Commit Graph
151 Commits
Author SHA1 Message Date
xixu-me 6afd952a1e fix(fedora): route through kernel.org mirror
Use the kernel.org Fedora mirror to avoid upstream bot challenges.

Preserve existing /pub/fedora/linux request paths with a Fedora transformer.

Closes #271
2026-05-10 13:00:03 +08:00
xixu-me 921a409bf1 fix(cache): harden cache policy guards 2026-05-05 16:30:30 +08:00
xixu-me 0ed5501ed9 perf(cache): add strategy-based cache policy 2026-05-05 15:15:58 +08:00
xixu-me f171c3441b chore: add AGPL headers and simplify skills install docs 2026-03-22 17:32:50 +08:00
xixu-me 5008a81c78 chore: align repository docs and ci 2026-03-21 17:05:21 +08:00
xixu-me f2936d2598 refactor(core): modularize request pipeline 2026-03-20 15:36:10 +08:00
xixu-me 8918095402 chore: switch license to AGPL-3.0 2026-03-16 18:31:06 +08:00
xixu-me 85a0c83484 fix(docker): harden auth token parsing 2026-03-16 14:51:43 +08:00
xixu-me fad1b710e8 fix(pypi): prevent caching origin-bound rewritten index pages 2026-03-16 12:57:21 +08:00
xixu-me 9214028cf9 fix(flathub): scope rewritten descriptor cache by origin 2026-03-16 01:14:33 +08:00
xixu-me e8d1dae226 style: format ci-tracked files 2026-03-14 17:51:40 +08:00
xixu-me 2b9d4790de fix: harden proxy error handling and regression tests 2026-03-14 17:33:06 +08:00
xixu-me 442263d8f9 chore: align Flathub ordering and commit guidance
Resolves #222
2026-03-14 16:45:01 +08:00
xixu-me be2ce81c2a feat: add Flathub mirror support 2026-03-14 16:23:38 +08:00
xixu-me ad5f1993c5 fix: handle docker host-style registry paths 2026-03-09 18:05:13 +08:00
xixu-me 18247d5cfe feat: refactor AI inference request detection and Docker authentication handling 2026-03-09 17:49:47 +08:00
xixu-me 89dc392374 feat: update dependencies and improve request handling 2026-03-09 17:37:27 +08:00
xixu-me ecef35dfe9 Revert "fix(proxy): correct registry auth and rewrite lengths"
This reverts commit cb44ddb66c.
2026-03-09 17:00:43 +08:00
xixu-me 8075a181de Revert "style(proxy): format docker protocol tests"
This reverts commit 213e04de76.
2026-03-09 16:56:27 +08:00
xixu-me a72f9142ab Revert "feat(platform): add ScoopInstaller support"
This reverts commit 6f0d7e15f8.
2026-03-09 13:04:37 +08:00
xixu-me 35a5d26d83 feat(platform): add ScoopInstaller support
Resolves #207
2026-03-08 13:05:15 +08:00
xixu-meandCopilot Autofix powered by AI 71f11618fc Potential fix for code scanning alert no. 17: Information exposure through a stack trace
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
2026-03-06 21:24:53 +08:00
xixu-me d891973b73 fix: harden proxy behavior and stabilize ci 2026-03-06 21:10:59 +08:00
xixu-me 6b0476f17e style(proxy): format docker protocol tests 2026-03-06 20:30:35 +08:00
xixu-me 805b4d0f6d fix(proxy): correct registry auth and rewrite lengths 2026-03-06 20:27:43 +08:00
xixu-me 87b7529628 style: format prettier violations 2026-03-06 19:45:03 +08:00
xixu-me 0837de2f14 fix(proxy): tighten protocol routing and stabilize tests 2026-03-06 19:41:14 +08:00
xixu-me e705367524 feat: enhance security validation and caching behavior for requests with sensitive headers 2026-02-01 13:50:11 +08:00
xixu-me 3ebc1fc4ff fix: resolve ESLint JSDoc warnings
- Remove duplicate @param in docker.js
- Remove extra blank lines after JSDoc descriptions in huggingface.js
2026-01-31 22:40:27 +08:00
xixu-me 9daa7e9a75 fix: resolve TypeScript type errors in index.js and huggingface.js
- Change env param type from 'object' to 'Record<string, unknown>'
- Store Authorization header in variable before null check
2026-01-31 22:35:22 +08:00
xixu-me 0fc3935042 fix: increase test timeouts and fix lint error
- Add global testTimeout (60s) and hookTimeout (30s) in vitest.config.js
- Increase timeouts for network-dependent tests in security, integration,
  and container-registry test files
- Use HEAD requests where appropriate to reduce network overhead
- Fix lint error: change 'let scope' to 'const scope' in src/index.js
2026-01-31 22:22:59 +08:00
google-labs-jules[bot] 893f976ab5 feat: add support for Hugging Face API operations
This change enables full support for Hugging Face API requests, including repository creation, by:
1. Identifying HF API requests via path patterns.
2. Allowing POST, PUT, PATCH, and DELETE methods for these requests.
3. Correctly forwarding request bodies and headers.
4. Skipping caching for API operations.

Fixes: huggingface_hub.errors.HfHubHTTPError: Client error '405 Method Not Allowed'
2026-01-06 14:53:29 +00:00
xixu-me 2e7716d66c Improve Docker redirect and auth header handling
Adds special handling for Docker registry redirects to prevent leaking Authorization headers to S3 or blob storage by using manual redirect mode and stripping sensitive headers before following redirects. Refactors scope handling for unauthorized responses and ensures retry logic for token fetches also respects Docker redirect requirements.
2025-12-12 13:29:07 +08:00
xixu-me 296b935cdf Fix client scope in unauthorized response for cr- platforms
Adjusts the client scope in unauthorized responses to include the platform prefix for platforms starting with 'cr-'. This ensures clients request tokens with a scope that Xget can properly route.
2025-12-12 13:20:47 +08:00
xixu-me dac733a2c5 Refactor Docker scope extraction and 401 response
Moved Docker registry scope extraction logic into a new getScopeFromUrl function in docker.js for reuse and clarity. Updated responseUnauthorized to accept an optional scope and improved its error response format to be more Docker/OCI-compliant. Refactored index.js to use the new scope extraction and 401 response logic.
2025-12-12 13:16:21 +08:00
xixu-me d529a16789 Improve JSDoc types and add eslint-plugin-jsdoc
Standardized JSDoc type annotations across the codebase, replacing 'Object' with 'object' and refining function signatures for better type safety. Added and configured eslint-plugin-jsdoc for enhanced documentation linting, and updated ESLint settings to include adapters and new JSDoc rules. Updated dependencies to include eslint-plugin-jsdoc and related packages.
2025-12-11 13:27:26 +08:00
xixu-me 0edc986711 Add GPL license header and clean up Docker 401 handling
Added GPL license header to Netlify edge-handler.js. Removed redundant comments and clarified logic for handling Docker 401 responses in src/index.js.
2025-12-11 12:58:11 +08:00
xixu-me fe5baef8b5 Add GPLv3 license headers to source files
Added GNU General Public License v3 headers to protocol and utility modules for Xget, clarifying copyright and licensing information. This ensures compliance and transparency regarding the project's open source status.
2025-12-11 12:34:10 +08:00
xixu-me 3832d565e2 Refactor integration tests and add feature-specific test suites
Moves Git, Git LFS, and authentication header forwarding tests from integration.test.js into dedicated feature test files under test/features/. Updates range-cache, security, and container-registry tests for consistency and minor improvements. Refactors src/index.js for code style and readability, especially around cache logic and error handling.
2025-12-10 16:23:44 +08:00
xixu-me 2c2862cb78 Add multi-platform function adapters and CI workflow
Introduces adapters for Vercel, Netlify Edge, Deno Deploy, and Cloudflare Pages, each with platform-specific entry points and configuration files. Adds a GitHub Actions CI workflow for linting, type checking, and testing. Updates lint scripts to include adapters, improves type annotations in src/index.js, and fixes a type assertion in security tests.
2025-12-10 16:08:10 +08:00
xixu-me cb0bb2da2f Refactor request handling and improve Docker detection
Refactored the main request handler in src/index.js for improved readability and error handling. Enhanced Docker request detection in validation.js to include additional Content-Type checks. Updated tests to increase timeouts and expand expected status codes for container registry platforms.
2025-12-10 15:47:25 +08:00
xixu-me b81b3968d9 Refactor protocol header logic into modular helpers
Moved AI and Git protocol detection and header configuration logic from utils/validation.js and index.js into dedicated modules (src/protocols/ai.js and src/protocols/git.js). This improves code organization, modularity, and maintainability by separating protocol-specific concerns.
2025-12-10 15:25:57 +08:00
xixu-me 75d8594532 Refactor protocol and utility logic into separate modules
Moved Docker/OCI protocol handling, performance monitoring, security, and validation logic into dedicated modules under src/protocols and src/utils. Updated src/index.js to use these new modules, improving maintainability and separation of concerns. Added pre-computed sorted platform keys for efficient matching in platform config.
2025-12-10 15:03:27 +08:00
xixu-me 24a53398fb Add transformPath utility to handle platform prefixes
Introduces the transformPath function to remove platform-specific prefixes from paths. This utility helps standardize path handling by stripping prefixes like /gh/ or /cr/docker/ based on the platform key.
2025-12-10 14:36:29 +08:00
xixu-me 9ea2bd0cfc Refactor Docker authentication handling in handleRequest
Moved Docker authentication logic to occur before platform detection for /v2/auth paths, parsing the scope parameter to identify the registry platform and repository. Improved parsing of the WWW-Authenticate header and removed redundant Docker authentication code from the platform detection block.
2025-12-10 13:44:30 +08:00
xixu-me 251dbd2181 Transform scope parameter for container registry auth
Added logic to remove the cr/[registry]/ prefix from the scope parameter and handle official Docker Hub images by adding the library/ prefix. Updated tests to verify correct scope transformation for Docker Hub, GHCR, and official images.
2025-12-10 13:04:33 +08:00
xixu-meandCopilot Autofix powered by AI 508cea92fe Potential fix for code scanning alert no. 11: Incomplete regular expression for hostnames
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
2025-12-08 20:05:05 +08:00
xixu-me 81e810ec9a Add type declarations and improve test typings
Introduces src/types.d.ts and test/types.d.ts for Cloudflare Workers and test utilities. Enhances JSDoc comments and type annotations across test files for better type safety and clarity. Updates tsconfig.json to use bundler module resolution and include additional type sources. Minor test logic and assertion improvements for robustness.
2025-12-08 19:57:48 +08:00
xixu-me e9b1e0a931 Add eslint-config-prettier and update ESLint config
Integrated eslint-config-prettier to disable formatting rules that conflict with Prettier. Updated ESLint configuration and added the dependency to package.json for improved code formatting consistency.
2025-12-08 19:34:56 +08:00
xixu-me 29ba7086cb Refactor cacheKey request formatting
Reformats the construction of the cacheKey Request object for improved readability and consistency in indentation.
2025-12-08 19:23:07 +08:00