NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #1288 most downloaded on Packagist
🌐 Nette Http: abstraction for HTTP request, response and session. Provides careful data sanitization and utility for URL and cookies manipulation.
Last release 1 months ago
27 Aug 2026
Ships fairly regularly
a new release about every 3 months
Rarely documented
notes for 11 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
61 releases · first in 2014
This release hardens the reverse-proxy trust model: the real client address, scheme and host are now resolved correctly from multi-hop Forwarded and X
This release hardens the reverse-proxy trust model: the real client address, scheme and host are now resolved correctly from multi-hop Forwarded and X-Forwarded-* headers, and you can choose which of them your proxy is allowed to speak for. On top of that, CLI scripts finally get a meaningful request URL.
X-Forwarded-* headers from a trusted proxy by default, so a client-supplied Forwarded header can no longer spoof the address or host. If your proxy uses the Forwarded header, set http: proxyHeaders: forwarded (or both).null instead of a non-IP string when the innermost forwarded value is not a valid IP address (e.g. an obfuscated identifier or a broken chain).both|xForwarded|forwarded|none) and the $forwarded / $xForwarded flags of RequestFactory::setProxy() let you tell Nette exactly which forwarding headers your proxy manages – and ignore the rest.http: baseUrl option give CLI runs (cron, tasks, MCP servers) a real request URL, so %baseUrl%, LinkGenerator, template $baseUrl and assets work outside the web server too. It kicks in only when no host can be detected, so web requests are unaffected.Forwarded into proper RFC 7239 hops and picks the client by stripping trailing trusted proxies, instead of blindly trusting the leftmost, client-spoofable value; scheme and host are taken from the same hop as the selected address and no longer discarded on multi-hop headers.$path or $domain as given: '' now yields a host-only cookie or the / path instead of silently falling back to the configured defaults. Only null means "not specified".One column per quarter.
UserStorage is gone – the long-deprecated class has been removed. Use the standard authentication storage instead.
This release brings serious firepower to server-side HTTP handling. The headline is a brand-new SSRF defense kit – IPAddress and UrlValidator let you validate URLs and pin connections before your app ever talks to an attacker-controlled host. On top of that, cookie handling gets a modern overhaul with a type-safe SameSite enum, CHIPS/Partitioned support, and a proper Max-Age attribute, while the new Request::isFrom() gives you reliable same-site request detection – even on Safari. Now on PHP 8.3.
UserStorage is gone – the long-deprecated class has been removed. Use the standard authentication storage instead.Request::getRemoteHost() is deprecated and now returns null – reverse DNS lookups were slow, unreliable, and a privacy footgun. Resolve the hostname yourself from getRemoteAddress() if you really need it (#218).IResponse::SameSite* constants are deprecated in favor of the new SameSite enum.Request::isSameSite() is deprecated – use isFrom() instead.0 as the expiration to Response::setCookie() is deprecated – use null for a session cookie.isPublic(), isPrivate(), isLoopback(), isLinkLocal(), isMulticast(), isReserved()), CIDR matching via isInRange(), and IPv4-mapped IPv6 normalization. Pair it with UrlValidator, a configurable guard that vets scheme, port, host allow/blocklists, userinfo, and – optionally with DNS – the resolved IP ranges. It even hands back the resolved IPs so you can pin the connection through CURLOPT_RESOLVE and defeat DNS-rebinding.Request::isFrom() – a single, reliable way to check where a request came from, with site, dest, and user parameters built on the Sec-Fetch-* headers. For browsers without Sec-Fetch support (Safari < 16.4), it transparently falls back to a strict cookie, so same-site detection just works everywhere.SameSite enum – setCookie() and Session now accept a proper enum instead of magic strings, so typos become compile-time problems, not silent security holes.Response::setCookie() speaks modern cookie – it now supports the Partitioned attribute (CHIPS) for third-party cookies, emits a Max-Age attribute (which takes precedence over expires and ignores the client clock), and forces Secure automatically when SameSite=None, sparing you a browser rejection.Helpers::expirationToSeconds() – one consistent parser for every expiration value across the library. Numbers are relative seconds, while DateTimeInterface and textual strings like '20 minutes' or '2024-01-01' resolve as absolute times; each caller decides what null means in its own context.Helpers::parseQualityList() – parses HTTP quality-value lists (Accept, Accept-Language, …) into a ranked token map. Request::detectLanguage() was rewritten on top of it and is more correct as a result.RequestFactory::setForceHttps() – force the request scheme to HTTPS regardless of the server environment, handy behind proxies and load balancers that
http: forceHttps: true.null for any Origin header that isn't a bare scheme://host[:port] (e.g. headers containing a path are rejected instead of being silently accepted).Nette\Http namespace – better IDE autocompletion and PHPStan inference for Request, Response, Session, Url and friends.Url, UrlImmutable: user & password are deprecated
Url, UrlImmutable: user & password are deprecated
resolve()isAbsolute() & removeDotSegments()build() methodUrl::canonicalize() char " does not need to be encodedFileUpload::__construct() accepts pathFileUpload::getSanitizedName() changes the extension only for image files #239
FileUpload::getSanitizedName() changes the extension only for image files #239requires PHP 8.1 uses PHP 8.1 features
FileUpload: added getSuggestedExtension()
getSuggestedExtension()FileUpload: detects supported images
SessionExtension: don't set readAndClose if null
Session::getSectionNames(), replacement for getIterator()Nothing published for this version
SessionExtension: don't set readAndClose if null
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →