Skip to content

Release 1.0.0: isolate CONNECT headers per request - #70

Closed
cursor[bot] wants to merge 2 commits into
mainfrom
release/1.0.0
Closed

cursor[bot] wants to merge 2 commits into
mainfrom
release/1.0.0

Conversation

@cursor

@cursor cursor Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Major release. CONNECT response headers are no longer merged into origin response.headers, and they are stored per connection so concurrent requests cannot mix proxy metadata.

Why

Shared lastProxyHeaders plus copying CONNECT headers onto origin responses mixed hop-by-hop proxy metadata with the target HTTPS response. Concurrent clients could attribute another request’s X-ProxyMesh-IP, and a CONNECT Set-Cookie / Location could appear as origin headers.

Breaking changes

  • Read CONNECT headers from response.proxyHeaders.get('x-proxymesh-ip'), not response.headers.
  • agent.lastProxyHeaders is last-write-wins. Prefer per-response proxyHeaders or getProxyHeaders().
  • Version bump 0.2.4 → 1.0.0 (package.json and jsr.json).

What changed

  • Attach CONNECT headers to the tunnel/TLS socket (lib/core/proxy-headers-store.js).
  • Axios, got, superagent, needle, node-fetch, make-fetch-happen, undici, and typed-rest-client expose per-request proxyHeaders.
  • Docs, types, and unit tests updated (no origin-header merge; concurrent axios isolation).

Merging this release/1.0.0 branch into main should create GitHub release v-1.0.0 and publish.

Open in Web View Automation 

cursoragent and others added 2 commits October 1, 2026 16:46
Stop merging proxy CONNECT headers into origin response.headers and
store them per connection so concurrent requests cannot mix CONNECT
metadata. Adapters expose response.proxyHeaders instead.

BREAKING CHANGE: read CONNECT headers from response.proxyHeaders, not
response.headers. agent.lastProxyHeaders remains last-write-wins.

Co-authored-by: ProxyMesh AI <proxymeshai@users.noreply.github.com>
Keep the CONNECT-header isolation as a 0.x breaking change instead of 1.0.0.

Co-authored-by: ProxyMesh AI <proxymeshai@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants