Commit Graph
148 Commits
Author SHA1 Message Date
xixu-me 0633e71743 chore: add AGPL headers and simplify skills install docs 2026-03-22 17:32:50 +08:00
xixu-me 82c27dab5e chore: align repository docs and ci 2026-03-21 17:05:21 +08:00
xixu-me 1b67fd2ff1 refactor(core): modularize request pipeline 2026-03-20 15:36:10 +08:00
xixu-me 29e2d2c966 chore: switch license to AGPL-3.0 2026-03-16 18:31:06 +08:00
xixu-me 993570fede fix(docker): harden auth token parsing 2026-03-16 14:51:43 +08:00
xixu-me a10413eddf fix(pypi): prevent caching origin-bound rewritten index pages 2026-03-16 12:57:21 +08:00
xixu-me c76dcca460 fix(flathub): scope rewritten descriptor cache by origin 2026-03-16 01:14:33 +08:00
xixu-me dd8941d00c style: format ci-tracked files 2026-03-14 17:51:40 +08:00
xixu-me 7bec13b3e5 fix: harden proxy error handling and regression tests 2026-03-14 17:33:06 +08:00
xixu-me 7340cb481f chore: align Flathub ordering and commit guidance
Resolves #222
2026-03-14 16:45:01 +08:00
xixu-me 88c351a9ac feat: add Flathub mirror support 2026-03-14 16:23:38 +08:00
xixu-me 234692584a fix: handle docker host-style registry paths 2026-03-09 18:05:13 +08:00
xixu-me fc7e08abfc feat: refactor AI inference request detection and Docker authentication handling 2026-03-09 17:49:47 +08:00
xixu-me 929337c494 feat: update dependencies and improve request handling 2026-03-09 17:37:27 +08:00
xixu-me 3957f78d9d Revert "fix(proxy): correct registry auth and rewrite lengths"
This reverts commit cb44ddb66c.
2026-03-09 17:00:43 +08:00
xixu-me 9a666f37a0 Revert "style(proxy): format docker protocol tests"
This reverts commit 213e04de76.
2026-03-09 16:56:27 +08:00
xixu-me fe17b9a1d6 Revert "feat(platform): add ScoopInstaller support"
This reverts commit 6f0d7e15f8.
2026-03-09 13:04:37 +08:00
xixu-me 6f0d7e15f8 feat(platform): add ScoopInstaller support
Resolves #207
2026-03-08 13:05:15 +08:00
xixu-meandCopilot Autofix powered by AI 7cfcee61ba Potential fix for code scanning alert no. 17: Information exposure through a stack trace
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
2026-03-06 21:24:53 +08:00
xixu-me cc3abf89c3 fix: harden proxy behavior and stabilize ci 2026-03-06 21:10:59 +08:00
xixu-me 213e04de76 style(proxy): format docker protocol tests 2026-03-06 20:30:35 +08:00
xixu-me cb44ddb66c fix(proxy): correct registry auth and rewrite lengths 2026-03-06 20:27:43 +08:00
xixu-me 4546821023 style: format prettier violations 2026-03-06 19:45:03 +08:00
xixu-me 71e239060c fix(proxy): tighten protocol routing and stabilize tests 2026-03-06 19:41:14 +08:00
xixu-me 90b8edd53a feat: enhance security validation and caching behavior for requests with sensitive headers 2026-02-01 13:50:11 +08:00
xixu-me e2e571aef4 fix: resolve ESLint JSDoc warnings
- Remove duplicate @param in docker.js
- Remove extra blank lines after JSDoc descriptions in huggingface.js
2026-01-31 22:40:27 +08:00
xixu-me 532f690073 fix: resolve TypeScript type errors in index.js and huggingface.js
- Change env param type from 'object' to 'Record<string, unknown>'
- Store Authorization header in variable before null check
2026-01-31 22:35:22 +08:00
xixu-me c700b6acee fix: increase test timeouts and fix lint error
- Add global testTimeout (60s) and hookTimeout (30s) in vitest.config.js
- Increase timeouts for network-dependent tests in security, integration,
  and container-registry test files
- Use HEAD requests where appropriate to reduce network overhead
- Fix lint error: change 'let scope' to 'const scope' in src/index.js
2026-01-31 22:22:59 +08:00
google-labs-jules[bot] 81c44f0c71 feat: add support for Hugging Face API operations
This change enables full support for Hugging Face API requests, including repository creation, by:
1. Identifying HF API requests via path patterns.
2. Allowing POST, PUT, PATCH, and DELETE methods for these requests.
3. Correctly forwarding request bodies and headers.
4. Skipping caching for API operations.

Fixes: huggingface_hub.errors.HfHubHTTPError: Client error '405 Method Not Allowed'
2026-01-06 14:53:29 +00:00
xixu-me 29fe048984 Improve Docker redirect and auth header handling
Adds special handling for Docker registry redirects to prevent leaking Authorization headers to S3 or blob storage by using manual redirect mode and stripping sensitive headers before following redirects. Refactors scope handling for unauthorized responses and ensures retry logic for token fetches also respects Docker redirect requirements.
2025-12-12 13:29:07 +08:00
xixu-me 9fc2804332 Fix client scope in unauthorized response for cr- platforms
Adjusts the client scope in unauthorized responses to include the platform prefix for platforms starting with 'cr-'. This ensures clients request tokens with a scope that Xget can properly route.
2025-12-12 13:20:47 +08:00
xixu-me e8d7a0ef6b Refactor Docker scope extraction and 401 response
Moved Docker registry scope extraction logic into a new getScopeFromUrl function in docker.js for reuse and clarity. Updated responseUnauthorized to accept an optional scope and improved its error response format to be more Docker/OCI-compliant. Refactored index.js to use the new scope extraction and 401 response logic.
2025-12-12 13:16:21 +08:00
xixu-me 07f5f35972 Improve JSDoc types and add eslint-plugin-jsdoc
Standardized JSDoc type annotations across the codebase, replacing 'Object' with 'object' and refining function signatures for better type safety. Added and configured eslint-plugin-jsdoc for enhanced documentation linting, and updated ESLint settings to include adapters and new JSDoc rules. Updated dependencies to include eslint-plugin-jsdoc and related packages.
2025-12-11 13:27:26 +08:00
xixu-me bfec1d2d9e Add GPL license header and clean up Docker 401 handling
Added GPL license header to Netlify edge-handler.js. Removed redundant comments and clarified logic for handling Docker 401 responses in src/index.js.
2025-12-11 12:58:11 +08:00
xixu-me 5cbcd0c3d4 Add GPLv3 license headers to source files
Added GNU General Public License v3 headers to protocol and utility modules for Xget, clarifying copyright and licensing information. This ensures compliance and transparency regarding the project's open source status.
2025-12-11 12:34:10 +08:00
xixu-me ce93ea9861 Refactor integration tests and add feature-specific test suites
Moves Git, Git LFS, and authentication header forwarding tests from integration.test.js into dedicated feature test files under test/features/. Updates range-cache, security, and container-registry tests for consistency and minor improvements. Refactors src/index.js for code style and readability, especially around cache logic and error handling.
2025-12-10 16:23:44 +08:00
xixu-me 44b54580ad Add multi-platform function adapters and CI workflow
Introduces adapters for Vercel, Netlify Edge, Deno Deploy, and Cloudflare Pages, each with platform-specific entry points and configuration files. Adds a GitHub Actions CI workflow for linting, type checking, and testing. Updates lint scripts to include adapters, improves type annotations in src/index.js, and fixes a type assertion in security tests.
2025-12-10 16:08:10 +08:00
xixu-me 214e596d00 Refactor request handling and improve Docker detection
Refactored the main request handler in src/index.js for improved readability and error handling. Enhanced Docker request detection in validation.js to include additional Content-Type checks. Updated tests to increase timeouts and expand expected status codes for container registry platforms.
2025-12-10 15:47:25 +08:00
xixu-me 1c20e7af4f Refactor protocol header logic into modular helpers
Moved AI and Git protocol detection and header configuration logic from utils/validation.js and index.js into dedicated modules (src/protocols/ai.js and src/protocols/git.js). This improves code organization, modularity, and maintainability by separating protocol-specific concerns.
2025-12-10 15:25:57 +08:00
xixu-me 70ff5b248d Refactor protocol and utility logic into separate modules
Moved Docker/OCI protocol handling, performance monitoring, security, and validation logic into dedicated modules under src/protocols and src/utils. Updated src/index.js to use these new modules, improving maintainability and separation of concerns. Added pre-computed sorted platform keys for efficient matching in platform config.
2025-12-10 15:03:27 +08:00
xixu-me 89c8da936d Add transformPath utility to handle platform prefixes
Introduces the transformPath function to remove platform-specific prefixes from paths. This utility helps standardize path handling by stripping prefixes like /gh/ or /cr/docker/ based on the platform key.
2025-12-10 14:36:29 +08:00
xixu-me a6a0e97ada Refactor Docker authentication handling in handleRequest
Moved Docker authentication logic to occur before platform detection for /v2/auth paths, parsing the scope parameter to identify the registry platform and repository. Improved parsing of the WWW-Authenticate header and removed redundant Docker authentication code from the platform detection block.
2025-12-10 13:44:30 +08:00
xixu-me 80e3c26967 Transform scope parameter for container registry auth
Added logic to remove the cr/[registry]/ prefix from the scope parameter and handle official Docker Hub images by adding the library/ prefix. Updated tests to verify correct scope transformation for Docker Hub, GHCR, and official images.
2025-12-10 13:04:33 +08:00
xixu-meandCopilot Autofix powered by AI ead7afed1a Potential fix for code scanning alert no. 11: Incomplete regular expression for hostnames
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
2025-12-08 20:05:05 +08:00
xixu-me 4993444f51 Add type declarations and improve test typings
Introduces src/types.d.ts and test/types.d.ts for Cloudflare Workers and test utilities. Enhances JSDoc comments and type annotations across test files for better type safety and clarity. Updates tsconfig.json to use bundler module resolution and include additional type sources. Minor test logic and assertion improvements for robustness.
2025-12-08 19:57:48 +08:00
xixu-me d2ee1bcd37 Add eslint-config-prettier and update ESLint config
Integrated eslint-config-prettier to disable formatting rules that conflict with Prettier. Updated ESLint configuration and added the dependency to package.json for improved code formatting consistency.
2025-12-08 19:34:56 +08:00
xixu-me 7036cbd39e Refactor cacheKey request formatting
Reformats the construction of the cacheKey Request object for improved readability and consistency in indentation.
2025-12-08 19:23:07 +08:00
xixu-me d88f1911a6 Improve parsing, regex, and test consistency
Refines regex patterns for URL rewriting and authentication parsing, ensures parseInt uses radix 10 throughout, and updates test mocks and helpers for consistency. Also adds more global variables to ESLint config, improves error handling, and removes unused code in tests.
2025-12-08 19:19:10 +08:00
xixu-me a4da6607c7 Improve Content-Length detection for HEAD requests
Enhances the logic for obtaining Content-Length when a HEAD request does not return it by first attempting a Range GET for the first byte, extracting the total size from Content-Range if available, and falling back to buffering the response body for small files. This approach avoids unnecessary full downloads and improves efficiency, especially for large files.
2025-11-27 18:36:26 +08:00
xixu-me f60661db6f Refactor test helpers and add auth header forwarding tests
Modularizes test helpers into separate files for assertions, generators, and mocks, and updates imports for platform tests. Adds new tests to verify Authorization header forwarding for authenticated requests. Cleans up and simplifies test setup, and updates fixtures for clarity and maintainability.
2025-11-27 16:27:42 +08:00