Update dependency socket.io to v4 #25
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.3.6->4.5.1Release Notes
socketio/socket.io
v4.5.1Compare Source
Bug Fixes
v4.5.0Compare Source
Bug Fixes
Features
This is similar to
onAny(), but for outgoing packets.Syntax:
Syntax:
So that clients in HTTP long-polling can decide how many packets they have to send to stay under the maxHttpBufferSize
value.
This is a backward compatible change which should not mandate a new major revision of the protocol (we stay in v4), as
we only add a field in the JSON-encoded handshake data:
4.4.1 (2022-01-06)
Bug Fixes
RemoteSocket.datatype safe (#4234) (770ee59)SocketDatatype to custom namespaces (#4233) (f2b8de7)v4.4.1Compare Source
Bug Fixes
RemoteSocket.datatype safe (#4234) (770ee59)SocketDatatype to custom namespaces (#4233) (f2b8de7)v4.4.0Compare Source
Bug Fixes
Features
socket.data(#4159) (fe8730c)4.3.2 (2021-11-08)
Bug Fixes
4.3.1 (2021-10-16)
Bug Fixes
v4.3.2Compare Source
Bug Fixes
v4.3.1Compare Source
Bug Fixes
v4.3.0Compare Source
Bug Fixes
Features
v4.2.0Compare Source
Bug Fixes
Features
4.1.3 (2021-07-10)
Bug Fixes
4.1.2 (2021-05-17)
Bug Fixes
4.1.1 (2021-05-11)
Bug Fixes
v4.1.3Compare Source
Bug Fixes
v4.1.2Compare Source
Bug Fixes
v4.1.1Compare Source
Bug Fixes
v4.1.0Compare Source
Features
engine.io)engine.io)Performance Improvements
4.0.2 (2021-05-06)
Bug Fixes
4.0.1 (2021-03-31)
Bug Fixes
v4.0.2Compare Source
Bug Fixes
v4.0.1Compare Source
Bug Fixes
v4.0.0Compare Source
Bug Fixes
Features
3.1.2 (2021-02-26)
Bug Fixes
3.1.1 (2021-02-03)
Bug Fixes
v3.1.2Compare Source
Bug Fixes
v3.1.1Compare Source
Bug Fixes
v3.1.0Compare Source
Features
Bug Fixes
3.0.5 (2021-01-05)
Bug Fixes
Reverts
3.0.4 (2020-12-07)
3.0.3 (2020-11-19)
3.0.2 (2020-11-17)
Bug Fixes
3.0.1 (2020-11-09)
Bug Fixes
v3.0.5Compare Source
Bug Fixes
Reverts
v3.0.4Compare Source
v3.0.3Compare Source
v3.0.2Compare Source
Bug Fixes
v3.0.1Compare Source
Bug Fixes
v3.0.0Compare Source
Bug Fixes
Features
BREAKING CHANGES
the Socket#use() method is removed (see 5c73733)
Socket#join() and Socket#leave() do not accept a callback argument anymore.
Before:
After:
Before:
The 'origins' option was used in the allowRequest method, in order to
determine whether the request should pass or not. And the Engine.IO
server would implicitly add the necessary Access-Control-Allow-xxx
headers.
After:
The already existing 'allowRequest' option can be used for validation:
Socket#rooms is now a Set instead of an object
Namespace#connected is now a Map instead of an object
there is no more implicit connection to the default namespace:
This method was kept for backward-compatibility with pre-1.0 versions.
v2.5.0Compare Source
The default value of the
maxHttpBufferSizeoption has been decreased from 100 MB to 1 MB, in order to prevent attacks by denial of service.Security advisory: GHSA-j4f2-536g-r55m
Bug Fixes
Links:
~3.6.0(diff)~7.4.2v2.4.1Compare Source
This release reverts the breaking change introduced in
2.4.0(socketio/socket.io@f78a575).If you are using Socket.IO v2, you should explicitly allow/disallow cross-origin requests:
In any case, please consider upgrading to Socket.IO v3, where this security issue is now fixed (CORS is disabled by default).
Reverts
Links:
~3.5.0~7.4.2v2.4.0Compare Source
Related blog post: https://socket.io/blog/socket-io-2-4-0/
Features (from Engine.IO)
Bug Fixes
Previously, CORS was enabled by default, which meant that a Socket.IO server sent the necessary CORS headers (
Access-Control-Allow-xxx) to any domain. This will not be the case anymore, and you now have to explicitly enable it.Please note that you are not impacted if:
originsoption to restrict the list of allowed domainsThis commit also removes the support for '*' matchers and protocol-less URL:
To restore the previous behavior (please use with caution):
See also:
Thanks a lot to @ni8walk3r for the security report.
Links:
~3.5.0~7.4.2v2.3.0Compare Source
This release mainly contains a bump of the
engine.ioandwspackages, but no additional features.Links:
~3.4.0(diff: socketio/engine.io@3.3.1...3.4.2)^7.1.2(diff: websockets/ws@6.1.2...7.3.1)v2.2.0Compare Source
Features
Bug fixes
Links
~3.3.1(diff: socketio/engine.io@3.2.0...3.3.1)~6.1.0(diff: websockets/ws@3.3.1...6.1.2)v2.1.1Compare Source
Features
Bug fixes
(client) fire an error event on middleware failure for non-root namespace (socketio/socket.io-client#1202)
Links:
~3.2.0~3.3.1v2.1.0Compare Source
Features
Bug fixes
Important note⚠️ from Engine.IO 3.2.0 release
There are two non-breaking changes that are somehow quite important:
wswas reverted as the default wsEngine ([chore] Revert towsas default wsEngine socketio/engine.io#550), as there was several blocking issues withuws. You can still useuwsby runningnpm install uws --savein your project and using thewsEngineoption:pingTimeoutnow defaults to 5 seconds (instead of 60 seconds): [chore] Update default value of pingTimeout socketio/engine.io#551Links:
~3.2.0(diff: socketio/engine.io@3.1.0...3.2.0)~3.3.1(diff: websockets/ws@2.3.1...3.3.1)v2.0.4Compare Source
Bug fixes
Links:
engine.io: -ws: -v2.0.3Compare Source
Bug fixes
Links:
engine.io: -ws: -v2.0.2Compare Source
Bug fixes
Links:
engine.io: -ws: -v2.0.1Compare Source
Bug fixes
- update path of client file (#2934)
Links:
engine.io: -ws: -v2.0.0Compare Source
This major release brings several performance improvements:
uws is now the default Websocket engine. It should bring significant improvement in performance (particularly in terms of memory consumption) (https://github.com/socketio/engine.io/releases/tag/2.0.0)
the Engine.IO and Socket.IO handshake packets were merged, reducing the number of roundtrips necessary to establish a connection. (#2833)
it is now possible to provide a custom parser according to the needs of your application (#2829). Please take a look at the example for more information.
Please note that this release is not backward-compatible, due to:
Please also note that if you are using a self-signed certificate,
rejectUnauthorizednow defaults totrue(socketio/engine.io-client#558).Finally, the API documentation is now in the repository (here), and the content of the website here. Do not hesitate if you see something wrong or missing!
The full list of changes:
localflag (#2816)clientsmethod in the API documentation (#2812)Besides, we are proud to announce that Socket.IO is now a part of open collective: https://opencollective.com/socketio. More on that later.
v1.7.4Compare Source
v1.7.3Compare Source
v1.7.2Compare Source
v1.7.1Compare Source
(following
socket.io-clientupdate)v1.7.0Compare Source
localflag (#2628)v1.6.0Compare Source
v1.5.1Compare Source
clientin test script (#2731)v1.5.0Compare Source
v1.4.8Compare Source
v1.4.7Compare Source
v1.4.6Compare Source
v1.4.5Compare Source
v1.4.4Compare Source
v1.4.3Compare Source
v1.4.2Compare Source
v1.4.1Compare Source
v1.4.0Compare Source
v1.3.7Compare Source
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.