Skip to content

Release 0.3.0: isolate CONNECT headers per request - #71

Draft
cursor[bot] wants to merge 4 commits into
mainfrom
release/0.3.0
Draft

cursor[bot] wants to merge 4 commits into
mainfrom
release/0.3.0

Conversation

@cursor

@cursor cursor Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Breaking 0.x release. CONNECT response headers are no longer merged into origin response.headers, and they are stored per connection so concurrent requests cannot mix proxy metadata.

Why

Shared lastProxyHeaders plus copying CONNECT headers onto origin responses mixed hop-by-hop proxy metadata with the target HTTPS response. Concurrent clients could attribute another request’s X-ProxyMesh-IP, and a CONNECT Set-Cookie / Location could appear as origin headers.

Breaking changes

  • Read CONNECT headers from response.proxyHeaders.get('x-proxymesh-ip'), not response.headers.
  • agent.lastProxyHeaders is last-write-wins. Prefer per-response proxyHeaders or getProxyHeaders().
  • Version bump 0.2.4 → 0.3.0 (package.json and jsr.json).

What changed

  • Attach CONNECT headers to the tunnel/TLS socket (lib/core/proxy-headers-store.js).
  • Axios, got, superagent, needle, node-fetch, make-fetch-happen, undici, and typed-rest-client expose per-request proxyHeaders.
  • Docs, types, and unit tests updated (no origin-header merge; concurrent axios isolation).

Merging this release/0.3.0 branch into main should create GitHub release v-0.3.0 and publish.

Please close #70 (wrong branch release/1.0.0 and 1.0.0 title).

Open in Web View Automation 

cursoragent and others added 2 commits October 1, 2026 16:46
Stop merging proxy CONNECT headers into origin response.headers and
store them per connection so concurrent requests cannot mix CONNECT
metadata. Adapters expose response.proxyHeaders instead.

BREAKING CHANGE: read CONNECT headers from response.proxyHeaders, not
response.headers. agent.lastProxyHeaders remains last-write-wins.

Co-authored-by: ProxyMesh AI <proxymeshai@users.noreply.github.com>
Keep the CONNECT-header isolation as a 0.x breaking change instead of 1.0.0.

Co-authored-by: ProxyMesh AI <proxymeshai@users.noreply.github.com>
@proxymeshai

Copy link
Copy Markdown
Collaborator

cursor review

@cursor

cursor Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Skipping Bugbot: Bugbot is disabled for this repository. Visit the Bugbot dashboard to update your settings.

@proxymeshai

Copy link
Copy Markdown
Collaborator

cursor review

@cursor

cursor Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Bugbot couldn't run — GitHub account mismatch

The GitHub account linked to your Cursor account does not match the PR author.

Please ensure you're using the correct GitHub account, or run Bugbot from a team that covers this repository.

@proxymesh

Copy link
Copy Markdown
Owner

cursor review

@cursor

cursor Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Skipping Bugbot: Unable to authenticate your request. Please make sure Bugbot is properly installed and configured for this repository.

@proxymeshai

Copy link
Copy Markdown
Collaborator

bugbot run

@cursor

cursor Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Bugbot couldn't run — GitHub account mismatch

The GitHub account linked to your Cursor account does not match the PR author.

Please ensure you're using the correct GitHub account, or run Bugbot from a team that covers this repository.

cursoragent and others added 2 commits October 1, 2026 17:39
…aders

Override typed-rest-client processResponse so RestClient results get
per-request proxyHeaders. Sync ALS from reused sockets so make-fetch-happen
keep-alive does not fall back to lastProxyHeaders. Attach proxyHeaders on
axios error.response for non-2xx.

Co-authored-by: ProxyMesh AI <proxymeshai@users.noreply.github.com>
Cache hits never CONNECT, so ALS and the Response have no tunnel socket.
Remember CONNECT headers from the live fetch by URL and restore them on
hit instead of falling back to the shared agent's last-write-wins snapshot.

Co-authored-by: ProxyMesh AI <proxymeshai@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants