This change enables full support for Hugging Face API requests, including repository creation, by:
1. Identifying HF API requests via path patterns.
2. Allowing POST, PUT, PATCH, and DELETE methods for these requests.
3. Correctly forwarding request bodies and headers.
4. Skipping caching for API operations.
Fixes: huggingface_hub.errors.HfHubHTTPError: Client error '405 Method Not Allowed'
Adds special handling for Docker registry redirects to prevent leaking Authorization headers to S3 or blob storage by using manual redirect mode and stripping sensitive headers before following redirects. Refactors scope handling for unauthorized responses and ensures retry logic for token fetches also respects Docker redirect requirements.
Adjusts the client scope in unauthorized responses to include the platform prefix for platforms starting with 'cr-'. This ensures clients request tokens with a scope that Xget can properly route.
Moved Docker registry scope extraction logic into a new getScopeFromUrl function in docker.js for reuse and clarity. Updated responseUnauthorized to accept an optional scope and improved its error response format to be more Docker/OCI-compliant. Refactored index.js to use the new scope extraction and 401 response logic.
Standardized JSDoc type annotations across the codebase, replacing 'Object' with 'object' and refining function signatures for better type safety. Added and configured eslint-plugin-jsdoc for enhanced documentation linting, and updated ESLint settings to include adapters and new JSDoc rules. Updated dependencies to include eslint-plugin-jsdoc and related packages.
Moves Git, Git LFS, and authentication header forwarding tests from integration.test.js into dedicated feature test files under test/features/. Updates range-cache, security, and container-registry tests for consistency and minor improvements. Refactors src/index.js for code style and readability, especially around cache logic and error handling.
Introduces adapters for Vercel, Netlify Edge, Deno Deploy, and Cloudflare Pages, each with platform-specific entry points and configuration files. Adds a GitHub Actions CI workflow for linting, type checking, and testing. Updates lint scripts to include adapters, improves type annotations in src/index.js, and fixes a type assertion in security tests.
Refactored the main request handler in src/index.js for improved readability and error handling. Enhanced Docker request detection in validation.js to include additional Content-Type checks. Updated tests to increase timeouts and expand expected status codes for container registry platforms.
Moved AI and Git protocol detection and header configuration logic from utils/validation.js and index.js into dedicated modules (src/protocols/ai.js and src/protocols/git.js). This improves code organization, modularity, and maintainability by separating protocol-specific concerns.
Moved Docker/OCI protocol handling, performance monitoring, security, and validation logic into dedicated modules under src/protocols and src/utils. Updated src/index.js to use these new modules, improving maintainability and separation of concerns. Added pre-computed sorted platform keys for efficient matching in platform config.
Introduces the transformPath function to remove platform-specific prefixes from paths. This utility helps standardize path handling by stripping prefixes like /gh/ or /cr/docker/ based on the platform key.
Moved Docker authentication logic to occur before platform detection for /v2/auth paths, parsing the scope parameter to identify the registry platform and repository. Improved parsing of the WWW-Authenticate header and removed redundant Docker authentication code from the platform detection block.
Added logic to remove the cr/[registry]/ prefix from the scope parameter and handle official Docker Hub images by adding the library/ prefix. Updated tests to verify correct scope transformation for Docker Hub, GHCR, and official images.
Integrated eslint-config-prettier to disable formatting rules that conflict with Prettier. Updated ESLint configuration and added the dependency to package.json for improved code formatting consistency.
Refines regex patterns for URL rewriting and authentication parsing, ensures parseInt uses radix 10 throughout, and updates test mocks and helpers for consistency. Also adds more global variables to ESLint config, improves error handling, and removes unused code in tests.
Enhances the logic for obtaining Content-Length when a HEAD request does not return it by first attempting a Range GET for the first byte, extracting the total size from Content-Range if available, and falling back to buffering the response body for small files. This approach avoids unnecessary full downloads and improves efficiency, especially for large files.
Modularizes test helpers into separate files for assertions, generators, and mocks, and updates imports for platform tests. Adds new tests to verify Authorization header forwarding for authenticated requests. Cleans up and simplifies test setup, and updates fixtures for clarity and maintainability.
Standardized terminology by changing 'Cloudflare Worker' to 'Cloudflare Workers' across documentation, workflow comments, and code. Expanded deployment instructions in README to include Cloudflare Pages and EdgeOne Pages, clarified secrets setup, and improved deployment notes for self-hosting.
Update request handling to redirect root, invalid platform prefixes, and platform prefixes without resource paths to the homepage. Adjust tests to expect 302 redirects instead of 404 or 400 responses for these cases.
This commit converts the entire Xget application from a Cloudflare Worker
to a Cloudflare Page, enabling static asset hosting while maintaining all
existing functionality.
Changes:
- Add functions/[[path]].js: Catch-all Pages Function handler
- Add public/index.html: Landing page with Xget information
- Update src/index.js: Export handleRequest for Pages Function import
- Update wrangler.toml: Configure for Pages deployment
- Update package.json: Change scripts to use Pages commands
- Update vitest.config.js: Include functions/ in coverage
- Update .github/workflows/depoly.yml: Deploy to Pages
- Update documentation: CLAUDE.md, README.md, README.en.md
The conversion maintains full backward compatibility with existing tests
and functionality. All caching strategies, security headers, and protocol
handling remain unchanged.
Enhances cache logic to ensure compatibility with non-Cloudflare environments by checking for cache API availability. Refactors cache key construction to always use GET method, adds error handling for cache operations, and ensures only GET requests are cached. Improves robustness and prevents runtime errors when cache API is unavailable.
Added Podman deployment instructions and badges to both English and Chinese README files. Updated several badge colors for consistency. Introduced new scripts for badge color fixes. Updated dependencies in package.json and package-lock.json. Added scripts/README.md and scripts/fix-badge-colors.js for badge management.
Updated the request handling logic in src/index.js to include isGitLFS in conditions for setting request body, copying headers, and returning responses. This ensures proper handling of Git LFS operations alongside Git, Docker, and AI requests.
Introduces detection and handling for Git LFS (Large File Storage) operations, including LFS-specific endpoints, headers, and user agents. Updates request validation, header management, and cache logic to properly support LFS requests and ensure real-time data synchronization. Adds comprehensive integration and unit tests for LFS scenarios, and documents the new behavior in CLAUDE.md.
This commit adds support for Docker Hub (registry-1.docker.io) as a container registry platform with special authentication handling for official images.
Changes:
- Add 'cr-docker' platform pointing to https://registry-1.docker.io in platforms.js
- Implement special authentication scope handling for Docker Hub official images
- Docker Hub stores official images (nginx, redis, etc.) as library/nginx, library/redis
- Single-component image names are automatically prefixed with 'library/' for authentication
- Multi-component names (user/image) are passed through unchanged
- Add comprehensive tests for Docker Hub support
This resolves the issue where pulling public images from Docker Hub would prompt for authentication incorrectly. The library prefix is now automatically added to the authentication scope for single-name images, allowing proper anonymous access to public official images.
Test coverage:
- Official images (single-name): /cr/docker/v2/nginx/manifests/latest
- User images (namespaced): /cr/docker/v2/nginxinc/nginx-unprivileged/manifests/latest
- GET and HEAD request methods verified
All Docker Hub specific tests pass.
Enhances caching strategy to only cache 200 responses (not 206), supports serving range requests from cached full content, and avoids compression for media files to ensure proper byte-range support. Adds comprehensive tests for range request caching, media file handling, cache key management, and performance metrics.
Introduces isAIInferenceRequest to detect AI inference API requests and updates request validation, caching, and header logic to support AI endpoints. Ensures proper content type and User-Agent headers for AI requests and skips caching for these operations, similar to Git and Docker requests.
Added support and documentation for AOSP (Android Open Source Project), CPAN (Perl), and CTAN (TeX/LaTeX) mirrors in both English and Chinese README files. Updated src/config/platforms.js to include these platforms. No functional changes to request handling logic.
Adds special handling for HEAD requests to guarantee the Content-Length header is present. If the initial HEAD response lacks this header, a GET request is performed to retrieve or calculate the correct Content-Length value.
This commit removes all code, documentation, and tests related to the PyTorch platform. PyTorch is no longer listed as a supported platform in the configuration, README files, or test suites.
Refactors PyTorch path transformation logic and enhances URL rewriting for PyTorch wheel index pages to handle both absolute and relative links. Removes unnecessary cache skipping for PyTorch index pages and adds dedicated tests for PyTorch URL rewriting and path transformation.
Added special handling for PyTorch pip index requests to skip cache and set shorter cache duration for index pages. Updated URL rewriting logic to correctly rewrite PyTorch download URLs in HTML responses. Refactored code to distinguish between npm and PyTorch URL rewriting and clarified path transformation for PyTorch in the config.
Introduces PyTorch platform support with URL rewriting for wheel index pages in src/index.js. Updates documentation in both English and Chinese READMEs to reflect new PyTorch installation URLs and verification steps. Adds comprehensive tests for PyTorch proxying, URL transformation, and error handling in test/index.test.js and new test/pytorch.test.js.
Introduces a createConfig function to generate configuration from environment variables, enabling dynamic overrides for deployment environments. Refactors request validation and error responses to use the new config and a standardized error response helper. Updates caching logic to only cache GET and HEAD requests, and rewrites response body handling for platform-specific URL rewrites. Sets package type to 'module' in package.json.
Eliminated Docker Hub-specific configuration, path/scope transforms, and related documentation. Deleted src/config/docker.js and its tests, removed Docker Hub from supported platforms, and refactored code to use generic container registry logic. This simplifies the codebase by dropping special handling for Docker Hub library images.
Changed import statements to use explicit .js extensions for ES module compatibility. Updated Docker request detection to include '/cr/' paths and improved logic to avoid duplicating '/v2' prefix when constructing target paths.
Introduces Docker Hub-specific configuration and utilities, including path and scope transformation for library images. Updates the main logic to handle Docker Hub authentication and path rewriting. Adds tests for Docker Hub path, scope, and authentication header parsing. Updates documentation to reflect Docker Hub support and usage examples.
Updated README to clarify container registry usage and examples, including new supported registries and configuration instructions. Removed NVIDIA NGC from supported registries in code and tests. Standardized test cases and examples to use 'nginxinc/nginx-unprivileged' for container registry paths, improving consistency across documentation and tests.
Eliminates support for Docker Hub ('cr-docker') from platform configuration, request handling logic, and all related tests. Updates terminology and test cases to use other container registries (e.g., GHCR) and removes Docker-specific path and scope transformations. This simplifies container registry support and focuses on currently supported platforms.
Simplifies Docker authentication and registry path handling by removing redundant logic and enforcing /cr/ prefix for Docker registry requests. Updates allowed HTTP methods for Git and Docker, streamlines DockerHub library image path transformation, and improves unauthorized response handling.
Moves Docker authentication handling to the beginning of request processing for priority and clarity. Improves error handling and response formatting for Docker auth endpoint, and removes duplicate logic from later in the function.
Enhances Docker registry proxy logic to better handle authentication challenges, support DELETE method, and improve path transformations for Docker Hub library images. Adds more robust handling for /v2/auth endpoint, upstream authentication checks, and anonymous token fetching for public repositories. Also refines error messaging and routing for Docker requests.
Simplifies and improves handling of 401 Unauthorized responses for Docker registry requests by passing through the authentication challenge with a modified WWW-Authenticate header, allowing the Docker client to handle authentication. Removes token fetching logic and ensures relevant headers are preserved in the response.
Simplifies unauthorized response structure and updates the service name in the WWW-Authenticate header. Refactors Docker registry path handling to require /cr/ prefix for all requests, removes special handling for /v2/auth, and improves token fetching logic for public repositories. Unauthorized errors now return a more helpful message when authentication fails.
Adds special handling for the Docker /v2/auth endpoint, allowing requests without the /cr/ prefix. Refines anonymous token retrieval for Docker Hub public images and ensures proper scope extraction for manifests and blobs. If anonymous access fails, the original authentication challenge is passed through instead of returning a custom unauthorized response.