Commit Graph
124 Commits
Author SHA1 Message Date
xixu-me 90b8edd53a feat: enhance security validation and caching behavior for requests with sensitive headers 2026-02-01 13:50:11 +08:00
xixu-me e2e571aef4 fix: resolve ESLint JSDoc warnings
- Remove duplicate @param in docker.js
- Remove extra blank lines after JSDoc descriptions in huggingface.js
2026-01-31 22:40:27 +08:00
xixu-me 532f690073 fix: resolve TypeScript type errors in index.js and huggingface.js
- Change env param type from 'object' to 'Record<string, unknown>'
- Store Authorization header in variable before null check
2026-01-31 22:35:22 +08:00
xixu-me c700b6acee fix: increase test timeouts and fix lint error
- Add global testTimeout (60s) and hookTimeout (30s) in vitest.config.js
- Increase timeouts for network-dependent tests in security, integration,
  and container-registry test files
- Use HEAD requests where appropriate to reduce network overhead
- Fix lint error: change 'let scope' to 'const scope' in src/index.js
2026-01-31 22:22:59 +08:00
google-labs-jules[bot] 81c44f0c71 feat: add support for Hugging Face API operations
This change enables full support for Hugging Face API requests, including repository creation, by:
1. Identifying HF API requests via path patterns.
2. Allowing POST, PUT, PATCH, and DELETE methods for these requests.
3. Correctly forwarding request bodies and headers.
4. Skipping caching for API operations.

Fixes: huggingface_hub.errors.HfHubHTTPError: Client error '405 Method Not Allowed'
2026-01-06 14:53:29 +00:00
xixu-me 29fe048984 Improve Docker redirect and auth header handling
Adds special handling for Docker registry redirects to prevent leaking Authorization headers to S3 or blob storage by using manual redirect mode and stripping sensitive headers before following redirects. Refactors scope handling for unauthorized responses and ensures retry logic for token fetches also respects Docker redirect requirements.
2025-12-12 13:29:07 +08:00
xixu-me 9fc2804332 Fix client scope in unauthorized response for cr- platforms
Adjusts the client scope in unauthorized responses to include the platform prefix for platforms starting with 'cr-'. This ensures clients request tokens with a scope that Xget can properly route.
2025-12-12 13:20:47 +08:00
xixu-me e8d7a0ef6b Refactor Docker scope extraction and 401 response
Moved Docker registry scope extraction logic into a new getScopeFromUrl function in docker.js for reuse and clarity. Updated responseUnauthorized to accept an optional scope and improved its error response format to be more Docker/OCI-compliant. Refactored index.js to use the new scope extraction and 401 response logic.
2025-12-12 13:16:21 +08:00
xixu-me 07f5f35972 Improve JSDoc types and add eslint-plugin-jsdoc
Standardized JSDoc type annotations across the codebase, replacing 'Object' with 'object' and refining function signatures for better type safety. Added and configured eslint-plugin-jsdoc for enhanced documentation linting, and updated ESLint settings to include adapters and new JSDoc rules. Updated dependencies to include eslint-plugin-jsdoc and related packages.
2025-12-11 13:27:26 +08:00
xixu-me bfec1d2d9e Add GPL license header and clean up Docker 401 handling
Added GPL license header to Netlify edge-handler.js. Removed redundant comments and clarified logic for handling Docker 401 responses in src/index.js.
2025-12-11 12:58:11 +08:00
xixu-me 5cbcd0c3d4 Add GPLv3 license headers to source files
Added GNU General Public License v3 headers to protocol and utility modules for Xget, clarifying copyright and licensing information. This ensures compliance and transparency regarding the project's open source status.
2025-12-11 12:34:10 +08:00
xixu-me ce93ea9861 Refactor integration tests and add feature-specific test suites
Moves Git, Git LFS, and authentication header forwarding tests from integration.test.js into dedicated feature test files under test/features/. Updates range-cache, security, and container-registry tests for consistency and minor improvements. Refactors src/index.js for code style and readability, especially around cache logic and error handling.
2025-12-10 16:23:44 +08:00
xixu-me 44b54580ad Add multi-platform function adapters and CI workflow
Introduces adapters for Vercel, Netlify Edge, Deno Deploy, and Cloudflare Pages, each with platform-specific entry points and configuration files. Adds a GitHub Actions CI workflow for linting, type checking, and testing. Updates lint scripts to include adapters, improves type annotations in src/index.js, and fixes a type assertion in security tests.
2025-12-10 16:08:10 +08:00
xixu-me 214e596d00 Refactor request handling and improve Docker detection
Refactored the main request handler in src/index.js for improved readability and error handling. Enhanced Docker request detection in validation.js to include additional Content-Type checks. Updated tests to increase timeouts and expand expected status codes for container registry platforms.
2025-12-10 15:47:25 +08:00
xixu-me 1c20e7af4f Refactor protocol header logic into modular helpers
Moved AI and Git protocol detection and header configuration logic from utils/validation.js and index.js into dedicated modules (src/protocols/ai.js and src/protocols/git.js). This improves code organization, modularity, and maintainability by separating protocol-specific concerns.
2025-12-10 15:25:57 +08:00
xixu-me 70ff5b248d Refactor protocol and utility logic into separate modules
Moved Docker/OCI protocol handling, performance monitoring, security, and validation logic into dedicated modules under src/protocols and src/utils. Updated src/index.js to use these new modules, improving maintainability and separation of concerns. Added pre-computed sorted platform keys for efficient matching in platform config.
2025-12-10 15:03:27 +08:00
xixu-me 89c8da936d Add transformPath utility to handle platform prefixes
Introduces the transformPath function to remove platform-specific prefixes from paths. This utility helps standardize path handling by stripping prefixes like /gh/ or /cr/docker/ based on the platform key.
2025-12-10 14:36:29 +08:00
xixu-me a6a0e97ada Refactor Docker authentication handling in handleRequest
Moved Docker authentication logic to occur before platform detection for /v2/auth paths, parsing the scope parameter to identify the registry platform and repository. Improved parsing of the WWW-Authenticate header and removed redundant Docker authentication code from the platform detection block.
2025-12-10 13:44:30 +08:00
xixu-me 80e3c26967 Transform scope parameter for container registry auth
Added logic to remove the cr/[registry]/ prefix from the scope parameter and handle official Docker Hub images by adding the library/ prefix. Updated tests to verify correct scope transformation for Docker Hub, GHCR, and official images.
2025-12-10 13:04:33 +08:00
xixu-meandCopilot Autofix powered by AI ead7afed1a Potential fix for code scanning alert no. 11: Incomplete regular expression for hostnames
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
2025-12-08 20:05:05 +08:00
xixu-me 4993444f51 Add type declarations and improve test typings
Introduces src/types.d.ts and test/types.d.ts for Cloudflare Workers and test utilities. Enhances JSDoc comments and type annotations across test files for better type safety and clarity. Updates tsconfig.json to use bundler module resolution and include additional type sources. Minor test logic and assertion improvements for robustness.
2025-12-08 19:57:48 +08:00
xixu-me d2ee1bcd37 Add eslint-config-prettier and update ESLint config
Integrated eslint-config-prettier to disable formatting rules that conflict with Prettier. Updated ESLint configuration and added the dependency to package.json for improved code formatting consistency.
2025-12-08 19:34:56 +08:00
xixu-me 7036cbd39e Refactor cacheKey request formatting
Reformats the construction of the cacheKey Request object for improved readability and consistency in indentation.
2025-12-08 19:23:07 +08:00
xixu-me d88f1911a6 Improve parsing, regex, and test consistency
Refines regex patterns for URL rewriting and authentication parsing, ensures parseInt uses radix 10 throughout, and updates test mocks and helpers for consistency. Also adds more global variables to ESLint config, improves error handling, and removes unused code in tests.
2025-12-08 19:19:10 +08:00
xixu-me a4da6607c7 Improve Content-Length detection for HEAD requests
Enhances the logic for obtaining Content-Length when a HEAD request does not return it by first attempting a Range GET for the first byte, extracting the total size from Content-Range if available, and falling back to buffering the response body for small files. This approach avoids unnecessary full downloads and improves efficiency, especially for large files.
2025-11-27 18:36:26 +08:00
xixu-me f60661db6f Refactor test helpers and add auth header forwarding tests
Modularizes test helpers into separate files for assertions, generators, and mocks, and updates imports for platform tests. Adds new tests to verify Authorization header forwarding for authenticated requests. Cleans up and simplifies test setup, and updates fixtures for clarity and maintainability.
2025-11-27 16:27:42 +08:00
xixu-me 89551136d7 Update API usage examples and rename Anthropic to Claude
Revised Python and JavaScript code samples in both English and Chinese READMEs to use updated OpenAI, Claude (formerly Anthropic), and Gemini API interfaces. Renamed references from 'Anthropic' to 'Claude' throughout documentation and config comments for clarity. Also updated tsconfig.json formatting for consistency.
2025-11-20 19:32:13 +08:00
xixu-me d3c8c147ae Update docs and code references from Worker to Workers
Standardized terminology by changing 'Cloudflare Worker' to 'Cloudflare Workers' across documentation, workflow comments, and code. Expanded deployment instructions in README to include Cloudflare Pages and EdgeOne Pages, clarified secrets setup, and improved deployment notes for self-hosting.
2025-11-18 22:08:42 +08:00
xixu-me 0204501aba Redirect invalid and incomplete paths to homepage
Update request handling to redirect root, invalid platform prefixes, and platform prefixes without resource paths to the homepage. Adjust tests to expect 302 redirects instead of 404 or 400 responses for these cases.
2025-11-18 18:30:15 +08:00
xixu-me 3b1ee1cd2e Revert "Convert Cloudflare Worker to Cloudflare Pages" 2025-11-16 23:29:53 +08:00
Claude eabf0782d4 Convert Cloudflare Worker to Cloudflare Pages
This commit converts the entire Xget application from a Cloudflare Worker
to a Cloudflare Page, enabling static asset hosting while maintaining all
existing functionality.

Changes:
- Add functions/[[path]].js: Catch-all Pages Function handler
- Add public/index.html: Landing page with Xget information
- Update src/index.js: Export handleRequest for Pages Function import
- Update wrangler.toml: Configure for Pages deployment
- Update package.json: Change scripts to use Pages commands
- Update vitest.config.js: Include functions/ in coverage
- Update .github/workflows/depoly.yml: Deploy to Pages
- Update documentation: CLAUDE.md, README.md, README.en.md

The conversion maintains full backward compatibility with existing tests
and functionality. All caching strategies, security headers, and protocol
handling remain unchanged.
2025-11-16 15:18:34 +00:00
xixu-me ef3dec1754 Improve cache handling and error resilience
Enhances cache logic to ensure compatibility with non-Cloudflare environments by checking for cache API availability. Refactors cache key construction to always use GET method, adds error handling for cache operations, and ensures only GET requests are cached. Improves robustness and prevents runtime errors when cache API is unavailable.
2025-11-16 20:50:13 +08:00
xixu-me 5a6ae81a9a Add GPLv3 license headers to source files
Added GNU General Public License v3 headers to index.js, config/index.js, and config/platforms.js to clarify licensing and copyright information.
2025-11-16 19:46:48 +08:00
xixu-me cadf5b1275 Add Podman support and update badges in docs
Added Podman deployment instructions and badges to both English and Chinese README files. Updated several badge colors for consistency. Introduced new scripts for badge color fixes. Updated dependencies in package.json and package-lock.json. Added scripts/README.md and scripts/fix-badge-colors.js for badge management.
2025-11-16 19:31:19 +08:00
xixu-me 6245da9e6f Add support for GitHub Gist platform
Added GitHub Gist ('gist') to the supported platforms in the configuration, updated documentation in both English and Chinese READMEs, and included related tests to ensure correct path transformation and base URL.
2025-11-10 20:45:58 +08:00
xixu-me 2a02852a5d Add isGitLFS checks to request handling logic
Updated the request handling logic in src/index.js to include isGitLFS in conditions for setting request body, copying headers, and returning responses. This ensures proper handling of Git LFS operations alongside Git, Docker, and AI requests.
2025-11-09 17:28:18 +08:00
xixu-me 17f94416d6 Add Git LFS protocol support and tests
Introduces detection and handling for Git LFS (Large File Storage) operations, including LFS-specific endpoints, headers, and user agents. Updates request validation, header management, and cache logic to properly support LFS requests and ensure real-time data synchronization. Adds comprehensive integration and unit tests for LFS scenarios, and documents the new behavior in CLAUDE.md.
2025-11-09 15:51:39 +08:00
Claude 57e30e8aaa Add Docker Hub container registry support with library prefix handling
This commit adds support for Docker Hub (registry-1.docker.io) as a container registry platform with special authentication handling for official images.

Changes:
- Add 'cr-docker' platform pointing to https://registry-1.docker.io in platforms.js
- Implement special authentication scope handling for Docker Hub official images
- Docker Hub stores official images (nginx, redis, etc.) as library/nginx, library/redis
- Single-component image names are automatically prefixed with 'library/' for authentication
- Multi-component names (user/image) are passed through unchanged
- Add comprehensive tests for Docker Hub support

This resolves the issue where pulling public images from Docker Hub would prompt for authentication incorrectly. The library prefix is now automatically added to the authentication scope for single-name images, allowing proper anonymous access to public official images.

Test coverage:
- Official images (single-name): /cr/docker/v2/nginx/manifests/latest
- User images (namespaced): /cr/docker/v2/nginxinc/nginx-unprivileged/manifests/latest
- GET and HEAD request methods verified

All Docker Hub specific tests pass.
2025-11-09 07:16:03 +00:00
xixu-me e66ae893d9 Add Siray platform support
Added Siray to the list of supported AI inference providers in documentation and configuration. This enables API acceleration for Siray via the platform configuration.
2025-11-06 18:12:21 +08:00
xixu-me 7d50e9e788 Improve range request caching and media file handling
Enhances caching strategy to only cache 200 responses (not 206), supports serving range requests from cached full content, and avoids compression for media files to ensure proper byte-range support. Adds comprehensive tests for range request caching, media file handling, cache key management, and performance metrics.
2025-09-03 03:26:01 +08:00
xixu-me 0a5ef94d81 Add Jenkins plugin mirror support
Introduces Jenkins plugin and update center mirror support in README and platform config. Updates transformPath logic for Jenkins endpoints and adds comprehensive tests for Jenkins path handling and URL construction.
2025-09-03 01:47:23 +08:00
xixu-me 481e5a6672 Revert "Add support for major JS CDN platforms"
This reverts commit 498ca5676a.
2025-09-01 00:50:02 +08:00
xixu-me 498ca5676a Add support for major JS CDN platforms
Added Google Hosted Libraries (ghl), unpkg, Skypack, and esm.sh to the supported platforms in both the README and the configuration file. Updated documentation with usage examples and badge links for these CDNs to improve clarity and user guidance.
2025-09-01 00:26:28 +08:00
xixu-me 4fd50be0c3 Add workflow to auto-translate README and enable arxiv platform
Introduces a GitHub Actions workflow to automatically translate README.md to English using DeepL, update language links, and add a translation disclaimer. Also enables the 'arxiv' platform in the platforms configuration.
2025-08-31 21:16:03 +08:00
xixu-me 2eaef9735d Update platforms.js 2025-08-31 00:15:43 +08:00
xixu-me 16edbd841d Revert "Add Kaggle platform support and path transformation"
This reverts commit 1480595fbc.
2025-08-20 22:30:06 +08:00
xixu-me 1480595fbc Add Kaggle platform support and path transformation
Introduces Kaggle as a supported platform in the configuration and health check. Implements special path transformation logic for Kaggle API endpoints in transformPath, and adds comprehensive tests to verify correct path handling for various Kaggle API routes.
2025-08-20 22:17:48 +08:00
xixu-me a9843ab948 Add Civitai platform support
Added 'civitai' to the PLATFORMS config and updated tests to include Civitai path transformations. This enables handling of Civitai URLs in the platform configuration and ensures correct path transformation logic.
2025-08-20 21:37:57 +08:00
xixu-me 1826aceef5 Update config to use environment variables
Replaced hardcoded configuration values in src/config/index.js with environment variable lookups to improve flexibility and security.
2025-08-20 13:33:35 +08:00
xixu-me 144da6a0e7 Update AI provider keys and docs for consistency
Renamed several AI provider keys and references (e.g., 'ip-google' to 'ip-gemini', 'ip-mistral' to 'ip-mistralai', etc.) in the codebase, documentation, and tests for improved clarity and alignment with provider branding. Updated README usage examples and provider tables to match the new keys.
2025-08-14 16:52:14 +08:00