zendframework/zend-http
Abandoned; use laminas/laminas-http. Provides an easy interface for performing Hyper-Text Transfer Protocol (HTTP) requests
2.11.2
25M downloads/mo
#2716 most downloaded on Packagist
zendframework/zend-http
What this package is like to depend on
Last release 7 years ago
no release in 18 months
Release timing varies
gaps range from 2 weeks to 10 months
Rarely documented
notes for 19 of 79 stable releases
Nothing withdrawn
no release was ever pulled
14 years old
79 releases · first in 2012
0 releases in the last 12 months
see the full history below
Release timeline
53 releases · Oct 2012 to Dec 2019Releases
latest 60 of 79-
2.11.230 Dec 2019Release notes
Open source →Added
- Nothing.
Changed
- Nothing.
Deprecated
- Nothing.
Removed
- Nothing.
Fixed
- #207 fixes case sensitivity for SameSite directive.
Release notes
Open source →Added
- Nothing.
Changed
- Nothing.
Deprecated
- Nothing.
Removed
- Nothing.
Fixed
- #207 fixes case sensitivity for SameSite directive.
-
2.11.104 Dec 2019Release notes
Open source →Added
- Nothing.
Changed
- Nothing.
Deprecated
- Nothing.
Removed
- Nothing.
Fixed
Release notes
Open source →Added
- Nothing.
Changed
- Nothing.
Deprecated
- Nothing.
Removed
- Nothing.
Fixed
-
2.11.003 Dec 2019Release notes
Open source →Added
-
#175 adds support for Content Security Policy Level 3 Header directives.
-
#200 adds support for additional directives in Content Security Policy header:
block-all-mixed-content,require-sri-for,trusted-types,upgrade-insecure-requests.
-
#177 adds support for Feature Policy header.
-
#186 adds support for SameSite directive in Set-Cookie header.
Changed
- #194 changes range of valid HTTP status codes to 100-599 (inclusive).
Deprecated
- Nothing.
Removed
- Nothing.
Fixed
- #200 fixes support for directives without value in Content Security Policy header.
Release notes
Open source →Added
-
#175 adds support for Content Security Policy Level 3 Header directives.
-
#200 adds support for additional directives in Content Security Policy header:
block-all-mixed-content,require-sri-for,trusted-types,upgrade-insecure-requests.
-
#177 adds support for Feature Policy header.
-
#186 adds support for SameSite directive in Set-Cookie header.
Changed
- #194 changes range of valid HTTP status codes to 100-599 (inclusive).
Deprecated
- Nothing.
Removed
- Nothing.
Fixed
- #200 fixes support for directives without value in Content Security Policy header.
-
-
2.10.102 Dec 2019Release notes
Open source →Added
- Nothing.
Changed
- #190 changes
ContentSecurityPolicyto allow multiple values. Before it was not possible to provide multiple headers of that type.
Deprecated
- Nothing.
Removed
- Nothing.
Fixed
-
#184 fixes responses for request through the proxy with
HTTP/1.1 200 Connection establishedheader. -
#187 fixes infinite recursion on invalid header. Now
InvalidArgumentExceptionexception is thrown. -
#188 fixes
Client::setCookiesmethod to properly handle array ofSetCookieobjects. Per documentation it should be allowed. -
#189 fixes
Headers::toArraymethod to properly handle headers of the same type. Behaviour was different depends how header has been attached (addHeaderoraddHeaderLinebroken before). -
#198 fixes merging options in Curl adapter. It was not possible to override integer-key options (constants) set via constructor with method
setOptions. -
#198 fixes allowed options type in
Proxy::setOptions.Traversable,arrayorZend\Configobject is expected. -
#198 fixes various issues with
Proxyadapter. -
#199 fixes saving resource to the file when streaming while client supports compression. Before, incorrectly, compressed resource was saved into the file.
Release notes
Open source →Added
- Nothing.
Changed
- #190 changes
ContentSecurityPolicyto allow multiple values. Before it was not possible to provide multiple headers of that type.
Deprecated
- Nothing.
Removed
- Nothing.
Fixed
-
#184 fixes responses for request through the proxy with
HTTP/1.1 200 Connection establishedheader. -
#187 fixes infinite recursion on invalid header. Now
InvalidArgumentExceptionexception is thrown. -
#188 fixes
Client::setCookiesmethod to properly handle array ofSetCookieobjects. Per documentation it should be allowed. -
#189 fixes
Headers::toArraymethod to properly handle headers of the same type. Behaviour was different depends how header has been attached (addHeaderoraddHeaderLinebroken before). -
#198 fixes merging options in Curl adapter. It was not possible to override integer-key options (constants) set via constructor with method
setOptions. -
#198 fixes allowed options type in
Proxy::setOptions.Traversable,arrayorZend\Configobject is expected. -
#198 fixes various issues with
Proxyadapter. -
#199 fixes saving resource to the file when streaming while client supports compression. Before, incorrectly, compressed resource was saved into the file.
-
2.10.019 Feb 2019Release notes
Open source →Added
- #173 adds support for HTTP/2 requests and responses.
Changed
- Nothing.
Deprecated
- Nothing.
Removed
- Nothing.
Fixed
- Nothing.
Release notes
Open source →Added
- #173 adds support for HTTP/2 requests and responses.
Changed
- Nothing.
Deprecated
- Nothing.
Removed
- Nothing.
Fixed
- Nothing.
-
2.9.122 Jan 2019Release notes
Open source →Added
- Nothing.
Changed
- Nothing.
Deprecated
- Nothing.
Removed
- Nothing.
Fixed
- #168 fixes a problem when validating the connection timeout for the
Curland
Socketclient adapters; it now correctly identifies both integer and string
integer values.
Release notes
Open source →Added
- Nothing.
Changed
- Nothing.
Deprecated
- Nothing.
Removed
- Nothing.
Fixed
- #168 fixes a problem when validating the connection timeout for the
CurlandSocketclient adapters; it now correctly identifies both integer and string integer values.
-
2.9.008 Jan 2019Release notes
Open source →Added
-
#154 adds the method
SetCookie::setEncodeValue(). By default, Set-Cookie
values are passed throughurlencode(); when a booleanfalseis provided to
this new method, the raw value will be used instead. -
#166 adds support for PHP 7.3.
Changed
-
#154 changes the behavior of
SetCookie::fromString()slightly: if the parsed
cookie value is the same as the one passed throughurldecode(), the
SetCookieheader's$encodeValueproperty will be toggled off to ensure the
value is not encoded in subsequent serializations, thus retaining the
integrity of the value between usages. -
#161 changes how the Socket and Test adapters aggregate headers. Previously,
they woulducfirst()the header name; now, they correctly leave the header
names untouched, as header names should be considered case-insensitive. -
#156 changes how gzip and deflate decompression occur in responses, ensuring
that if the Content-Length header reports 0, no decompression is attempted,
and an empty string is returned.
Deprecated
- Nothing.
Removed
- #166 removes support for zend-stdlib v2 releases.
Fixed
- Nothing.
Release notes
Open source →Added
-
#154 adds the method
SetCookie::setEncodeValue(). By default, Set-Cookie values are passed throughurlencode(); when a booleanfalseis provided to this new method, the raw value will be used instead. -
#166 adds support for PHP 7.3.
Changed
-
#154 changes the behavior of
SetCookie::fromString()slightly: if the parsed cookie value is the same as the one passed throughurldecode(), theSetCookieheader's$encodeValueproperty will be toggled off to ensure the value is not encoded in subsequent serializations, thus retaining the integrity of the value between usages. -
#161 changes how the Socket and Test adapters aggregate headers. Previously, they would
ucfirst()the header name; now, they correctly leave the header names untouched, as header names should be considered case-insensitive. -
#156 changes how gzip and deflate decompression occur in responses, ensuring that if the Content-Length header reports 0, no decompression is attempted, and an empty string is returned.
Deprecated
- Nothing.
Removed
- #166 removes support for zend-stdlib v2 releases.
Fixed
- Nothing.
-
-
2.8.407 Feb 2019Release notes
Open source →Added
- Nothing.
Changed
- Nothing.
Deprecated
- Nothing.
Removed
- Nothing.
Fixed
- #168 fixes a problem when validating the connection timeout for the
Curland
Socketclient adapters; it now correctly identifies both integer and string
integer values.
-
2.8.308 Jan 2019Release notes
Open source →Added
- Nothing.
Changed
- Nothing.
Deprecated
- Nothing.
Removed
- Nothing.
Fixed
-
#165 fixes detection of the base URL when operating under a CLI environment.
-
#149 provides fixes to
Client::setUri()to ensure its status as a relative
or absolute URI is correctly memoized. -
#162 fixes a typo in an exception message raised within
Cookies::fromString(). -
#121 adds detection for non-numeric connection timeout values as well as
integer casting to ensure the timeout is set properly in both the Curl and
Socket adapters.
Release notes
Open source →Added
- Nothing.
Changed
- Nothing.
Deprecated
- Nothing.
Removed
- Nothing.
Fixed
-
#165 fixes detection of the base URL when operating under a CLI environment.
-
#149 provides fixes to
Client::setUri()to ensure its status as a relative or absolute URI is correctly memoized. -
#162 fixes a typo in an exception message raised within
Cookies::fromString(). -
#121 adds detection for non-numeric connection timeout values as well as integer casting to ensure the timeout is set properly in both the Curl and Socket adapters.
-
2.8.213 Aug 2018Release notes
Open source →Added
- Nothing.
Changed
- #153 changes the reason phrase associated with the status code 425
from "Unordered Collection" to "Too Early", corresponding to a new definition
of the code as specified by the IANA.
Deprecated
- Nothing.
Removed
- Nothing.
Fixed
- #151 fixes how Referer and other location-based headers report problems with
invalid URLs provided in the header value, raising aZend\Http\Exception\InvalidArgumentException
in such cases. This change ensures the behavior is consistent with behavior
prior to the 2.8.0 release.
Release notes
Open source →Added
- Nothing.
Changed
- #153 changes the reason phrase associated with the status code 425 from "Unordered Collection" to "Too Early", corresponding to a new definition of the code as specified by the IANA.
Deprecated
- Nothing.
Removed
- Nothing.
Fixed
- #151 fixes how Referer and other location-based headers report problems with
invalid URLs provided in the header value, raising a
Zend\Http\Exception\InvalidArgumentExceptionin such cases. This change ensures the behavior is consistent with behavior prior to the 2.8.0 release.
-
2.8.101 Aug 2018Release notes
Open source →Added
- Nothing.
Changed
-
This release modifies how
Zend\Http\PhpEnvironment\Requestmarshals the request URI. In prior releases, we would attempt to inspect theX-Rewrite-UrlandX-Original-Urlheaders, using their values, if present. These headers are issued by the ISAPI_Rewrite module for IIS (developed by HeliconTech). However, we have no way of guaranteeing that the module is what issued the headers, making it an unreliable source for discovering the URI. As such, we have removed this feature in this release of zend-http.If you are developing a zend-mvc application, you can mimic the functionality by adding a bootstrap listener like the following:
public function onBootstrap(MvcEvent $mvcEvent) { $request = $mvcEvent->getRequest(); $requestUri = null; $httpXRewriteUrl = $request->getHeader('X-Rewrite-Url'); if ($httpXRewriteUrl) { $requestUri = $httpXRewriteUrl->getFieldValue(); } $httpXOriginalUrl = $request->getHeader('X-Original-Url'); if ($httpXOriginalUrl) { $requestUri = $httpXOriginalUrl->getFieldValue(); } if ($requestUri) { $request->setUri($requestUri) } }If you use a listener such as the above, make sure you also instruct your web server to strip any incoming headers of the same name so that you can guarantee they are issued by the ISAPI_Rewrite module.
Deprecated
- Nothing.
Removed
- Nothing.
Fixed
- Nothing.
-
2.8.026 Apr 2018Release notes
Open source →Added
-
#135 adds a package suggestion of paragonie/certainty, which provides automated management of cacert.pem files.
-
#143 adds support for PHP 7.2.
Changed
- Nothing.
Deprecated
- Nothing.
Removed
- Nothing.
Fixed
-
#140 fixes retrieval of headers when multiple headers of the same name are added to the
Headersinstance; it now ensures that the last header added of the same type is retrieved when it is not a multi-value type. Previous values are overwritten. -
#112 provides performance improvements when parsing large chunked messages.
-
introduces changes to
Response::fromString()to pull the next line of the response and parse it for the status when a 100 status code is initially encountered, per https://tools.ietf.org/html/rfc7231#section-6.2.1 -
#122 fixes an issue with the stream response whereby if the
outputstreamoption is set, the output file was opened twice; it is now opened exactly once. -
#147 fixes an issue with header retrieval when the header line is malformed. Previously, an exception would be raised if a specific
HeaderInterfaceimplementation determined the header line was invalid. Now,Header::has()will return false for such headers, allowingRequest::getHeader()to returnfalseor the provided default value. Additionally, in cases where the header name is malformed (e.g.,Useragentinstead ofUser-Agent, users can still retrieve by the submitted header name; they will receive aGenericHeaderinstance in such cases, however. -
#133 Adds back missing sprintf placeholder in CacheControl exception message
-
-
2.7.013 Oct 2017Release notes
Open source →Added
- #110 Adds status codes 226, 308, 444, 499, 510, 599 with their corresponding constants and reason phrases.
Changed
- #120 Changes handling of Cookie Max-Age parameter to conform to specification rfc6265#section-5.2.2. Specifically, non-numeric values are ignored and negative numbers are changed to 0.
Deprecated
- Nothing.
Removed
- #115 dropped php 5.5 support
Fixed
- #130 Fixed cURL adapter not resetting headers from previous request when used with output stream.
-
2.6.031 Jan 2017Release notes
Open source →Added
- #99 added TimeoutException for cURL adapter.
- #98 added connection
timeout (
connecttimeout) for cURL and Socket adapters. - #97 added support to
sslcafileandsslcapathto cURL adapter.
Deprecated
- Nothing.
Removed
- Nothing.
Fixed
- Nothing.
-
2.5.631 Jan 2017Release notes
Open source →Added
- Nothing.
Deprecated
- Nothing.
Removed
- Nothing.
Fixed
- #107 fixes the
Expiresheader to allow values of0or'0'; these now resolve to the start of the unix epoch (1970-01-01). - #102 fixes the Curl adapter timeout detection.
- #93 fixes the Content
Security Policy CSP HTTP header when it is
none(empty value). - #92 fixes the flatten cookies value for array value (also multidimensional).
- #34 fixes the standard separator (&) for application/x-www-form-urlencoded.
-
2.5.508 Aug 2016Release notes
Open source →Added
- #44, #45, #46, #47, #48, and #49 prepare the documentation for publication at https://zendframework.github.io/zend-http/
Deprecated
- Nothing.
Removed
- Nothing.
Fixed
- #87 fixes the
ContentLengthconstructor to test for a non null value (vs a falsy value) before validating the value; this ensures 0 values may be specified for the length. - #85 fixes infinite recursion on AbstractAccept. If you create a new Accept and try to call getFieldValue(), an infinite recursion and a fatal error happens.
- #58 avoid triggering a notice with special crafted accept headers. In the case the value of an accept header does not contain an equal sign, an "Undefined offset" notice is triggered.
-
2.5.404 Feb 2016Release notes
Open source →Added
- Nothing.
Deprecated
- Nothing.
Removed
- Nothing.
Fixed
- #42 updates dependencies to ensure it can work with PHP 5.5+ and 7.0+, as well as zend-stdlib 2.5+/3.0+.
-
2.5.314 Sep 2015Release notes
Open source →Added
- Nothing.
Deprecated
- Nothing.
Removed
- Nothing.
Fixed
- #23 fixes a BC break
introduced with fixes for ZF2015-04,
pertaining specifically to the
SetCookieheader. The fix backs out a check for message splitting syntax, as that particular class already encodes the value in a manner that prevents the attack. It also adds tests to ensure the security vulnerability remains patched.
-
2.5.205 Aug 2015Release notes
Open source →Added
- Nothing.
Deprecated
- Nothing.
Removed
- Nothing.
Fixed
- #7 fixes a call in the
proxy adapter to
Response::extractCode(), which does not exist, toResponse::fromString()->getStatusCode(), which does. - #8 ensures that the Curl
client adapter enables the
CURLINFO_HEADER_OUT, which is required to ensure we can fetch the raw request after it is sent. - #14 fixes
Zend\Http\PhpEnvironment\Requestto ensure that emptySCRIPT_FILENAMEandSCRIPT_NAMEvalues which result in an empty$baseUrlwill not raise anE_WARNINGwhen used to do astrpos()check during base URI detection.
-
2.5.103 Jun 2015Nothing published for this version
-
2.5.003 Jun 2015Nothing published for this version
-
2.4.1314 Sep 2015Nothing published for this version
-
2.4.12no dateNothing published for this version
-
2.4.11no dateNothing published for this version
-
2.4.10no dateNothing published for this version
-
2.4.9no dateNothing published for this version
-
2.4.8no dateNothing published for this version
-
2.4.711 May 2015Nothing published for this version
-
2.4.6no dateNothing published for this version
-
2.4.5no dateNothing published for this version
-
2.4.4no dateNothing published for this version
-
2.4.3no dateNothing published for this version
-
2.4.2no dateNothing published for this version
-
2.4.107 May 2015Nothing published for this version
-
2.4.027 Mar 2015Nothing published for this version
-
2.3.911 May 2015Nothing published for this version
-
2.3.807 May 2015Nothing published for this version
-
2.3.710 Feb 2015Nothing published for this version
-
2.3.6no dateNothing published for this version
-
2.3.5no dateNothing published for this version
-
2.3.413 Jan 2015Nothing published for this version
-
2.3.311 Aug 2014Nothing published for this version
-
2.3.2no dateNothing published for this version
-
2.3.115 Apr 2014Nothing published for this version
-
2.3.012 Mar 2014Nothing published for this version
-
2.2.1005 Mar 2014Nothing published for this version
-
2.2.9no dateNothing published for this version
-
2.2.8no dateNothing published for this version
-
2.2.7no dateNothing published for this version
-
2.2.6no dateNothing published for this version
-
2.2.531 Oct 2013Nothing published for this version
-
2.2.421 Aug 2013Nothing published for this version
-
2.2.3no dateNothing published for this version
-
2.2.223 Jul 2013Nothing published for this version
-
2.2.112 Jun 2013Nothing published for this version
-
2.2.010 May 2013Nothing published for this version
-
2.1.617 Apr 2013Nothing published for this version
-
2.1.5no dateNothing published for this version
-
2.1.413 Mar 2013Nothing published for this version
-
2.1.319 Feb 2013Nothing published for this version