bodies; an auth that sets requires_response_body gets each response read under the cap, so an oversized one raises ResponseTooLargeError. Without a cap nothing changes.
With a cap set, these now match httpx2's own behaviour:
DigestAuthanswers a challenge that arrives after a redirect (0.20.0 could not).- Credentials written into a redirect
LocationURL are not applied. - Auth steps count toward
max_redirects. - With an auth that sets
requires_response_body,stream()yields a body already read under the cap.
Full Changelog: 0.20.0...0.20.1