Skip to content

0.20.1

Choose a tag to compare

@github-actions github-actions released this 03 Oct 09:53
· 5 commits to main since this release
0.20.1
afeaf59

What's Changed

  • fix: keep multi-step auth responses under the response body cap by @lesnik512 in #153

Body cap fix

Before this release, an auth= that takes more than one step got around max_response_body_bytes: httpx2 reads every intermediate auth response without a limit. That covers the 401 challenge of httpx2.DigestAuth and custom flows such as a token refresh that calls a token endpoint and retries. With a cap set, httpware now runs the auth flow itself. Intermediate auth responses are closed without reading their bodies; an auth that sets requires_response_body gets each response read under the cap, so an oversized one raises ResponseTooLargeError. Without a cap nothing changes.

With a cap set, these now match httpx2's own behaviour:

  • DigestAuth answers a challenge that arrives after a redirect (0.20.0 could not).
  • Credentials written into a redirect Location URL are not applied.
  • Auth steps count toward max_redirects.
  • With an auth that sets requires_response_body, stream() yields a body already read under the cap.

Full Changelog: 0.20.0...0.20.1