NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #3256 most downloaded on Packagist
Provides an easy interface for performing Hyper-Text Transfer Protocol (HTTP) requests
Last release 7 years ago
no release in 18 months
Release timing varies
gaps range from 2 weeks to 10 months
Some releases are documented
notes for 19 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
14 years old
79 releases · first in 2012
Added Nothing. Changed Nothing. Deprecated Nothing. Removed Nothing. Fixed #207 fixes case sensitivity for SameSite directive.
Added Nothing. Changed Nothing. Deprecated Nothing. Removed Nothing. Fixed #204 fixes numerous header classes to cast field value to string (since Hea
One column per quarter.
Added #175 adds support for Content Security Policy Level 3 Header directives. #200 adds support for additional directives in Content Security Policy
#175 adds support for Content Security Policy Level 3 Header directives.
#200 adds support for additional directives in Content Security Policy header:
block-all-mixed-content,require-sri-for,trusted-types,upgrade-insecure-requests.#177 adds support for Feature Policy header.
#186 adds support for SameSite directive in Set-Cookie header.
Added Nothing. Changed #190 changes ContentSecurityPolicy to allow multiple values. Before it was not possible to provide multiple headers of that typ
ContentSecurityPolicy to allow multiple values. Before it was not possible to provide multiple headers of that type.#184 fixes responses for request through the proxy with HTTP/1.1 200 Connection established header.
#187 fixes infinite recursion on invalid header. Now InvalidArgumentException exception is thrown.
#188 fixes Client::setCookies method to properly handle array of SetCookie objects. Per documentation it should be allowed.
#189 fixes Headers::toArray method to properly handle headers of the same type. Behaviour was different depends how header has been attached (addHeader or addHeaderLine broken before).
#198 fixes merging options in Curl adapter. It was not possible to override integer-key options (constants) set via constructor with method setOptions.
#198 fixes allowed options type in Proxy::setOptions. Traversable, array or Zend\Config object is expected.
#198 fixes various issues with Proxy adapter.
#199 fixes saving resource to the file when streaming while client supports compression. Before, incorrectly, compressed resource was saved into the file.
Added #173 adds support for HTTP/2 requests and responses. Changed Nothing. Deprecated Nothing. Removed Nothing. Fixed Nothing.
Added Nothing. Changed Nothing. Deprecated Nothing. Removed Nothing. Fixed #168 fixes a problem when validating the connection timeout for the Curl an
Curl andSocket client adapters; it now correctly identifies both integer and stringAdded #154 adds the method SetCookie::setEncodeValue() . By default, Set-Cookie values are passed through urlencode() ; when a boolean false is provid
#154 adds the method SetCookie::setEncodeValue(). By default, Set-Cookie
values are passed through urlencode(); when a boolean false is provided to
this new method, the raw value will be used instead.
#166 adds support for PHP 7.3.
#154 changes the behavior of SetCookie::fromString() slightly: if the parsed
cookie value is the same as the one passed through urldecode(), the
SetCookie header's $encodeValue property will be toggled off to ensure the
value is not encoded in subsequent serializations, thus retaining the
integrity of the value between usages.
#161 changes how the Socket and Test adapters aggregate headers. Previously,
they would ucfirst() the header name; now, they correctly leave the header
names untouched, as header names should be considered case-insensitive.
#156 changes how gzip and deflate decompression occur in responses, ensuring
that if the Content-Length header reports 0, no decompression is attempted,
and an empty string is returned.
Added Nothing. Changed Nothing. Deprecated Nothing. Removed Nothing. Fixed #168 fixes a problem when validating the connection timeout for the Curl an
Curl andSocket client adapters; it now correctly identifies both integer and stringAdded Nothing. Changed Nothing. Deprecated Nothing. Removed Nothing. Fixed #165 fixes detection of the base URL when operating under a CLI environment
#165 fixes detection of the base URL when operating under a CLI environment.
#149 provides fixes to Client::setUri() to ensure its status as a relative
or absolute URI is correctly memoized.
#162 fixes a typo in an exception message raised within Cookies::fromString().
#121 adds detection for non-numeric connection timeout values as well as
integer casting to ensure the timeout is set properly in both the Curl and
Socket adapters.
Added Nothing. Changed #153 changes the reason phrase associated with the status code 425 from "Unordered Collection" to "Too Early", corresponding to
Zend\Http\Exception\InvalidArgumentExceptionThis release modifies how Zend\Http\PhpEnvironment\Request marshals the request URI. In prior releases, we would attempt to inspect the X-Rewrite-Url
This release modifies how Zend\Http\PhpEnvironment\Request marshals the
request URI. In prior releases, we would attempt to inspect the
X-Rewrite-Url and X-Original-Url headers, using their values, if present.
These headers are issued by the ISAPI_Rewrite module for IIS (developed by
HeliconTech). However, we have no way of guaranteeing that the module is what
issued the headers, making it an unreliable source for discovering the URI. As
such, we have removed this feature in this release of zend-http.
If you are developing a zend-mvc application, you can mimic the functionality by adding a bootstrap listener like the following:
public function onBootstrap(MvcEvent $mvcEvent)
{
$request = $mvcEvent->getRequest();
$requestUri = null;
$httpXRewriteUrl = $request->getHeader('X-Rewrite-Url');
if ($httpXRewriteUrl) {
$requestUri = $httpXRewriteUrl->getFieldValue();
}
$httpXOriginalUrl = $request->getHeader('X-Original-Url');
if ($httpXOriginalUrl) {
$requestUri = $httpXOriginalUrl->getFieldValue();
}
if ($requestUri) {
$request->setUri($requestUri)
}
}
If you use a listener such as the above, make sure you also instruct your web server to strip any incoming headers of the same name so that you can guarantee they are issued by the ISAPI_Rewrite module.
introduces changes to Response::fromString() to pull the next line of the response and parse it for the status when a 100 status code is initially enc
#135 adds a package suggestion of paragonie/certainty, which provides automated management of cacert.pem files.
#143 adds support for PHP 7.2.
#140 fixes retrieval of headers when multiple headers of the same name
are added to the Headers instance; it now ensures that the last header added of the same
type is retrieved when it is not a multi-value type. Previous values are overwritten.
#112 provides performance improvements when parsing large chunked messages.
introduces changes to Response::fromString() to pull the next line of the response
and parse it for the status when a 100 status code is initially encountered, per https://tools.ietf.org/html/rfc7231#section-6.2.1
#122 fixes an issue with the stream response whereby if the outputstream
option is set, the output file was opened twice; it is now opened exactly once.
#147 fixes an issue with header retrieval when the header line is malformed.
Previously, an exception would be raised if a specific HeaderInterface implementation determined
the header line was invalid. Now, Header::has() will return false for such headers, allowing
Request::getHeader() to return false or the provided default value. Additionally, in cases
where the header name is malformed (e.g., Useragent instead of User-Agent, users can still
retrieve by the submitted header name; they will receive a GenericHeader instance in such
cases, however.
#133 Adds back missing sprintf placeholder in CacheControl exception message
### Added - #110 Adds status codes 226, 308, 444, 499, 510, 599 with their corresponding constants and reason phrases. ### Changed - #120 Changes hand
### Added - #99 added TimeoutException for cURL adapter. - #98 added connection timeout (connecttimeout) for cURL and Socket adapters. - #97 added sup
### Added - Nothing. ### Deprecated - Nothing. ### Removed - Nothing. ### Fixed - #107 fixes the Expires header to allow values of 0 or '0'; these now
Expires header to allow values of 0 or '0'; these now resolve
to the start of the unix epoch (1970-01-01).none (empty value).### Added - #44, #45, #46, #47, #48, and #49 prepare the documentation for publication at https://zendframework.github.io/zend-http/ ### Deprecated -
ContentLength constructor to test for a non null value (vs a falsy value)
before validating the value; this ensures 0 values may be specified for the
length.### Added - Nothing. ### Deprecated - Nothing. ### Removed - Nothing. ### Fixed - #42 updates dependencies to ensure it can work with PHP 5.5+ and 7.0
### Added - Nothing. ### Deprecated - Nothing. ### Removed - Nothing. ### Fixed - #23 fixes a BC break introduced with fixes for ZF2015-04, pertaining
SetCookie header. The fix backs out a
check for message splitting syntax, as that particular class already encodes
the value in a manner that prevents the attack. It also adds tests to ensure
the security vulnerability remains patched.### Added - Nothing. ### Deprecated - Nothing. ### Removed - Nothing. ### Fixed - #7 fixes a call in the proxy adapter to Response::extractCode(), whi
Response::extractCode(), which does not exist, to
Response::fromString()->getStatusCode(), which does.CURLINFO_HEADER_OUT, which is required to ensure
we can fetch the raw request after it is sent.Zend\Http\PhpEnvironment\Request to ensure that empty SCRIPT_FILENAME and
SCRIPT_NAME values which result in an empty $baseUrl will not raise an
E_WARNING when used to do a strpos() check during base URI detection.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →