Repository navigation
Conversation
🦋 Changeset detectedLatest commit: 0a8ba16 The changes in this PR will be included in the next version bump. This PR includes changesets to release 9 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info
📝 Walkthrough
Merge Risk: ⚪ Minimal · up to No actionable merge-blocking risk is established; the change is ready for normal merge checks. Pre-merge checks |
|
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
18a2dc3 to
878605b
Compare
228a427 to
878605b
Compare
…st beta - Bump h3-v2 to npm:[email protected], srvx to ^1.0.5 and nitro to ^3.0.260903-beta across packages, examples and e2e apps. The only remaining srvx 0.x copy comes from @vitejs/plugin-rsc. - h3 2.0.1 no longer throws on malformed percent-encoded paths, so requestHandler checks the pathname itself and keeps responding 400. The decoded value is used so bundlers cannot drop the decodeURI call. - Mark the auth-docs login e2e test as fixme under vite preview: the MSW 2.x preload drops copied response headers (mswjs/interceptors#850, fixed in MSW 3.0.2). Co-Authored-By: Claude Opus 5.5 <[email protected]>
0.5.36 depends on srvx ^1.0.5 (vitejs/vite-plugin-react#1456), so the lockfile now resolves a single srvx. react-start-rsc keeps its optional peer range at >=0.5.30; older versions still work with their own srvx copy. Co-Authored-By: Claude Opus 5.5 <[email protected]>
… URL helpers h3 2.0.1 only reads `x-forwarded-proto` when `xForwardedProto: true` is passed, so the JSDoc for `getRequestUrl()` and `getRequestProtocol()` no longer describes it as the default. Add the same trusted-proxy note that `getRequestIP()` has for `xForwardedFor`. Co-Authored-By: Claude Opus 5.5 <[email protected]>
The MSW 2 preload installs the @mswjs/interceptors ClientRequest interceptor, which replaces the global `Headers` and rebuilds a copied `Headers` from an empty raw-header list (mswjs/interceptors#850). h3 2.0.1 copies response headers when it adds pending ones (e.g. a session `Set-Cookie`), so under vite preview the auth-docs login response kept only `set-cookie` and the redirect was never followed. The e2e apps only call the mocked API with `fetch`, so the preload now uses `SetupServerApi` with just the `FetchInterceptor`, which never patches `Headers`. `@mswjs/interceptors` is pinned to the version MSW 2.15 uses. The auth-docs login test runs in vite preview again. Co-Authored-By: Claude Opus 5.5 <[email protected]>
Add JSDoc to the two functions touched by this PR that had none, and restore the x-forwarded-proto note on getRequestUrl. Co-Authored-By: Claude Opus 5.5 <[email protected]>
2dc38e2 to
0a8ba16
Compare
srvxhas shipped a v1.0! This PR updates all the dependencies required to get Router using the v1.x sensibly; there are a few very minor tweaks and default changes made but the majority of this is just updates to the package logs.srvx 1.0.0 is a stable re-release of 0.12.8; its breaking changes landed in 0.12.0 (renamed
srvx/staticandsrvx/logexports), which nothing uses in Router.NodeRequest,sendNodeResponse,toNodeHandlerandFastResponsekeep their signatures, and the CLI flags used by the e2e apps are unchanged.AI Disclosure
Claude Code using Opus 5.5 Extra reasoning was used during the creation of this PR.
All code has been manually checked and comments (and this description) reworded for clarity
Updates
Router was stuck on srvx 0.11, because
@tanstack/start-server-corepinnedh3-v2: npm:[email protected], which depends onsrvx ^0.11. h3 2.0.1 is now stable (Oct 3) and depends onsrvx ^1.0.5.A number of other dependencies had transitive dependencies on various versions of
srvxso they are also updated to ensure a consistentsrvxversion is possible.These could all be raised as separate PRs if wanted - but keeping the change in a single commit seems sensible to me.
Dependency updates
h3-v2(npm:h3)2.0.1-rc.202.0.1start-server-coresrvx^0.10/^0.11^1.0.5start-plugin-core, e2e apps, examples (early-hints keeps its exact pin, now1.0.5)@vitejs/plugin-rsc^0.5.30^0.5.36react-start-rsc(dev), RSC e2e apps,start-rscsexample@mswjs/interceptors0.41.9(pinned, same version MSW 2.15 uses)e2e-utils(test-only, see below)The lockfile now has a single h3, crossws and srvx (1.0.5).
Nitro is no longer updated here:
mainmoved to^3.0.260903-betain #7830. The only Nitro-related change left is in the lockfile, where itsh3dependency now resolves to2.0.1instead of2.0.1-rc.32.@vitejs/plugin-rsc0.5.36 moved tosrvx ^1.0.5(vitejs/vite-plugin-react#1456).react-start-rsckeeps its optional@vitejs/plugin-rscpeer range at>=0.5.30.Required Changes
Malformed paths still respond with 400
h3 2.0.1's
H3Eventconstructor no longer throwsURIErrorfor paths like/%80. It now only flags them for h3's own app, which Start doesn't use, so the existingcatch (URIError)inrequestHandlerbecame unreachable and these requests reached the router as 404s.requestHandlernow decodes the pathname itself.Note - the helper deliberately returns the decoded value: Rolldown treats
decodeURIas side-effect free and drops a call whose result is unused, even insidetry(Rollup keeps it). Atry { decodeURI(p); return false } catch { return true }version passed the unit tests from source but was compiled toreturn falseindist. Covered by new unit tests inrequest-response.test.tsand the existing special-characters e2e tests in React, Solid and Vue.Behaviour changes inherited from h3 2.0.1
These surface through the request/response utilities exported from
@tanstack/*-start/server. The PR currently adopts h3's new defaults and these are reflected in the changeset:getRequestProtocol()/getRequestUrl()only readx-forwarded-protowhen called with{ xForwardedProto: true }. h3 made it opt-in because clients can spoof the header. Start could keep its old default by passingxForwardedProto: truein the wrappers.SameSite=Lax, which can be overridden withcookie.sameSite.getSession()no longer sets a cookie for a brand-new session until it is updated;useSession()still does. Start could restore the old behaviour by callinguseSession()inside itsgetSession()wrapper.legacySealFallback(on by default) and are re-sealed on the next request, so nobody is logged out.Test harness: MSW preload intercepts only
fetchWith h3 2.0.1, the auth-docs login e2e test failed in vite preview only. The MSW 2 preload's
@mswjs/interceptors0.41 replaces the globalHeadersand rebuilds a copiedHeadersfrom an empty raw-header list. h3 2.0.1 copies the response headers when it adds the sessionSet-Cookie, and the vite preview plugin readsresponse.headers, so the login response kept onlyset-cookieand the redirect was never followed. Without the preload, preview login works, so this is not a production issue. It is fixed upstream in@mswjs/interceptors0.45.6 (mswjs/interceptors#850), first shipped in MSW 3.0.2.Rather than upgrade MSW, the preload in
e2e/e2e-utils/mock-api.mjsnow intercepts onlyfetch:Headerspatch comes from MSW 2'sClientRequestinterceptor, which intercepts Node'shttp/httpsmodules and is installed bysetupServer()by default. Thefetchinterceptor never patchesHeaders.fetch, directly or throughredaxios. The preload now uses MSW 2's exportedSetupServerApiwith onlyFetchInterceptor, so the mocks behave as before.@mswjs/interceptorsis added as a dev dependency ofe2e-utils, pinned to0.41.9, the version MSW 2.15 already uses, so there is still a single copy. The pin needs to move together with MSW.http/httpswould not be mocked; the comment inmock-api.mjsnotes this. When MSW is upgraded to 3, the preload can go back tosetupServer().mock-apiunit tests are unchanged, and the auth-docs login test runs in vite preview again.Test results
Run locally on
878605b5e8(Node 24.19.0, macOS) with--skip-nx-cache; e2e vianx run-many -t test:e2e --parallel=3, as in CI.Package checks: all passed
start-server-corestart-plugin-coretest.fails)react-start-serversolid-start-servervue-start-serverreact-start-rscreact-startsolid-startvue-startrouter-e2e-utils(private)e2e: every React, Solid and Vue Start e2e app, all modes and shards
Skipped tests are existing mode-specific skips.
react-start/basic-authandreact-start/clerk-basichave e2e disabled in the repo (exit 0), andreact-start/flamegraph-benchhas no e2e target. Router-only e2e apps were not run: they do not use the changed server code, and their browser-side MSW fixture is unchanged frommain.✅ Checklist
🚀 Release Impact
Summary by CodeRabbit
h3andsrvxversions.