- Add global testTimeout (60s) and hookTimeout (30s) in vitest.config.js
- Increase timeouts for network-dependent tests in security, integration,
and container-registry test files
- Use HEAD requests where appropriate to reduce network overhead
- Fix lint error: change 'let scope' to 'const scope' in src/index.js
This change enables full support for Hugging Face API requests, including repository creation, by:
1. Identifying HF API requests via path patterns.
2. Allowing POST, PUT, PATCH, and DELETE methods for these requests.
3. Correctly forwarding request bodies and headers.
4. Skipping caching for API operations.
Fixes: huggingface_hub.errors.HfHubHTTPError: Client error '405 Method Not Allowed'
Adds special handling for Docker registry redirects to prevent leaking Authorization headers to S3 or blob storage by using manual redirect mode and stripping sensitive headers before following redirects. Refactors scope handling for unauthorized responses and ensures retry logic for token fetches also respects Docker redirect requirements.
Adjusts the client scope in unauthorized responses to include the platform prefix for platforms starting with 'cr-'. This ensures clients request tokens with a scope that Xget can properly route.
Moved Docker registry scope extraction logic into a new getScopeFromUrl function in docker.js for reuse and clarity. Updated responseUnauthorized to accept an optional scope and improved its error response format to be more Docker/OCI-compliant. Refactored index.js to use the new scope extraction and 401 response logic.
Standardized JSDoc type annotations across the codebase, replacing 'Object' with 'object' and refining function signatures for better type safety. Added and configured eslint-plugin-jsdoc for enhanced documentation linting, and updated ESLint settings to include adapters and new JSDoc rules. Updated dependencies to include eslint-plugin-jsdoc and related packages.
Added GNU General Public License v3 headers to protocol and utility modules for Xget, clarifying copyright and licensing information. This ensures compliance and transparency regarding the project's open source status.
Moves Git, Git LFS, and authentication header forwarding tests from integration.test.js into dedicated feature test files under test/features/. Updates range-cache, security, and container-registry tests for consistency and minor improvements. Refactors src/index.js for code style and readability, especially around cache logic and error handling.
Introduces adapters for Vercel, Netlify Edge, Deno Deploy, and Cloudflare Pages, each with platform-specific entry points and configuration files. Adds a GitHub Actions CI workflow for linting, type checking, and testing. Updates lint scripts to include adapters, improves type annotations in src/index.js, and fixes a type assertion in security tests.
Refactored the main request handler in src/index.js for improved readability and error handling. Enhanced Docker request detection in validation.js to include additional Content-Type checks. Updated tests to increase timeouts and expand expected status codes for container registry platforms.
Moved AI and Git protocol detection and header configuration logic from utils/validation.js and index.js into dedicated modules (src/protocols/ai.js and src/protocols/git.js). This improves code organization, modularity, and maintainability by separating protocol-specific concerns.
Moved Docker/OCI protocol handling, performance monitoring, security, and validation logic into dedicated modules under src/protocols and src/utils. Updated src/index.js to use these new modules, improving maintainability and separation of concerns. Added pre-computed sorted platform keys for efficient matching in platform config.
Introduces the transformPath function to remove platform-specific prefixes from paths. This utility helps standardize path handling by stripping prefixes like /gh/ or /cr/docker/ based on the platform key.
Moved Docker authentication logic to occur before platform detection for /v2/auth paths, parsing the scope parameter to identify the registry platform and repository. Improved parsing of the WWW-Authenticate header and removed redundant Docker authentication code from the platform detection block.
Added logic to remove the cr/[registry]/ prefix from the scope parameter and handle official Docker Hub images by adding the library/ prefix. Updated tests to verify correct scope transformation for Docker Hub, GHCR, and official images.
Introduces src/types.d.ts and test/types.d.ts for Cloudflare Workers and test utilities. Enhances JSDoc comments and type annotations across test files for better type safety and clarity. Updates tsconfig.json to use bundler module resolution and include additional type sources. Minor test logic and assertion improvements for robustness.
Integrated eslint-config-prettier to disable formatting rules that conflict with Prettier. Updated ESLint configuration and added the dependency to package.json for improved code formatting consistency.
Refines regex patterns for URL rewriting and authentication parsing, ensures parseInt uses radix 10 throughout, and updates test mocks and helpers for consistency. Also adds more global variables to ESLint config, improves error handling, and removes unused code in tests.
Enhances the logic for obtaining Content-Length when a HEAD request does not return it by first attempting a Range GET for the first byte, extracting the total size from Content-Range if available, and falling back to buffering the response body for small files. This approach avoids unnecessary full downloads and improves efficiency, especially for large files.
Modularizes test helpers into separate files for assertions, generators, and mocks, and updates imports for platform tests. Adds new tests to verify Authorization header forwarding for authenticated requests. Cleans up and simplifies test setup, and updates fixtures for clarity and maintainability.