NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #51 most downloaded on PyPI
Async http client/server framework (asyncio)
Last release 2 months ago
23 Jul 2026
Release timing varies
gaps range from 8 days to 3 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
7 versions withdrawn
withdrawn after publishing
13 years old
312 releases · first in 2013
Nothing published for this version
Nothing published for this version
Fixed the client dropping only the first Authorization, Cookie and Proxy-Authorization header when a redirect crossed an origin -- by arshsmith1.
Fixed the client dropping only the first Authorization, Cookie and
Proxy-Authorization header when a redirect crossed an origin -- by :user:arshsmith1.
Related issues and pull requests on GitHub: #13180.
Fixed error message construction in the C HTTP parser -- by :user:bdraco.
Related issues and pull requests on GitHub: #13222.
One column per quarter.
Fixed the client dropping only the first Authorization, Cookie and
Proxy-Authorization header when a redirect crossed an origin -- by :user:arshsmith1.
Related issues and pull requests on GitHub:
#13180.
Fixed error message construction in the C HTTP parser -- by :user:bdraco.
Related issues and pull requests on GitHub:
#13222.
Added admin documentation on incident response and on running reproducer code safely, covering security vulnerability handling and supply-chain, accou…
Fixed ~aiohttp.web.StreamResponse.last_modified rounding a datetime.datetime with a fractional second down.
Related issues and pull requests on GitHub: #5303.
Fixed resolving localhost on Windows to fall back without AI_ADDRCONFIG when the first lookup fails, so localhost still works without an active network.
Related issues and pull requests on GitHub: #5357.
Rejected multipart body parts whose Content-Length header is not a plain sequence of digits (e.g. +5, -1, 1_0), matching the strictness of the main request parser per 9110#section-8.6 -- by dxbjavid.
Related issues and pull requests on GitHub: #12794.
Fixed GunicornWebWorker endlessly reloading when app fails during startup -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #12879.
Fixed some inconsistent case sensitivity on request methods -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #12931.
Fixed IndexError: string index out of range in parse_content_disposition when a header parameter has an empty value (e.g. filename=). -- by JSap0914.
Related issues and pull requests on GitHub: #12948.
Fixed the sock_read timeout being re-armed on a keep-alive connection after it had been returned to the pool. An idle pooled connection could be left with a pending read timeout that fired and poisoned it, so the next request reusing the connection failed immediately with aiohttp.SocketTimeoutError. The read timeout is now only rescheduled when resuming a transport that was actually paused -- by daragok.
Related issues and pull requests on GitHub: #12953, #12954.
Fixed the client decompressing frames when permessage-deflate was not negotiated -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #12976.
Fixed DigestAuthMiddleware raising an IndexError on empty domain -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #12983.
Fixed ~aiohttp.DigestAuthMiddleware corrupting the Digest challenge when a WWW-Authenticate response offered more than one authentication scheme -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #12984.
Fixed client not closing cleanly after an exception -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #12985.
Fixed control frames breaking fragmented WebSocket messages -- by arshsmith1.
Related issues and pull requests on GitHub: #12988.
Fixed parse_content_disposition rejecting otherwise-valid Content-Disposition header values that contain optional whitespace (OWS) around the disposition type (e.g. "form-data ; name=\"field\""). The disposition type is now stripped before token validation, consistent with how parameter keys are already handled -- by JSap0914.
Related issues and pull requests on GitHub: #12996.
Fixed an IndexError in the pure-Python HTTP parser -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #13001.
Fixed parsing optional whitespace in Content-Disposition -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #13002.
Fixed request body not being read on rejected WebSocket upgrades -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #13016.
Fixed LookupError (and an unguarded UnicodeDecodeError) escaping Content-Disposition parsing when a multipart part supplies an extended parameter with an unknown charset -- by arshsmith1.
Related issues and pull requests on GitHub: #13042.
Fixed escape_quotes in the Digest authentication middleware not escaping backslashes, so a WWW-Authenticate challenge value containing a backslash could break out of its quoted-string in the generated Authorization header -- by dxbjavid.
Related issues and pull requests on GitHub: #13054.
Fixed Python parser not rejecting a bare LF in the request line -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #13136.
Fixed the C HTTP parser folding the fragment into the query string for an origin-form request target with an empty query (e.g. /path?#frag), which diverged from the pure-Python parser -- by GiulioDER.
Related issues and pull requests on GitHub: #13171.
Fixed the C parser reporting newer HTTP methods such as QUERY as <unknown>; the method table is now derived from the vendored llhttp instead of a hand-maintained count -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #13174.
Upgraded llhttp to v9.4.2 -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #12956.
Added admin documentation on incident response and on running reproducer code safely, covering security vulnerability handling and supply-chain, account, and CI/infrastructure compromise -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #12914.
Fixed :py:attr:~aiohttp.web.StreamResponse.last_modified rounding a
:class:datetime.datetime with a fractional second down.
Related issues and pull requests on GitHub:
#5303.
Fixed resolving localhost on Windows to fall back without AI_ADDRCONFIG
when the first lookup fails, so localhost still works without an active
network.
Related issues and pull requests on GitHub:
#5357.
Rejected multipart body parts whose Content-Length header is not a
plain sequence of digits (e.g. +5, -1, 1_0), matching the
strictness of the main request parser per :rfc:9110#section-8.6
-- by :user:dxbjavid.
Related issues and pull requests on GitHub:
#12794.
Fixed GunicornWebWorker endlessly reloading when app fails during startup -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#12879.
Fixed some inconsistent case sensitivity on request methods -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#12931.
Fixed IndexError: string index out of range in parse_content_disposition
when a header parameter has an empty value (e.g. filename=).
-- by :user:JSap0914.
Related issues and pull requests on GitHub:
#12948.
Fixed the sock_read timeout being re-armed on a keep-alive connection after
it had been returned to the pool. An idle pooled connection could be left with a
pending read timeout that fired and poisoned it, so the next request reusing the
connection failed immediately with :exc:aiohttp.SocketTimeoutError. The read
timeout is now only rescheduled when resuming a transport that was actually
paused -- by :user:daragok.
Fixed the client decompressing frames when permessage-deflate was not negotiated -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#12976.
Fixed DigestAuthMiddleware raising an IndexError on empty domain -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#12983.
Fixed :class:~aiohttp.DigestAuthMiddleware corrupting the Digest
challenge when a WWW-Authenticate response offered more than one
authentication scheme -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#12984.
Fixed client not closing cleanly after an exception -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#12985.
Fixed control frames breaking fragmented WebSocket messages -- by :user:arshsmith1.
Related issues and pull requests on GitHub:
#12988.
Fixed parse_content_disposition rejecting otherwise-valid
Content-Disposition header values that contain optional whitespace (OWS)
around the disposition type (e.g. "form-data ; name=\"field\"").
The disposition type is now stripped before token validation, consistent with
how parameter keys are already handled -- by :user:JSap0914.
Related issues and pull requests on GitHub:
#12996.
Fixed an :exc:IndexError in the pure-Python HTTP parser -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#13001.
Fixed parsing optional whitespace in Content-Disposition -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#13002.
Fixed request body not being read on rejected WebSocket upgrades -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#13016.
Fixed :exc:LookupError (and an unguarded :exc:UnicodeDecodeError) escaping
Content-Disposition parsing when a multipart part supplies an extended
parameter with an unknown charset
-- by :user:arshsmith1.
Related issues and pull requests on GitHub:
#13042.
Fixed escape_quotes in the Digest authentication middleware not escaping
backslashes, so a WWW-Authenticate challenge value containing a backslash
could break out of its quoted-string in the generated Authorization header
-- by :user:dxbjavid.
Related issues and pull requests on GitHub:
#13054.
Fixed Python parser not rejecting a bare LF in the request line -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#13136.
Fixed the C HTTP parser folding the fragment into the query string for an
origin-form request target with an empty query (e.g. /path?#frag),
which diverged from the pure-Python parser -- by :user:GiulioDER.
Related issues and pull requests on GitHub:
#13171.
Fixed the C parser reporting newer HTTP methods such as QUERY as <unknown>;
the method table is now derived from the vendored llhttp instead of a hand-maintained count
-- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#13174.
Upgraded llhttp to v9.4.2 -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#12956.
Added admin documentation on incident response and on running reproducer code
safely, covering security vulnerability handling and supply-chain, account, and
CI/infrastructure compromise -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#12914.
Fixed a race condition in class:~aiohttp.TCPConnector where closing the connector while a DNS resolution was in-flight could raise exc:AttributeError
Fixed a race condition in ~aiohttp.TCPConnector where closing the connector while a DNS resolution was in-flight could raise AttributeError instead of ~aiohttp.ClientConnectionError -- by goingforstudying-ctrl.
Related issues and pull requests on GitHub: #12497.
Fixed CancelledError not closing a connection -- by aiolibsbot.
Related issues and pull requests on GitHub: #12795.
Tightened up some websocket parser checks -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #12817.
Fixed ~aiohttp.CookieJar dropping the host-only flag of cookies when persisted with ~aiohttp.CookieJar.save and reloaded with ~aiohttp.CookieJar.load, so a cookie set without a Domain attribute is again scoped to the exact host that set it after a reload; the absolute expiration deadline is now persisted as well, so a reloaded cookie keeps its original lifetime instead of being rescheduled from the load time. ~aiohttp.CookieJar.load now replaces the jar contents rather than merging onto prior state, and loaded cookies pass through the same acceptance rules as ~aiohttp.CookieJar.update_cookies, so a cookie for an IP-address host is dropped when loaded into a jar created without unsafe=True -- by bdraco.
Related issues and pull requests on GitHub: #12824.
Scoped ~aiohttp.DigestAuthMiddleware credentials to the origin of the first request it handles, so a redirect to a different origin no longer triggers a digest response computed from the configured credentials; a challenge from another origin is only answered when that origin falls within a protection space advertised by the anchor origin through the RFC 7616 domain directive -- by bdraco.
Related issues and pull requests on GitHub: #12825.
Fixed the C HTTP parser not enforcing max_line_size on a request target or response reason phrase that is split across multiple reads; each fragment was checked on its own, so an accumulated line could exceed the limit without raising LineTooLong. The accumulated length is now checked, matching the pure-Python parser -- by bdraco.
Related issues and pull requests on GitHub: #12826.
Changed ~aiohttp.TCPConnector to reject legacy non-canonical numeric IPv4 host forms such as 2130706433, 017700000001 and 127.1 with ~aiohttp.InvalidUrlClientError; only canonical dotted-quad IPv4 literals are now treated as IP address literals, while every other host is sent through the configured resolver -- by bdraco.
Related issues and pull requests on GitHub: #12827.
Fixed ~aiohttp.StreamReader.readany and ~aiohttp.StreamReader.read_nowait joining data fed back into the buffer during the call (when draining below the low water mark resumes reading) into a single unbounded bytes; a call now returns only the chunks that were buffered when it started, keeping the drain of an unread auto-decompressed request body bounded by the read buffer -- by bdraco.
Related issues and pull requests on GitHub: #12828.
Bounded the number of parsed-but-unhandled pipelined HTTP/1 requests buffered per connection on the server; once the queue reaches an internal limit the parser stops emitting and the transport is paused, resuming as the request handler drains the queue, so a client keeping one handler busy can no longer accumulate an unbounded backlog of pipelined requests -- by bdraco.
Related issues and pull requests on GitHub: #12830.
Fixed aiohttp.web.Response.write_eof skipping Payload.close() when the body write was interrupted by an error or cancellation, for example when a client disconnects mid-response; the payload close hook now runs in a finally so a ~aiohttp.payload.Payload body always releases its resources -- by bdraco.
Related issues and pull requests on GitHub: #12831.
Fixed the pure-Python HTTP parser not enforcing max_line_size on a chunk-size line when the whole line arrived in a single read; the limit was only applied to chunk-size metadata split across reads. The complete-line case is now checked too, matching the split-line behavior -- by bdraco.
Related issues and pull requests on GitHub: #12832.
Included the per-request server_hostname override in the ~aiohttp.TCPConnector connection pool key, so a pooled TLS connection is no longer reused for a request that sets server_hostname to a different value -- by bdraco.
Related issues and pull requests on GitHub: #12835.
Fixed a race condition in :py:class:~aiohttp.TCPConnector where closing the connector while a DNS resolution was in-flight could raise :py:exc:AttributeError instead of :py:exc:~aiohttp.ClientConnectionError -- by :user:goingforstudying-ctrl.
Related issues and pull requests on GitHub:
#12497.
Fixed CancelledError not closing a connection -- by :user:aiolibsbot.
Related issues and pull requests on GitHub:
#12795.
Tightened up some websocket parser checks -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#12817.
Fixed :class:~aiohttp.CookieJar dropping the host-only flag of cookies when persisted with :meth:~aiohttp.CookieJar.save and reloaded with :meth:~aiohttp.CookieJar.load, so a cookie set without a Domain attribute is again scoped to the exact host that set it after a reload; the absolute expiration deadline is now persisted as well, so a reloaded cookie keeps its original lifetime instead of being rescheduled from the load time. :meth:~aiohttp.CookieJar.load now replaces the jar contents rather than merging onto prior state, and loaded cookies pass through the same acceptance rules as :meth:~aiohttp.CookieJar.update_cookies, so a cookie for an IP-address host is dropped when loaded into a jar created without unsafe=True -- by :user:bdraco.
Related issues and pull requests on GitHub:
#12824.
Scoped :class:~aiohttp.DigestAuthMiddleware credentials to the origin of the first request it handles, so a redirect to a different origin no longer triggers a digest response computed from the configured credentials; a challenge from another origin is only answered when that origin falls within a protection space advertised by the anchor origin through the RFC 7616 domain directive -- by :user:bdraco.
Related issues and pull requests on GitHub:
#12825.
Fixed the C HTTP parser not enforcing max_line_size on a request target or response reason phrase that is split across multiple reads; each fragment was checked on its own, so an accumulated line could exceed the limit without raising LineTooLong. The accumulated length is now checked, matching the pure-Python parser -- by :user:bdraco.
Related issues and pull requests on GitHub:
#12826.
Changed :class:~aiohttp.TCPConnector to reject legacy non-canonical numeric IPv4 host forms such as 2130706433, 017700000001 and 127.1 with :exc:~aiohttp.InvalidUrlClientError; only canonical dotted-quad IPv4 literals are now treated as IP address literals, while every other host is sent through the configured resolver -- by :user:bdraco.
Related issues and pull requests on GitHub:
#12827.
Fixed :meth:~aiohttp.StreamReader.readany and :meth:~aiohttp.StreamReader.read_nowait joining data fed back into the buffer during the call (when draining below the low water mark resumes reading) into a single unbounded :class:bytes; a call now returns only the chunks that were buffered when it started, keeping the drain of an unread auto-decompressed request body bounded by the read buffer -- by :user:bdraco.
Related issues and pull requests on GitHub:
#12828.
Bounded the number of parsed-but-unhandled pipelined HTTP/1 requests buffered per connection on the server; once the queue reaches an internal limit the parser stops emitting and the transport is paused, resuming as the request handler drains the queue, so a client keeping one handler busy can no longer accumulate an unbounded backlog of pipelined requests -- by :user:bdraco.
Related issues and pull requests on GitHub:
#12830.
Fixed :meth:aiohttp.web.Response.write_eof skipping Payload.close() when the body write was interrupted by an error or cancellation, for example when a client disconnects mid-response; the payload close hook now runs in a finally so a :class:~aiohttp.payload.Payload body always releases its resources -- by :user:bdraco.
Related issues and pull requests on GitHub:
#12831.
Fixed the pure-Python HTTP parser not enforcing max_line_size on a chunk-size line when the whole line arrived in a single read; the limit was only applied to chunk-size metadata split across reads. The complete-line case is now checked too, matching the split-line behavior -- by :user:bdraco.
Related issues and pull requests on GitHub:
#12832.
Included the per-request server_hostname override in the :class:~aiohttp.TCPConnector connection pool key, so a pooled TLS connection is no longer reused for a request that sets server_hostname to a different value -- by :user:bdraco.
Related issues and pull requests on GitHub:
#12835.
The zip bomb security fix in 3.13 stopped highly compressed payloads from being decompressed, regardless of validity. Now aiohttp will decompress such…
We have a new website! https://aio-libs.org Subscribe to the news feed to find out more about what we're working on in future.
Added RequestKey and ResponseKey classes, which enable static type checking for request & response context storages in the same way that AppKey does for Application -- by gsoldatov.
Related issues and pull requests on GitHub: #11766.
Added ~aiohttp.encode_basic_auth for encoding HTTP Basic Authentication credentials. Replaces the now-deprecated ~aiohttp.BasicAuth -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #12499.
Started accepting asynchronous context managers for cleanup contexts. Legacy single-yield asynchronous generator cleanup contexts continue to be supported; async context managers are adapted internally so they are entered at startup and exited during cleanup.
-- by MannXo.
Related issues and pull requests on GitHub: #11681.
Added ~aiohttp.CookieJar.cookies and ~aiohttp.CookieJar.host_only_cookies read-only properties to ~aiohttp.CookieJar exposing the stored cookies with their full attributes -- by Br1an67.
Related issues and pull requests on GitHub: #3951.
Added ~aiohttp.web.TCPSite.port accessor for dynamic port allocations in ~aiohttp.web.TCPSite -- by twhittock-disguise and rodrigobnogueira.
Related issues and pull requests on GitHub: #10665.
Added decode_text parameter to ~aiohttp.ClientSession.ws_connect and ~aiohttp.web.WebSocketResponse to receive WebSocket TEXT messages as raw bytes instead of decoded strings, enabling direct use with high-performance JSON parsers like orjson -- by bdraco.
Related issues and pull requests on GitHub: #11763, #11764.
Large overhaul of parser/decompression code.
The zip bomb security fix in 3.13 stopped highly compressed payloads from being decompressed, regardless of validity. Now aiohttp will decompress such payloads in chunks of 256+ KiB, allowing safe decompression of such payloads.
-- by Dreamsorcerer.
Related issues and pull requests on GitHub: #11966.
Added explicit APIs for bytes-returning JSON serializer: JSONBytesEncoder type, JsonBytesPayload, ~aiohttp.web.json_bytes_response, ~aiohttp.web.WebSocketResponse.send_json_bytes and ~aiohttp.ClientWebSocketResponse.send_json_bytes methods, and json_serialize_bytes parameter for ~aiohttp.ClientSession -- by kevinpark1217.
Related issues and pull requests on GitHub: #11989.
Added ~aiohttp.ClientResponse.output_size and ~aiohttp.ClientResponse.upload_complete -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #12452.
Fixed ZLibDecompressor silently dropping data past the first member when decompressing concatenated gzip/deflate streams. Each subsequent member is now handed to a fresh decompressor, matching the behaviour already implemented for ZSTD multi-frame streams.
-- by Ashutosh-177
Related issues and pull requests on GitHub: #7157.
Improved the parser error message shown when TLS handshake bytes are received on an HTTP port -- by puneetdixit200.
Related issues and pull requests on GitHub: #10142.
Fixed the C parser failing to reject a response with a body when none was expected -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #10587.
Fixed http parser not rejecting HTTP/1.1 requests that do not have valid Host header. -- by Cycloctane.
Related issues and pull requests on GitHub: #10600.
Fixed misleading TLS-in-TLS warning being emitted when sending HTTPS requests through an HTTP proxy. The warning now only fires when the proxy itself uses HTTPS, which is the only case where TLS-in-TLS actually applies -- by wavebyrd.
Related issues and pull requests on GitHub: #10683.
Fixed AssertionError when the transport is None during WebSocket preparation or file response sending (e.g. when a client disconnects immediately after connecting). A ConnectionResetError is now raised instead -- by agners.
Related issues and pull requests on GitHub: #11761.
Fixed ad-hoc cookies passed to individual requests not being sent when the session's cookie jar has unsafe=True and the target URL uses an IP address, by copying the unsafe setting from the session's cookie jar to the temporary cookie jar -- by Krishnachaitanyakc.
Related issues and pull requests on GitHub: #12011.
Reset the WebSocket heartbeat timer on inbound data to avoid false ping/pong timeouts while receiving large frames -- by hoffmang9.
Related issues and pull requests on GitHub: #12030.
Switched ~aiohttp.CookieJar.save to use JSON format and ~aiohttp.CookieJar.load to try JSON first with a fallback to a restricted pickle unpickler -- by YuvalElbar6.
Related issues and pull requests on GitHub: #12091.
Fixed redirects with consumed non-rewindable request bodies to raise aiohttp.ClientPayloadError instead of silently sending an empty body.
Related issues and pull requests on GitHub: #12195.
Fixed zstd decompression failing with ClientPayloadError when the server sends a response as multiple zstd frames -- by josu-moreno.
Related issues and pull requests on GitHub: #12234.
Fixed spurious Future exception was never retrieved warning on disconnect during back-pressure -- by availov.
Related issues and pull requests on GitHub: #12281.
Cookiejar.save() now uses 0x600 permissions to better protect them from being read by other users -- by digiscrypt.
Related issues and pull requests on GitHub: #12312.
Fixed a crash (~http.cookies.CookieError) in the cookie parser when receiving cookies containing ASCII control characters on CPython builds with the 2026-3644 patch. The parser now gracefully skips cookies whose value contains control characters instead of letting the exception propagate -- by rodrigobnogueira.
Related issues and pull requests on GitHub: #12395.
Fixed digest authentication failing for requests whose path or query string contains percent-encoded reserved characters; the digest signature now uses the encoded request-target that is sent on the wire instead of the decoded form -- by bdraco.
Related issues and pull requests on GitHub: #12436.
Fixed aiohttp.web.run_app losing inner traceback frames when an exception is raised during application startup (e.g. inside cleanup_ctx or on_startup). Regression since 3.10.6.
Related issues and pull requests on GitHub: #12493.
Fixed per-request cookies not being dropped on cross-origin redirects -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #12550.
Fixed invalid bytes being allowed in multipart/payload headers -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #12719.
Fixed ~aiohttp.FormData.add_field accepting invalid bytes in name and filename -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #12721.
Fixed websocket upgrade occurring when header contained a value like notupgrade -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #12723.
Deprecated ~aiohttp.BasicAuth and the auth / proxy_auth parameters. They will be removed in aiohttp 4.0. Use the new ~aiohttp.encode_basic_auth helper together with headers={"Authorization": ...} (or proxy_headers={"Proxy-Authorization": ...} for proxies) instead. Note that encode_basic_auth() defaults to utf-8, not latin1 -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #12499.
Added deprecation warning to aiohttp.pytest_plugin, please switch to pytest-aiohttp -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #10785.
Stopped calling socket.getfqdn as the fallback for aiohttp.web.BaseRequest.host. socket.getfqdn performs blocking reverse DNS resolution on the event loop thread and can stall a worker for many seconds when the system resolver is slow, and could be triggered remotely by an HTTP/1.0 request that omits the Host header. The fallback when no Host header is present is now the local socket address the request arrived on (transport sockname), or an empty string if no transport information is available. Code that relied on the FQDN being returned must now read it from socket.getfqdn directly, off the event loop -- by bdraco.
Related issues and pull requests on GitHub: #9308, #12597.
Dropped support for Python 3.9 -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #11601.
Tightened outbound header serialization to reject all ASCII control characters forbidden by 9110#section-5.5 and 9112#section-4 (0x00-0x08, 0x0A-0x1F, 0x7F) in status lines, header field-names, and field-values. Previously only CR, LF and NUL were rejected. HTAB (0x09) remains permitted in field values. Applications that placed bare control characters in outbound headers will now raise ValueError instead of emitting non-RFC-compliant bytes -- by rodrigobnogueira.
Related issues and pull requests on GitHub: #12689.
Replaced the deprecated ujson library with orjson in the client quickstart documentation. ujson has been put into maintenance-only mode; orjson is the recommended alternative. -- by indoor47
Related issues and pull requests on GitHub: #10795.
Added the threat_model to the Sphinx documentation -- by omkar-334.
Related issues and pull requests on GitHub: #12549.
Removed archived and deprecated repositories from third party list -- by Polandia94.
Related issues and pull requests on GitHub: #12726.
Added aiointercept to list of third-party libraries -- by Polandia94.
Related issues and pull requests on GitHub: #12727.
Added wheels for Android and iOS platforms -- by timrid.
Related issues and pull requests on GitHub: #11750.
Parallelized the Cython extension compilation by defaulting build_ext.parallel to os.cpu_count(), so each module's gcc invocation now runs concurrently instead of one at a time -- by bdraco.
Related issues and pull requests on GitHub: #12576.
Submitted vendored llhttp to Github's SBOM -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #12678.
Updated llhttp to v9.4.1 -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #12681.
The coverage tool is now configured using the new native auto-discovered .coveragerc.toml file -- by webknjaz.
It is also set up to use the ctrace core that works around the performance issues in the sysmon tracer which is default under Python 3.14.
Related issues and pull requests on GitHub: #11826.
Fixed and reworked autobahn tests -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #12173.
Added a CI job to measure Cython coverage -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #12349.
Disabled coverage and xdist by default to ease local development -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #12364.
Avoid installation of backports.zstd on Python 3.14 in linting dependency set -- by seifertm.
Related issues and pull requests on GitHub: #12406.
Added --durations=30 to the benchmark CI run so the slowest tests are reported when the job hits its timeout -- by aiolibsbot.
Related issues and pull requests on GitHub: #12562.
Fixed two flakey test_middleware_uses_session_avoids_recursion_with_* tests that hard coded localhost in the inner middleware request; they now target the bound server URL so happy eyeballs cannot pick an unbound address on Windows runners -- by bdraco.
Related issues and pull requests on GitHub: #12571.
Restricted the isal test dependency to CPython, since isal 1.8.0 stopped publishing PyPy wheels and the source build requires nasm, which is not available on the CI runners. The parametrize_zlib_backend fixture already calls pytest.importorskip, so PyPy continues to exercise the zlib and zlib_ng backends with no further changes -- by bdraco.
Related issues and pull requests on GitHub: #12589.
Fixed a flakey test_tcp_connector_fingerprint_ok by aborting the SSL shutdown on the test's TCP connector before returning. The graceful TLS close was occasionally outliving the test event loop on one of the CI jobs, and the teardown gc.collect() then surfaced the still-open transport as a PytestUnraisableExceptionWarning -- by bdraco.
Related issues and pull requests on GitHub: #12592.
Switched the cibuildwheel build frontend to build[uv] so that uv provisions every build-isolation virtual environment in the wheel matrix, replacing the per-ABI pip resolve with a roughly sub-second uv resolve -- by bdraco.
Related issues and pull requests on GitHub: #12595.
Fixed flaky test_handler_returns_not_response and test_handler_returns_none by routing loop.set_debug(True) through a new loop_debug_mode fixture that disables debug mode before the aiohttp_client fixture finalizes. Leaving debug on through teardown let PyPy 3.11's asyncio slow-callback logger walk into Task.__repr__ during connector close, surfacing a spurious RuntimeWarning: coroutine was never awaited -- by bdraco.
Related issues and pull requests on GitHub: #12603.
Reduced runtime of several of the slowest unit tests (decompress size-limit payloads from 64 MiB to 2 MiB, test_chunk_splits_after_pause chunk count from 50000 to 20000, and test_set_cookies_max_age sleep from 2 seconds to 1.1 seconds) without changing what they exercise -- by bdraco.
Related issues and pull requests on GitHub: #12606.
Added a default 120-second per-test timeout via pytest-timeout so a hung test surfaces by name in CI output instead of getting hidden behind the job-level timeout added in 12619. The autobahn and benchmark jobs opt out with --timeout=0 -- by bdraco.
Related issues and pull requests on GitHub: #12624.
Switched the CI test and autobahn jobs from actions/setup-python to astral-sh/setup-uv for installing interpreters, cutting the Setup Python step from 40-58s to a few seconds on macos-latest and windows-latest runners for variants not in the hosted tool-cache (notably the free-threaded 3.14t) -- by bdraco.
Related issues and pull requests on GitHub: #12629.
Made the pip command used by the Makefile configurable via a PIP variable; downstream consumers can now run, for example, make .develop PIP="uv pip" to install via uv without us maintaining a parallel target -- by bdraco.
Related issues and pull requests on GitHub: #12641.
Allowed re-running the deploy job in .github/workflows/ci-cd.yml after a partial release failure: the Make Release step now skips when the GitHub Release already exists, and the PyPI publish step uses skip-existing so dists that were already uploaded on a prior attempt do not break the retry -- by bdraco.
Related issues and pull requests on GitHub: #12651.
Switched the armv7l wheel builds onto GitHub's hosted ARM runners. The 32-bit ARM build still runs under QEMU, but the host is now aarch64 rather than x86_64, so the emulation overhead drops sharply -- by bdraco.
Related issues and pull requests on GitHub: #12655.
Added win_arm64 to the wheels that gets pushed to PyPI -- by AraHaan.
Related issues and pull requests on GitHub: #11937.
Added cdef type declarations and inlined the upgrade check in the HTTP parser -- by bdraco.
Related issues and pull requests on GitHub: #12321.
Changed zlib_executor_size default so compressed payloads are async by default -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #12358.
Added THREAT_MODEL.md detailing our security stance -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #12512.
Reduced payload sizes and request counts in the slowest client and URL dispatcher benchmarks so they no longer dominate CI runtime -- by bdraco.
Related issues and pull requests on GitHub: #12569.
Improved ContentLengthError exception messages to include both expected and received byte counts. This enhancement provides better diagnostics when debugging response body size mismatches -- by bdraco and Dreamsorcerer.
Related issues and pull requests on GitHub: #12753.
We have a new website! https://aio-libs.org
Subscribe to the news feed to find out more about what we're working on in future.
Added RequestKey and ResponseKey classes,
which enable static type checking for request & response
context storages in the same way that AppKey does for Application
-- by :user:gsoldatov.
Related issues and pull requests on GitHub:
#11766.
Added :func:~aiohttp.encode_basic_auth for encoding HTTP Basic
Authentication credentials. Replaces the now-deprecated
:class:~aiohttp.BasicAuth -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#12499.
Started accepting :term:asynchronous context managers <asynchronous context manager> for cleanup contexts.
Legacy single-yield :term:asynchronous generator cleanup contexts continue to be
supported; async context managers are adapted internally so they are
entered at startup and exited during cleanup.
-- by :user:MannXo.
Related issues and pull requests on GitHub:
#11681.
Added :py:attr:~aiohttp.CookieJar.cookies and :py:attr:~aiohttp.CookieJar.host_only_cookies read-only properties to :py:class:~aiohttp.CookieJar exposing the stored cookies with their full attributes -- by :user:Br1an67.
Related issues and pull requests on GitHub:
#3951.
Added :py:attr:~aiohttp.web.TCPSite.port accessor for dynamic port allocations in :class:~aiohttp.web.TCPSite -- by :user:twhittock-disguise and :user:rodrigobnogueira.
Related issues and pull requests on GitHub:
#10665.
Added decode_text parameter to :meth:~aiohttp.ClientSession.ws_connect and :class:~aiohttp.web.WebSocketResponse to receive WebSocket TEXT messages as raw bytes instead of decoded strings, enabling direct use with high-performance JSON parsers like orjson -- by :user:bdraco.
Large overhaul of parser/decompression code.
The zip bomb security fix in 3.13 stopped highly compressed payloads
from being decompressed, regardless of validity. Now aiohttp will
decompress such payloads in chunks of 256+ KiB, allowing safe decompression
of such payloads.
-- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#11966.
Added explicit APIs for bytes-returning JSON serializer:
JSONBytesEncoder type, JsonBytesPayload,
:func:~aiohttp.web.json_bytes_response,
:meth:~aiohttp.web.WebSocketResponse.send_json_bytes and
:meth:~aiohttp.ClientWebSocketResponse.send_json_bytes methods, and
json_serialize_bytes parameter for :class:~aiohttp.ClientSession
-- by :user:kevinpark1217.
Related issues and pull requests on GitHub:
#11989.
Added :attr:~aiohttp.ClientResponse.output_size and
:attr:~aiohttp.ClientResponse.upload_complete -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#12452.
Fixed ZLibDecompressor silently dropping data past the first
member when decompressing concatenated gzip/deflate streams. Each subsequent
member is now handed to a fresh decompressor, matching the behaviour already
implemented for ZSTD multi-frame streams.
-- by :user:Ashutosh-177
Related issues and pull requests on GitHub:
#7157.
Improved the parser error message shown when TLS handshake bytes are received on an HTTP port -- by :user:puneetdixit200.
Related issues and pull requests on GitHub:
#10142.
Fixed the C parser failing to reject a response with a body when none was expected -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#10587.
Fixed http parser not rejecting HTTP/1.1 requests that do not have valid Host header.
-- by :user:Cycloctane.
Related issues and pull requests on GitHub:
#10600.
Fixed misleading TLS-in-TLS warning being emitted when sending HTTPS requests through an HTTP proxy. The warning now only fires when the proxy itself uses HTTPS, which is the only case where TLS-in-TLS actually applies -- by :user:wavebyrd.
Related issues and pull requests on GitHub:
#10683.
Fixed AssertionError when the transport is None during WebSocket
preparation or file response sending (e.g. when a client disconnects
immediately after connecting). A ConnectionResetError is now raised
instead -- by :user:agners.
Related issues and pull requests on GitHub:
#11761.
Fixed ad-hoc cookies passed to individual requests not being sent when the session's cookie jar has unsafe=True and the target URL uses an IP address, by copying the unsafe setting from the session's cookie jar to the temporary cookie jar -- by :user:Krishnachaitanyakc.
Related issues and pull requests on GitHub:
#12011.
Reset the WebSocket heartbeat timer on inbound data to avoid false ping/pong timeouts while receiving large frames
-- by :user:hoffmang9.
Related issues and pull requests on GitHub:
#12030.
Switched :py:meth:~aiohttp.CookieJar.save to use JSON format and
:py:meth:~aiohttp.CookieJar.load to try JSON first with a fallback to
a restricted pickle unpickler -- by :user:YuvalElbar6.
Related issues and pull requests on GitHub:
#12091.
Fixed redirects with consumed non-rewindable request bodies to raise
:class:aiohttp.ClientPayloadError instead of silently sending an empty body.
Related issues and pull requests on GitHub:
#12195.
Fixed zstd decompression failing with ClientPayloadError when the server
sends a response as multiple zstd frames -- by :user:josu-moreno.
Related issues and pull requests on GitHub:
#12234.
Fixed spurious Future exception was never retrieved warning on disconnect during back-pressure -- by :user:availov.
Related issues and pull requests on GitHub:
#12281.
Cookiejar.save() now uses 0x600 permissions to better protect them from being read by other users -- by :user:digiscrypt.
Related issues and pull requests on GitHub:
#12312.
Fixed a crash (:external+python:exc:~http.cookies.CookieError) in the cookie parser when receiving cookies
containing ASCII control characters on CPython builds with the :cve:2026-3644
patch. The parser now gracefully skips cookies whose value contains control
characters instead of letting the exception propagate -- by :user:rodrigobnogueira.
Related issues and pull requests on GitHub:
#12395.
Fixed digest authentication failing for requests whose path or query string contains percent-encoded reserved characters; the digest signature now uses the encoded request-target that is sent on the wire instead of the decoded form -- by :user:bdraco.
Related issues and pull requests on GitHub:
#12436.
Fixed :func:aiohttp.web.run_app losing inner traceback frames when an
exception is raised during application startup (e.g. inside
cleanup_ctx or on_startup). Regression since 3.10.6.
Related issues and pull requests on GitHub:
#12493.
Fixed per-request cookies not being dropped on cross-origin redirects -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#12550.
Fixed invalid bytes being allowed in multipart/payload headers -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#12719.
Fixed :py:meth:~aiohttp.FormData.add_field accepting invalid bytes in name and filename -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#12721.
Fixed websocket upgrade occurring when header contained a value like notupgrade -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#12723.
Deprecated :class:~aiohttp.BasicAuth and the auth / proxy_auth
parameters. They will be removed in aiohttp 4.0. Use the new
:func:~aiohttp.encode_basic_auth helper together with
headers={"Authorization": ...} (or
proxy_headers={"Proxy-Authorization": ...} for proxies) instead.
Note that encode_basic_auth() defaults to utf-8, not latin1
-- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#12499.
Added deprecation warning to aiohttp.pytest_plugin, please switch to pytest-aiohttp -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#10785.
Stopped calling :func:socket.getfqdn as the fallback for
:attr:aiohttp.web.BaseRequest.host. :func:socket.getfqdn
performs blocking reverse DNS resolution on the event loop
thread and can stall a worker for many seconds when the system
resolver is slow, and could be triggered remotely by an HTTP/1.0
request that omits the Host header. The fallback when no
Host header is present is now the local socket address the
request arrived on (transport sockname), or an empty string
if no transport information is available. Code that relied on
the FQDN being returned must now read it from
:func:socket.getfqdn directly, off the event loop
-- by :user:bdraco.
Dropped support for Python 3.9 -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#11601.
Tightened outbound header serialization to reject all ASCII control
characters forbidden by :rfc:9110#section-5.5 and :rfc:9112#section-4
(0x00-0x08, 0x0A-0x1F, 0x7F) in status lines,
header field-names, and field-values. Previously only CR, LF and NUL were
rejected. HTAB (0x09) remains permitted in field values. Applications
that placed bare control characters in outbound headers will now raise
:exc:ValueError instead of emitting non-RFC-compliant bytes -- by :user:rodrigobnogueira.
Related issues and pull requests on GitHub:
#12689.
Replaced the deprecated ujson library with orjson in the
client quickstart documentation. ujson has been put into
maintenance-only mode; orjson is the recommended alternative.
-- by :user:indoor47
Related issues and pull requests on GitHub:
#10795.
Added the :doc:threat_model to the Sphinx documentation -- by :user:omkar-334.
Related issues and pull requests on GitHub:
#12549.
Removed archived and deprecated repositories from third party list -- by :user:Polandia94.
Related issues and pull requests on GitHub:
#12726.
Added aiointercept to list of third-party libraries -- by :user:Polandia94.
Related issues and pull requests on GitHub:
#12727.
Added wheels for Android and iOS platforms -- by :user:timrid.
Related issues and pull requests on GitHub:
#11750.
Parallelized the Cython extension compilation by defaulting
build_ext.parallel to os.cpu_count(), so each module's
gcc invocation now runs concurrently instead of one at a time
-- by :user:bdraco.
Related issues and pull requests on GitHub:
#12576.
Submitted vendored llhttp to Github's SBOM -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#12678.
Updated llhttp to v9.4.1 -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#12681.
The coverage tool is now configured using the new native
auto-discovered :file:.coveragerc.toml file
-- by :user:webknjaz.
It is also set up to use the ctrace core that works
around the performance issues in the sysmon tracer
which is default under Python 3.14.
Related issues and pull requests on GitHub:
#11826.
Fixed and reworked autobahn tests -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#12173.
Added a CI job to measure Cython coverage -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#12349.
Disabled coverage and xdist by default to ease local development -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#12364.
Avoid installation of backports.zstd on Python 3.14 in linting dependency set
-- by :user:seifertm.
Related issues and pull requests on GitHub:
#12406.
Added --durations=30 to the benchmark CI run so the slowest tests are reported when the job hits its timeout -- by :user:aiolibsbot.
Related issues and pull requests on GitHub:
#12562.
Fixed two flakey test_middleware_uses_session_avoids_recursion_with_* tests
that hard coded localhost in the inner middleware request; they now target
the bound server URL so happy eyeballs cannot pick an unbound address on
Windows runners -- by :user:bdraco.
Related issues and pull requests on GitHub:
#12571.
Restricted the isal test dependency to CPython, since
isal 1.8.0 stopped publishing PyPy wheels and the source
build requires nasm, which is not available on the CI
runners. The parametrize_zlib_backend fixture already
calls pytest.importorskip, so PyPy continues to exercise
the zlib and zlib_ng backends with no further
changes -- by :user:bdraco.
Related issues and pull requests on GitHub:
#12589.
Fixed a flakey test_tcp_connector_fingerprint_ok by aborting
the SSL shutdown on the test's TCP connector before returning.
The graceful TLS close was occasionally outliving the test event
loop on one of the CI jobs, and the teardown gc.collect()
then surfaced the still-open transport as a
PytestUnraisableExceptionWarning -- by :user:bdraco.
Related issues and pull requests on GitHub:
#12592.
Switched the cibuildwheel build frontend to build[uv] so
that uv provisions every build-isolation virtual environment
in the wheel matrix, replacing the per-ABI pip resolve with a
roughly sub-second uv resolve
-- by :user:bdraco.
Related issues and pull requests on GitHub:
#12595.
Fixed flaky test_handler_returns_not_response and
test_handler_returns_none by routing loop.set_debug(True)
through a new loop_debug_mode fixture that disables debug
mode before the aiohttp_client fixture finalizes. Leaving
debug on through teardown let PyPy 3.11's asyncio slow-callback
logger walk into Task.__repr__ during connector close,
surfacing a spurious RuntimeWarning: coroutine was never awaited -- by :user:bdraco.
Related issues and pull requests on GitHub:
#12603.
Reduced runtime of several of the slowest unit tests
(decompress size-limit payloads from 64 MiB to 2 MiB,
test_chunk_splits_after_pause chunk count from 50000
to 20000, and test_set_cookies_max_age sleep from 2
seconds to 1.1 seconds) without changing what they
exercise -- by :user:bdraco.
Related issues and pull requests on GitHub:
#12606.
Added a default 120-second per-test timeout via pytest-timeout so a
hung test surfaces by name in CI output instead of getting hidden behind
the job-level timeout added in :pr:12619. The autobahn and
benchmark jobs opt out with --timeout=0 -- by :user:bdraco.
Related issues and pull requests on GitHub:
#12624.
Switched the CI test and autobahn jobs from
actions/setup-python to astral-sh/setup-uv for installing
interpreters, cutting the Setup Python step from 40-58s to a
few seconds on macos-latest and windows-latest runners for
variants not in the hosted tool-cache (notably the free-threaded
3.14t)
-- by :user:bdraco.
Related issues and pull requests on GitHub:
#12629.
Made the pip command used by the :file:Makefile configurable via a
PIP variable; downstream consumers can now run, for example,
make .develop PIP="uv pip" to install via uv without us
maintaining a parallel target
-- by :user:bdraco.
Related issues and pull requests on GitHub:
#12641.
Allowed re-running the deploy job in .github/workflows/ci-cd.yml
after a partial release failure: the Make Release step now skips
when the GitHub Release already exists, and the PyPI publish step uses
skip-existing so dists that were already uploaded on a prior
attempt do not break the retry -- by :user:bdraco.
Related issues and pull requests on GitHub:
#12651.
Switched the armv7l wheel builds onto GitHub's hosted ARM runners. The
32-bit ARM build still runs under QEMU, but the host is now aarch64
rather than x86_64, so the emulation overhead drops sharply
-- by :user:bdraco.
Related issues and pull requests on GitHub:
#12655.
Added win_arm64 to the wheels that gets pushed to PyPI
-- by :user:AraHaan.
Related issues and pull requests on GitHub:
#11937.
Added cdef type declarations and inlined the upgrade check in the HTTP parser
-- by :user:bdraco.
Related issues and pull requests on GitHub:
#12321.
Changed zlib_executor_size default so compressed payloads are async by default -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#12358.
Added THREAT_MODEL.md detailing our security stance -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#12512.
Reduced payload sizes and request counts in the slowest client and URL
dispatcher benchmarks so they no longer dominate CI runtime
-- by :user:bdraco.
Related issues and pull requests on GitHub:
#12569.
Improved ContentLengthError exception messages to include both expected and received byte counts. This enhancement provides better diagnostics when debugging response body size mismatches
-- by :user:bdraco and :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#12753.
Skipped the duplicate singleton header check in lax mode (the default for response parsing). In strict mode (request parsing, or -X dev), all RFC 9110
Skipped the duplicate singleton header check in lax mode (the default for response
parsing). In strict mode (request parsing, or -X dev), all RFC 9110 singletons
are still enforced -- by :user:bdraco.
Related issues and pull requests on GitHub: #12302.
The method was inadvertently changed to async in 3.13.3 as part of the decompression bomb security fix. A new meth:~aiohttp.BodyPartReader.decode_iter…
Added max_headers parameter to limit the number of headers that should be read from a response -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #11955.
Added a dns_cache_max_size parameter to TCPConnector to limit the size of the cache -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #12106.
Fixed server hanging indefinitely when chunked transfer encoding chunk-size does not match actual data length. The server now raises TransferEncodingError instead of waiting forever for data that will never arrive -- by Fridayai700.
Related issues and pull requests on GitHub: #10596.
Fixed access log timestamps ignoring daylight saving time (DST) changes. The previous implementation used time.timezone which is a constant and does not reflect DST transitions -- by nightcityblade.
Related issues and pull requests on GitHub: #11283.
Fixed RuntimeError: An event loop is running error when using aiohttp.GunicornWebWorker or aiohttp.GunicornUVLoopWebWorker on Python >=3.14. -- by Tasssadar.
Related issues and pull requests on GitHub: #11701.
Fixed ValueError when creating a TLS connection with ClientTimeout(total=0) by converting 0 to None before passing to ssl_handshake_timeout in asyncio.loop.start_tls -- by veeceey.
Related issues and pull requests on GitHub: #11859.
Restored ~aiohttp.BodyPartReader.decode as a synchronous method for backward compatibility. The method was inadvertently changed to async in 3.13.3 as part of the decompression bomb security fix. A new ~aiohttp.BodyPartReader.decode_iter method is now available for non-blocking decompression of large payloads using an async generator. Internal aiohttp code uses the async variant to maintain security protections.
Changed multipart processing chunk sizes from 64 KiB to 256KiB, to better match aiohttp internals -- by bdraco and Dreamsorcerer.
Related issues and pull requests on GitHub: #11898.
Fixed false-positive DeprecationWarning for passing enable_cleanup_closed=True to ~aiohttp.TCPConnector specifically on Python 3.12.7. -- by Robsdedude.
Related issues and pull requests on GitHub: #11972.
Fixed _sendfile_fallback over-reading beyond requested count -- by bysiber.
Related issues and pull requests on GitHub: #12096.
Fixed digest auth dropping challenge fields with empty string values -- by bysiber.
Related issues and pull requests on GitHub: #12097.
ClientConnectorCertificateError.os_error no longer raises AttributeError -- by themylogin.
Related issues and pull requests on GitHub: #12136.
Adjusted pure-Python request header value validation to align with RFC 9110 control-character handling, while preserving lax response parser behavior, and added regression tests for Host/header control-character cases. -- by rodrigobnogueira.
Related issues and pull requests on GitHub: #12231.
Rejected duplicate singleton headers (Host, Content-Type, Content-Length, etc.) in the C extension HTTP parser to match the pure Python parser behaviour, preventing potential host-based access control bypasses via parser differentials -- by rodrigobnogueira.
Related issues and pull requests on GitHub: #12240.
Aligned the pure-Python HTTP request parser with the C parser by splitting comma-separated and repeated Connection header values for keep-alive, close, and upgrade handling -- by rodrigobnogueira.
Related issues and pull requests on GitHub: #12249.
Documented asyncio.TimeoutError for WebSocketResponse.receive() and related methods -- by veeceey.
Related issues and pull requests on GitHub: #12042.
Upgraded llhttp to 3.9.1 -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #12069.
The benchmark CI job now runs only in the upstream repository -- by Cycloctane.
It used to always fail in forks, which this change fixed.
Related issues and pull requests on GitHub: #11737.
Fixed flaky performance tests by using appropriate fixed thresholds that account for CI variability -- by rodrigobnogueira.
Related issues and pull requests on GitHub: #11992.
Fixed test_invalid_idna to work with idna 3.11 by using an invalid character (\u0080) that is rejected by yarl during URL construction -- by rodrigobnogueira.
Related issues and pull requests on GitHub: #12027.
Fixed race condition in test_data_file on Python 3.14 free-threaded builds -- by rodrigobnogueira.
Related issues and pull requests on GitHub: #12170.
Added max_headers parameter to limit the number of headers that should be read from a response -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#11955.
Added a dns_cache_max_size parameter to TCPConnector to limit the size of the cache -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#12106.
Fixed server hanging indefinitely when chunked transfer encoding chunk-size
does not match actual data length. The server now raises
TransferEncodingError instead of waiting forever for data that will
never arrive -- by :user:Fridayai700.
Related issues and pull requests on GitHub:
#10596.
Fixed access log timestamps ignoring daylight saving time (DST) changes. The
previous implementation used :py:data:time.timezone which is a constant and
does not reflect DST transitions -- by :user:nightcityblade.
Related issues and pull requests on GitHub:
#11283.
Fixed RuntimeError: An event loop is running error when using aiohttp.GunicornWebWorker
or aiohttp.GunicornUVLoopWebWorker on Python >=3.14.
-- by :user:Tasssadar.
Related issues and pull requests on GitHub:
#11701.
Fixed :exc:ValueError when creating a TLS connection with ClientTimeout(total=0) by converting 0 to None before passing to ssl_handshake_timeout in :py:meth:asyncio.loop.start_tls -- by :user:veeceey.
Related issues and pull requests on GitHub:
#11859.
Restored :py:meth:~aiohttp.BodyPartReader.decode as a synchronous method
for backward compatibility. The method was inadvertently changed to async
in 3.13.3 as part of the decompression bomb security fix. A new
:py:meth:~aiohttp.BodyPartReader.decode_iter method is now available
for non-blocking decompression of large payloads using an async generator.
Internal aiohttp code uses the async variant to maintain security protections.
Changed multipart processing chunk sizes from 64 KiB to 256KiB, to better
match aiohttp internals
-- by :user:bdraco and :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#11898.
Fixed false-positive :py:class:DeprecationWarning for passing enable_cleanup_closed=True to :py:class:~aiohttp.TCPConnector specifically on Python 3.12.7.
-- by :user:Robsdedude.
Related issues and pull requests on GitHub:
#11972.
Fixed _sendfile_fallback over-reading beyond requested count -- by :user:bysiber.
Related issues and pull requests on GitHub:
#12096.
Fixed digest auth dropping challenge fields with empty string values -- by :user:bysiber.
Related issues and pull requests on GitHub:
#12097.
ClientConnectorCertificateError.os_error no longer raises :exc:AttributeError
-- by :user:themylogin.
Related issues and pull requests on GitHub:
#12136.
Adjusted pure-Python request header value validation to align with RFC 9110 control-character handling, while preserving lax response parser behavior, and added regression tests for Host/header control-character cases.
-- by :user:rodrigobnogueira.
Related issues and pull requests on GitHub:
#12231.
Rejected duplicate singleton headers (Host, Content-Type,
Content-Length, etc.) in the C extension HTTP parser to match
the pure Python parser behaviour, preventing potential host-based
access control bypasses via parser differentials
-- by :user:rodrigobnogueira.
Related issues and pull requests on GitHub:
#12240.
Aligned the pure-Python HTTP request parser with the C parser by splitting
comma-separated and repeated Connection header values for keep-alive,
close, and upgrade handling -- by :user:rodrigobnogueira.
Related issues and pull requests on GitHub:
#12249.
Documented :exc:asyncio.TimeoutError for WebSocketResponse.receive()
and related methods -- by :user:veeceey.
Related issues and pull requests on GitHub:
#12042.
Upgraded llhttp to 3.9.1 -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#12069.
The benchmark CI job now runs only in the upstream repository -- by :user:Cycloctane.
It used to always fail in forks, which this change fixed.
Related issues and pull requests on GitHub:
#11737.
Fixed flaky performance tests by using appropriate fixed thresholds that account for CI variability -- by :user:rodrigobnogueira.
Related issues and pull requests on GitHub:
#11992.
Fixed test_invalid_idna to work with idna 3.11 by using an invalid character (\u0080) that is rejected by yarl during URL construction -- by :user:rodrigobnogueira.
Related issues and pull requests on GitHub:
#12027.
Fixed race condition in test_data_file on Python 3.14 free-threaded builds -- by :user:rodrigobnogueira.
Related issues and pull requests on GitHub:
#12170.
This release contains fixes for several vulnerabilities. It is advised to upgrade as soon as possible.
This release contains fixes for several vulnerabilities. It is advised to upgrade as soon as possible.
Fixed proxy authorization headers not being passed when reusing a connection, which caused 407 (Proxy authentication required) errors
-- by :user:GLeurquin.
Related issues and pull requests on GitHub: #2596.
Fixed multipart reading failing when encountering an empty body part -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub: #11857.
Fixed a case where the parser wasn't raising an exception for a websocket continuation frame when there was no initial frame in context.
Related issues and pull requests on GitHub: #11862.
Brotli and brotlicffi minimum version is now 1.2.
Decompression now has a default maximum output size of 32MiB per decompress call -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub: #11898.
Moved dependency metadata from :file:setup.cfg to :file:pyproject.toml per :pep:621
-- by :user:cdce8p.
Related issues and pull requests on GitHub: #11643.
Removed unused update-pre-commit github action workflow -- by :user:Cycloctane.
Related issues and pull requests on GitHub: #11689.
Optimized web server performance when access logging is disabled by reducing time syscalls -- by :user:bdraco.
Related issues and pull requests on GitHub: #10713.
Added regression test for cached logging status -- by :user:meehand.
Related issues and pull requests on GitHub: #11778.
This release contains fixes for several vulnerabilities. It is advised to
upgrade as soon as possible.
Fixed proxy authorization headers not being passed when reusing a connection, which caused 407 (Proxy authentication required) errors
-- by :user:GLeurquin.
Related issues and pull requests on GitHub:
#2596.
Fixed multipart reading failing when encountering an empty body part -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#11857.
Fixed a case where the parser wasn't raising an exception for a websocket continuation frame when there was no initial frame in context.
Related issues and pull requests on GitHub:
#11862.
Brotli and brotlicffi minimum version is now 1.2.
Decompression now has a default maximum output size of 32MiB per decompress call -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#11898.
Moved dependency metadata from :file:setup.cfg to :file:pyproject.toml per :pep:621
-- by :user:cdce8p.
Related issues and pull requests on GitHub:
#11643.
Removed unused update-pre-commit github action workflow -- by :user:Cycloctane.
Related issues and pull requests on GitHub:
#11689.
Optimized web server performance when access logging is disabled by reducing time syscalls -- by :user:bdraco.
Related issues and pull requests on GitHub:
#10713.
Added regression test for cached logging status -- by :user:meehand.
Related issues and pull requests on GitHub:
#11778.
Fixed cookie parser to continue parsing subsequent cookies when encountering a malformed cookie that fails regex validation, such as Google's g_state
Fixed cookie parser to continue parsing subsequent cookies when encountering a malformed cookie that fails regex validation, such as Google's g_state cookie with unescaped quotes -- by :user:bdraco.
Related issues and pull requests on GitHub: #11632.
Fixed loading netrc credentials from the default :file:~/.netrc (:file:~/_netrc on Windows) location when the :envvar:NETRC environment variable is not set -- by :user:bdraco.
Related issues and pull requests on GitHub: #11713, #11714.
Fixed WebSocket compressed sends to be cancellation safe. Tasks are now shielded during compression to prevent compressor state corruption. This ensures that the stateful compressor remains consistent even when send operations are cancelled -- by :user:bdraco.
Related issues and pull requests on GitHub: #11725.
Fixed cookie parser to continue parsing subsequent cookies when encountering a malformed cookie that fails regex validation, such as Google's g_state cookie with unescaped quotes -- by :user:bdraco.
Related issues and pull requests on GitHub:
#11632.
Fixed loading netrc credentials from the default :file:~/.netrc (:file:~/_netrc on Windows) location when the :envvar:NETRC environment variable is not set -- by :user:bdraco.
Fixed WebSocket compressed sends to be cancellation safe. Tasks are now shielded during compression to prevent compressor state corruption. This ensures that the stateful compressor remains consistent even when send operations are cancelled -- by :user:bdraco.
Related issues and pull requests on GitHub:
#11725.
Make configuration options in AppRunner also available in run_app() -- by Cycloctane.
Make configuration options in AppRunner also available in run_app()
-- by :user:Cycloctane.
Related issues and pull requests on GitHub: #11633.
Switched to backports.zstd for Python <3.14 and fixed zstd decompression for chunked zstd streams -- by :user:ZhaoMJ.
Note: Users who installed zstandard for support on Python <3.14 will now need to install
backports.zstd instead (installing aiohttp[speedups] will do this automatically).
Related issues and pull requests on GitHub: #11623.
Updated Content-Type header parsing to return application/octet-stream when header contains invalid syntax.
See :rfc:9110#section-8.3-5.
-- by :user:sgaist.
Related issues and pull requests on GitHub: #10889.
Fixed Python 3.14 support when built without zstd support -- by :user:JacobHenner.
Related issues and pull requests on GitHub: #11603.
Fixed blocking I/O in the event loop when using netrc authentication by moving netrc file lookup to an executor -- by :user:bdraco.
Related issues and pull requests on GitHub: #11634.
Fixed routing to a sub-application added via .add_domain() not working
if the same path exists on the parent app. -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub: #11673.
Moved core packaging metadata from :file:setup.cfg to :file:pyproject.toml per :pep:621
-- by :user:cdce8p.
Related issues and pull requests on GitHub: #9951.
Make configuration options in AppRunner also available in run_app()
-- by :user:Cycloctane.
Related issues and pull requests on GitHub:
#11633.
Switched to backports.zstd for Python <3.14 and fixed zstd decompression for chunked zstd streams -- by :user:ZhaoMJ.
Note: Users who installed zstandard for support on Python <3.14 will now need to install
backports.zstd instead (installing aiohttp[speedups] will do this automatically).
Related issues and pull requests on GitHub:
#11623.
Updated Content-Type header parsing to return application/octet-stream when header contains invalid syntax.
See :rfc:9110#section-8.3-5.
-- by :user:sgaist.
Related issues and pull requests on GitHub:
#10889.
Fixed Python 3.14 support when built without zstd support -- by :user:JacobHenner.
Related issues and pull requests on GitHub:
#11603.
Fixed blocking I/O in the event loop when using netrc authentication by moving netrc file lookup to an executor -- by :user:bdraco.
Related issues and pull requests on GitHub:
#11634.
Fixed routing to a sub-application added via .add_domain() not working
if the same path exists on the parent app. -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub:
#11673.
Moved core packaging metadata from :file:setup.cfg to :file:pyproject.toml per :pep:621
-- by :user:cdce8p.
Related issues and pull requests on GitHub:
#9951.
Fixed pytest plugin to not use deprecated mod:asyncio policy APIs.
Added support for Python 3.14.
Related issues and pull requests on GitHub: #10851, #10872.
Added support for free-threading in Python 3.14+ -- by kumaraditya303.
Related issues and pull requests on GitHub: #11466, #11464.
Added support for Zstandard (aka Zstd) compression -- by KGuillaume-chaps.
Related issues and pull requests on GitHub: #11161.
Added StreamReader.total_raw_bytes to check the number of bytes downloaded -- by robpats.
Related issues and pull requests on GitHub: #11483.
Fixed pytest plugin to not use deprecated asyncio policy APIs.
Related issues and pull requests on GitHub: #10851.
Updated Content-Disposition header parsing to handle trailing semicolons and empty parts -- by PLPeeters.
Related issues and pull requests on GitHub: #11243.
Fixed saved CookieJar failing to be loaded if cookies have partitioned flag when http.cookie does not have partitioned cookies supports. -- by Cycloctane.
Related issues and pull requests on GitHub: #11523.
Added Wireup to third-party libraries -- by maldoinc.
Related issues and pull requests on GitHub: #11233.
The blockbuster test dependency is now optional; the corresponding test fixture is disabled when it is unavailable -- by musicinybrain.
Related issues and pull requests on GitHub: #11363.
Added riscv64 build to releases -- by eshattow.
Related issues and pull requests on GitHub: #11425.
Fixed test_send_compress_text failing when alternative zlib implementation is used. (zlib-ng in python 3.14 windows build) -- by Cycloctane.
Related issues and pull requests on GitHub: #11546.
Added support for Python 3.14.
Added support for free-threading in Python 3.14+ -- by :user:kumaraditya303.
Added support for Zstandard (aka Zstd) compression
-- by :user:KGuillaume-chaps.
Related issues and pull requests on GitHub:
#11161.
Added StreamReader.total_raw_bytes to check the number of bytes downloaded
-- by :user:robpats.
Related issues and pull requests on GitHub:
#11483.
Fixed pytest plugin to not use deprecated :py:mod:asyncio policy APIs.
Related issues and pull requests on GitHub:
#10851.
Updated Content-Disposition header parsing to handle trailing semicolons and empty parts
-- by :user:PLPeeters.
Related issues and pull requests on GitHub:
#11243.
Fixed saved CookieJar failing to be loaded if cookies have partitioned flag when
http.cookie does not have partitioned cookies supports. -- by :user:Cycloctane.
Related issues and pull requests on GitHub:
#11523.
Added Wireup to third-party libraries -- by :user:maldoinc.
Related issues and pull requests on GitHub:
#11233.
The blockbuster test dependency is now optional; the corresponding test fixture is disabled when it is unavailable
-- by :user:musicinybrain.
Related issues and pull requests on GitHub:
#11363.
Added riscv64 build to releases -- by :user:eshattow.
Related issues and pull requests on GitHub:
#11425.
Fixed test_send_compress_text failing when alternative zlib implementation
is used. (zlib-ng in python 3.14 windows build) -- by :user:Cycloctane.
Related issues and pull requests on GitHub:
#11546.
Fixed ~aiohttp.DigestAuthMiddleware to preserve the algorithm case from the server's challenge in the authorization response. This improves compatibil
Fixed ~aiohttp.DigestAuthMiddleware to preserve the algorithm case from the server's challenge in the authorization response. This improves compatibility with servers that perform case-sensitive algorithm matching (e.g., servers expecting algorithm=MD5-sess instead of algorithm=MD5-SESS) -- by bdraco.
Related issues and pull requests on GitHub: #11352.
Remove outdated contents of aiohttp-devtools and aiohttp-swagger from Web_advanced docs. -- by Cycloctane
Related issues and pull requests on GitHub: #11347.
Started including the llhttp LICENSE file in wheels by adding vendor/llhttp/LICENSE to license-files in setup.cfg -- by threexc.
Related issues and pull requests on GitHub: #11226.
Updated a regex in test_aiohttp_request_coroutine for Python 3.14.
Related issues and pull requests on GitHub: #11271.
Fixed file uploads failing with HTTP 422 errors when encountering 307/308 redirects, and 301/302 redirects for non-POST methods, by preserving the req
Fixed file uploads failing with HTTP 422 errors when encountering 307/308 redirects, and 301/302 redirects for non-POST methods, by preserving the request body when appropriate per 9110#section-15.4.3-3.1 -- by bdraco.
Related issues and pull requests on GitHub: #11270.
Fixed ClientSession.close() hanging indefinitely when using HTTPS requests through HTTP proxies -- by bdraco.
Related issues and pull requests on GitHub: #11273.
Bumped minimum version of aiosignal to 1.4+ to resolve typing issues -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #11280.
Added initial trailer parsing logic to Python HTTP parser -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #11269.
Clarified exceptions raised by WebSocketResponse.send_frame et al. -- by DoctorJohn.
Related issues and pull requests on GitHub: #11234.
Fixed auto-created class:~aiohttp.TCPConnector not using the session's event loop when class:~aiohttp.ClientSession is created without an explicit con
Fixed auto-created ~aiohttp.TCPConnector not using the session's event loop when ~aiohttp.ClientSession is created without an explicit connector -- by bdraco.
Related issues and pull requests on GitHub: #11147.
Fixed cookie unquoting to properly handle octal escape sequences in cookie values (e.g., \012 for newline) by vendoring the correct _unquote implement
Fixed cookie unquoting to properly handle octal escape sequences in cookie values (e.g., \012 for newline) by vendoring the correct _unquote implementation from Python's http.cookies module -- by :user:bdraco.
Related issues and pull requests on GitHub: #11173.
Fixed Cookie header parsing to treat attribute names as regular cookies per :rfc:6265#section-5.4 -- by :user:bdraco.
Related issues and pull requests on GitHub: #11178.
The ssl_shutdown_timeout parameter is now deprecated and will be removed in aiohttp 4.0 as there is no clear use case for changing the default.
Improved SSL connection handling by changing the default ssl_shutdown_timeout
from 0.1 to 0 seconds. SSL connections now use Python's default graceful
shutdown during normal operation but are aborted immediately when the connector
is closed, providing optimal behavior for both cases. Also added support for
ssl_shutdown_timeout=0 on all Python versions. Previously, this value was
rejected on Python 3.11+ and ignored on earlier versions. Non-zero values on
Python < 3.11 now trigger a RuntimeWarning -- by :user:bdraco.
The ssl_shutdown_timeout parameter is now deprecated and will be removed in
aiohttp 4.0 as there is no clear use case for changing the default.
Related issues and pull requests on GitHub: #11148.
Improved SSL connection handling by changing the default ssl_shutdown_timeout
from 0.1 to 0 seconds. SSL connections now use Python's default graceful
shutdown during normal operation but are aborted immediately when the connector
is closed, providing optimal behavior for both cases. Also added support for
ssl_shutdown_timeout=0 on all Python versions. Previously, this value was
rejected on Python 3.11+ and ignored on earlier versions. Non-zero values on
Python < 3.11 now trigger a RuntimeWarning -- by :user:bdraco.
The ssl_shutdown_timeout parameter is now deprecated and will be removed in
aiohttp 4.0 as there is no clear use case for changing the default.
Related issues and pull requests on GitHub: #11148.
Fixed leak of aiodns.DNSResolver when class:~aiohttp.TCPConnector is closed and no resolver was passed when creating the connector -- by Tasssadar.
Fixed leak of aiodns.DNSResolver when ~aiohttp.TCPConnector is closed and no resolver was passed when creating the connector -- by Tasssadar.
This was a regression introduced in version 3.12.0 (10897).
Related issues and pull requests on GitHub: #11150.
Fixed IOBasePayload and TextIOPayload reading entire files into memory when streaming large files -- by bdraco.
Fixed IOBasePayload and TextIOPayload reading entire files into memory when streaming large files -- by :user:bdraco.
When using file-like objects with the aiohttp client, the entire file would be read into memory if the file size was provided in the Content-Length header. This could cause out-of-memory errors when uploading large files. The payload classes now correctly read data in chunks of READ_SIZE (64KB) regardless of the total content length.
Related issues and pull requests on GitHub: #11138.
Added preemptive digest authentication to ~aiohttp.DigestAuthMiddleware -- by bdraco.
Added preemptive digest authentication to ~aiohttp.DigestAuthMiddleware -- by bdraco.
The middleware now reuses authentication credentials for subsequent requests to the same protection space, improving efficiency by avoiding extra authentication round trips. This behavior matches how web browsers handle digest authentication and follows 7616#section-3.6.
Preemptive authentication is enabled by default but can be disabled by passing preemptive=False to the middleware constructor.
Related issues and pull requests on GitHub: #11128, #11129.
> This release fixes an issue where the quote_cookie parameter was not being properly respected for shared cookies (domain="", path=""). If your serve
> [!WARNING] > This release fixes an issue where the quote_cookie parameter was not being properly respected for shared cookies (domain="", path=""). If your server does not handle quoted cookies correctly, you may need to disable cookie quoting by setting quote_cookie=False when creating your ClientSession or CookieJar. > See https://docs.aiohttp.org/en/stable/client_advanced.html#cookie-quoting-routine for details.
Fixed cookie parsing to be more lenient when handling cookies with special characters in names or values. Cookies with characters like {, }, and / in names are now accepted instead of causing a ~http.cookies.CookieError and 500 errors. Additionally, cookies with mismatched quotes in values are now parsed correctly, and quoted cookie values are now handled consistently whether or not they include special attributes like Domain. Also fixed ~aiohttp.CookieJar to ensure shared cookies (domain="", path="") respect the quote_cookie parameter, making cookie quoting behavior consistent for all cookies -- by bdraco.
Related issues and pull requests on GitHub: #2683, #5397, #7993, #11112.
Fixed an issue where cookies with duplicate names but different domains or paths were lost when updating the cookie jar. The ~aiohttp.ClientSession cookie jar now correctly stores all cookies even if they have the same name but different domain or path, following the 6265#section-5.3 storage model -- by bdraco.
Note that ClientResponse.cookies returns a ~http.cookies.SimpleCookie which uses the cookie name as a key, so only the last cookie with each name is accessible via this interface. All cookies can be accessed via ClientResponse.headers.getall('Set-Cookie') if needed.
Related issues and pull requests on GitHub: #4486, #11105, #11106.
Avoided creating closed futures in ResponseHandler that will never be awaited -- by bdraco.
Related issues and pull requests on GitHub: #11107.
Downgraded the logging level for connector close errors from ERROR to DEBUG, as these are expected behavior with TLS 1.3 connections -- by bdraco.
Related issues and pull requests on GitHub: #11114.
Fixed cookie parsing to be more lenient when handling cookies with special characters in names or values. Cookies with characters like {, }, and / in
Fixed cookie parsing to be more lenient when handling cookies with special characters in names or values. Cookies with characters like {, }, and / in names are now accepted instead of causing a ~http.cookies.CookieError and 500 errors. Additionally, cookies with mismatched quotes in values are now parsed correctly, and quoted cookie values are now handled consistently whether or not they include special attributes like Domain. Also fixed ~aiohttp.CookieJar to ensure shared cookies (domain="", path="") respect the quote_cookie parameter, making cookie quoting behavior consistent for all cookies -- by bdraco.
Related issues and pull requests on GitHub: #2683, #5397, #7993, #11112.
Fixed an issue where cookies with duplicate names but different domains or paths were lost when updating the cookie jar. The ~aiohttp.ClientSession cookie jar now correctly stores all cookies even if they have the same name but different domain or path, following the 6265#section-5.3 storage model -- by bdraco.
Note that ClientResponse.cookies returns a ~http.cookies.SimpleCookie which uses the cookie name as a key, so only the last cookie with each name is accessible via this interface. All cookies can be accessed via ClientResponse.headers.getall('Set-Cookie') if needed.
Related issues and pull requests on GitHub: #4486, #11105, #11106.
Avoided creating closed futures in ResponseHandler that will never be awaited -- by bdraco.
Related issues and pull requests on GitHub: #11107.
Downgraded the logging level for connector close errors from ERROR to DEBUG, as these are expected behavior with TLS 1.3 connections -- by bdraco.
Related issues and pull requests on GitHub: #11114.
Fixed spurious "Future exception was never retrieved" warnings for connection lost errors when the connector is not closed -- by bdraco.
Fixed spurious "Future exception was never retrieved" warnings for connection lost errors when the connector is not closed -- by :user:bdraco.
When connections are lost, the exception is now marked as retrieved since it is always propagated through other means, preventing unnecessary warnings in logs.
Related issues and pull requests on GitHub: #11100.
Fixed connector not waiting for connections to close before returning from ~aiohttp.BaseConnector.close (partial backport of 3733) -- by atemate and b
Fixed connector not waiting for connections to close before returning from ~aiohttp.BaseConnector.close (partial backport of 3733) -- by atemate and bdraco.
Related issues and pull requests on GitHub: #1925, #11074.
Fixed memory leak in meth:~aiohttp.CookieJar.filter_cookies that caused unbounded memory growth when making requests to different URL paths -- by bdra
Fixed memory leak in ~aiohttp.CookieJar.filter_cookies that caused unbounded memory growth when making requests to different URL paths -- by bdraco and Cycloctane.
Related issues and pull requests on GitHub: #11052, #11054.
Fixed Content-Length header not being set to 0 for non-GET requests with None body -- by bdraco.
Fixed Content-Length header not being set to 0 for non-GET requests with None body -- by :user:bdraco.
Non-GET requests (POST, PUT, PATCH, DELETE) with None as the body now correctly set the Content-Length header to 0, matching the behavior of requests with empty bytes (b""). This regression was introduced in aiohttp 3.12.1.
Related issues and pull requests on GitHub: #11035.
Added support for reusable request bodies to enable retries, redirects, and digest authentication -- by bdraco and GLGDLY.
Added support for reusable request bodies to enable retries, redirects, and digest authentication -- by :user:bdraco and :user:GLGDLY.
Most payloads can now be safely reused multiple times, fixing long-standing issues where POST requests with form data or file uploads would fail on redirects with errors like "Form data has been processed already" or "I/O operation on closed file". This also enables digest authentication to work with request bodies and allows retry mechanisms to resend requests without consuming the payload. Note that payloads derived from async iterables may still not be reusable in some cases.
Related issues and pull requests on GitHub: #5530, #5577, #9201, #11017.
Added support for reusable request bodies to enable retries, redirects, and digest authentication -- by bdraco and GLGDLY.
Added support for reusable request bodies to enable retries, redirects, and digest authentication -- by :user:bdraco and :user:GLGDLY.
Most payloads can now be safely reused multiple times, fixing long-standing issues where POST requests with form data or file uploads would fail on redirects with errors like "Form data has been processed already" or "I/O operation on closed file". This also enables digest authentication to work with request bodies and allows retry mechanisms to resend requests without consuming the payload. Note that payloads derived from async iterables may still not be reusable in some cases.
Related issues and pull requests on GitHub: #5530, #5577, #9201, #11017.
Fixed pytest plugin to not use deprecated mod:asyncio policy APIs.
Fixed ~aiohttp.web.WebSocketResponse.prepared property to correctly reflect the prepared state, especially during timeout scenarios -- by bdraco
Related issues and pull requests on GitHub: #6009, #10988.
Response is now always True, instead of using MutableMapping behaviour (False when map is empty)
Related issues and pull requests on GitHub: #10119.
Fixed connection reuse for file-like data payloads by ensuring buffer truncation respects content-length boundaries and preventing premature connection closure race -- by bdraco.
Related issues and pull requests on GitHub: #10325, #10915, #10941, #10943.
Fixed pytest plugin to not use deprecated asyncio policy APIs.
Related issues and pull requests on GitHub: #10851.
Fixed ~aiohttp.resolver.AsyncResolver not using the loop argument in versions 3.x where it should still be supported -- by bdraco.
Related issues and pull requests on GitHub: #10951.
Added a comprehensive HTTP Digest Authentication client middleware (DigestAuthMiddleware) that implements RFC 7616. The middleware supports all standard hash algorithms (MD5, SHA, SHA-256, SHA-512) with session variants, handles both 'auth' and 'auth-int' quality of protection options, and automatically manages the authentication flow by intercepting 401 responses and retrying with proper credentials -- by feus4177, TimMenninger, and bdraco.
Related issues and pull requests on GitHub: #2213, #10725.
Added client middleware support -- by bdraco and Dreamsorcerer.
This change allows users to add middleware to the client session and requests, enabling features like authentication, logging, and request/response modification without modifying the core request logic. Additionally, the session attribute was added to ClientRequest, allowing middleware to access the session for making additional requests.
Related issues and pull requests on GitHub: #9732, #10902, #10945, #10952, #10959, #10968.
Allow user setting zlib compression backend -- by TimMenninger
This change allows the user to call aiohttp.set_zlib_backend() with the zlib compression module of their choice. Default behavior continues to use the builtin zlib library.
Related issues and pull requests on GitHub: #9798.
Added support for overriding the base URL with an absolute one in client sessions -- by vivodi.
Related issues and pull requests on GitHub: #10074.
Added host parameter to aiohttp_server fixture -- by christianwbrock.
Related issues and pull requests on GitHub: #10120.
Detect blocking calls in coroutines using BlockBuster -- by cbornet.
Related issues and pull requests on GitHub: #10433.
Added socket_factory to aiohttp.TCPConnector to allow specifying custom socket options -- by TimMenninger.
Related issues and pull requests on GitHub: #10474, #10520, #10961, #10962.
Started building armv7l manylinux wheels -- by bdraco.
Related issues and pull requests on GitHub: #10797.
Implemented shared DNS resolver management to fix excessive resolver object creation when using multiple client sessions. The new _DNSResolverManager singleton ensures only one DNSResolver object is created for default configurations, significantly reducing resource usage and improving performance for applications using multiple client sessions simultaneously -- by bdraco.
Related issues and pull requests on GitHub: #10847, #10923, #10946.
Upgraded to LLHTTP 9.3.0 -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #10972.
Optimized small HTTP requests/responses by coalescing headers and body into a single TCP packet -- by bdraco.
This change enhances network efficiency by reducing the number of packets sent for small HTTP payloads, improving latency and reducing overhead. Most importantly, this fixes compatibility with memory-constrained IoT devices that can only perform a single read operation and expect HTTP requests in one packet. The optimization uses zero-copy writelines when coalescing data and works with both regular and chunked transfer encoding.
When aiohttp uses client middleware to communicate with an aiohttp server, connection reuse is more likely to occur since complete responses arrive in a single packet for small payloads.
This aligns aiohttp with other popular HTTP clients that already coalesce small requests.
Related issues and pull requests on GitHub: #10991.
Improved documentation for middleware by adding warnings and examples about request body stream consumption. The documentation now clearly explains that request body streams can only be read once and provides best practices for sharing parsed request data between middleware and handlers -- by bdraco.
Related issues and pull requests on GitHub: #2914.
Removed non SPDX-license description from setup.cfg -- by devanshu-ziphq.
Related issues and pull requests on GitHub: #10662.
Added support for building against system llhttp library -- by mgorny.
This change adds support for AIOHTTP_USE_SYSTEM_DEPS environment variable that can be used to build aiohttp against the system install of the llhttp library rather than the vendored one.
Related issues and pull requests on GitHub: #10759.
aiodns is now installed on Windows with speedups extra -- by bdraco.
As of aiodns 3.3.0, SelectorEventLoop is no longer required when using pycares 4.7.0 or later.
Related issues and pull requests on GitHub: #10823.
Fixed compatibility issue with Cython 3.1.1 -- by bdraco
Related issues and pull requests on GitHub: #10877.
Sped up tests by disabling blockbuster fixture for test_static_file_huge and test_static_file_huge_cancel tests -- by dikos1337.
Related issues and pull requests on GitHub: #9705, #10761.
Updated tests to avoid using deprecated asyncio policy APIs and make it compatible with Python 3.14.
Related issues and pull requests on GitHub: #10851.
Added Winloop to test suite to support in the future -- by Vizonex.
Related issues and pull requests on GitHub: #10922.
Added support for the partitioned attribute in the set_cookie method.
Related issues and pull requests on GitHub: #9870.
Setting aiohttp.web.StreamResponse.last_modified to an unsupported type will now raise TypeError instead of silently failing -- by bdraco.
Related issues and pull requests on GitHub: #10146.
Fixed pytest plugin to not use deprecated mod:asyncio policy APIs.
Fixed ~aiohttp.web.WebSocketResponse.prepared property to correctly reflect the prepared state, especially during timeout scenarios -- by bdraco
Related issues and pull requests on GitHub: #6009, #10988.
Response is now always True, instead of using MutableMapping behaviour (False when map is empty)
Related issues and pull requests on GitHub: #10119.
Fixed connection reuse for file-like data payloads by ensuring buffer truncation respects content-length boundaries and preventing premature connection closure race -- by bdraco.
Related issues and pull requests on GitHub: #10325, #10915, #10941, #10943.
Fixed pytest plugin to not use deprecated asyncio policy APIs.
Related issues and pull requests on GitHub: #10851.
Fixed ~aiohttp.resolver.AsyncResolver not using the loop argument in versions 3.x where it should still be supported -- by bdraco.
Related issues and pull requests on GitHub: #10951.
Added a comprehensive HTTP Digest Authentication client middleware (DigestAuthMiddleware) that implements RFC 7616. The middleware supports all standard hash algorithms (MD5, SHA, SHA-256, SHA-512) with session variants, handles both 'auth' and 'auth-int' quality of protection options, and automatically manages the authentication flow by intercepting 401 responses and retrying with proper credentials -- by feus4177, TimMenninger, and bdraco.
Related issues and pull requests on GitHub: #2213, #10725.
Added client middleware support -- by bdraco and Dreamsorcerer.
This change allows users to add middleware to the client session and requests, enabling features like authentication, logging, and request/response modification without modifying the core request logic. Additionally, the session attribute was added to ClientRequest, allowing middleware to access the session for making additional requests.
Related issues and pull requests on GitHub: #9732, #10902, #10945, #10952, #10959, #10968.
Allow user setting zlib compression backend -- by TimMenninger
This change allows the user to call aiohttp.set_zlib_backend() with the zlib compression module of their choice. Default behavior continues to use the builtin zlib library.
Related issues and pull requests on GitHub: #9798.
Added support for overriding the base URL with an absolute one in client sessions -- by vivodi.
Related issues and pull requests on GitHub: #10074.
Added host parameter to aiohttp_server fixture -- by christianwbrock.
Related issues and pull requests on GitHub: #10120.
Detect blocking calls in coroutines using BlockBuster -- by cbornet.
Related issues and pull requests on GitHub: #10433.
Added socket_factory to aiohttp.TCPConnector to allow specifying custom socket options -- by TimMenninger.
Related issues and pull requests on GitHub: #10474, #10520, #10961, #10962.
Started building armv7l manylinux wheels -- by bdraco.
Related issues and pull requests on GitHub: #10797.
Implemented shared DNS resolver management to fix excessive resolver object creation when using multiple client sessions. The new _DNSResolverManager singleton ensures only one DNSResolver object is created for default configurations, significantly reducing resource usage and improving performance for applications using multiple client sessions simultaneously -- by bdraco.
Related issues and pull requests on GitHub: #10847, #10923, #10946.
Upgraded to LLHTTP 9.3.0 -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #10972.
Optimized small HTTP requests/responses by coalescing headers and body into a single TCP packet -- by bdraco.
This change enhances network efficiency by reducing the number of packets sent for small HTTP payloads, improving latency and reducing overhead. Most importantly, this fixes compatibility with memory-constrained IoT devices that can only perform a single read operation and expect HTTP requests in one packet. The optimization uses zero-copy writelines when coalescing data and works with both regular and chunked transfer encoding.
When aiohttp uses client middleware to communicate with an aiohttp server, connection reuse is more likely to occur since complete responses arrive in a single packet for small payloads.
This aligns aiohttp with other popular HTTP clients that already coalesce small requests.
Related issues and pull requests on GitHub: #10991.
Improved documentation for middleware by adding warnings and examples about request body stream consumption. The documentation now clearly explains that request body streams can only be read once and provides best practices for sharing parsed request data between middleware and handlers -- by bdraco.
Related issues and pull requests on GitHub: #2914.
Removed non SPDX-license description from setup.cfg -- by devanshu-ziphq.
Related issues and pull requests on GitHub: #10662.
Added support for building against system llhttp library -- by mgorny.
This change adds support for AIOHTTP_USE_SYSTEM_DEPS environment variable that can be used to build aiohttp against the system install of the llhttp library rather than the vendored one.
Related issues and pull requests on GitHub: #10759.
aiodns is now installed on Windows with speedups extra -- by bdraco.
As of aiodns 3.3.0, SelectorEventLoop is no longer required when using pycares 4.7.0 or later.
Related issues and pull requests on GitHub: #10823.
Fixed compatibility issue with Cython 3.1.1 -- by bdraco
Related issues and pull requests on GitHub: #10877.
Sped up tests by disabling blockbuster fixture for test_static_file_huge and test_static_file_huge_cancel tests -- by dikos1337.
Related issues and pull requests on GitHub: #9705, #10761.
Updated tests to avoid using deprecated asyncio policy APIs and make it compatible with Python 3.14.
Related issues and pull requests on GitHub: #10851.
Added Winloop to test suite to support in the future -- by Vizonex.
Related issues and pull requests on GitHub: #10922.
Added support for the partitioned attribute in the set_cookie method.
Related issues and pull requests on GitHub: #9870.
Setting aiohttp.web.StreamResponse.last_modified to an unsupported type will now raise TypeError instead of silently failing -- by bdraco.
Related issues and pull requests on GitHub: #10146.
Fixed pytest plugin to not use deprecated mod:asyncio policy APIs.
Fixed ~aiohttp.web.WebSocketResponse.prepared property to correctly reflect the prepared state, especially during timeout scenarios -- by bdraco
Related issues and pull requests on GitHub: #6009, #10988.
Response is now always True, instead of using MutableMapping behaviour (False when map is empty)
Related issues and pull requests on GitHub: #10119.
Fixed connection reuse for file-like data payloads by ensuring buffer truncation respects content-length boundaries and preventing premature connection closure race -- by bdraco.
Related issues and pull requests on GitHub: #10325, #10915, #10941, #10943.
Fixed pytest plugin to not use deprecated asyncio policy APIs.
Related issues and pull requests on GitHub: #10851.
Fixed ~aiohttp.resolver.AsyncResolver not using the loop argument in versions 3.x where it should still be supported -- by bdraco.
Related issues and pull requests on GitHub: #10951.
Added a comprehensive HTTP Digest Authentication client middleware (DigestAuthMiddleware) that implements RFC 7616. The middleware supports all standard hash algorithms (MD5, SHA, SHA-256, SHA-512) with session variants, handles both 'auth' and 'auth-int' quality of protection options, and automatically manages the authentication flow by intercepting 401 responses and retrying with proper credentials -- by feus4177, TimMenninger, and bdraco.
Related issues and pull requests on GitHub: #2213, #10725.
Added client middleware support -- by bdraco and Dreamsorcerer.
This change allows users to add middleware to the client session and requests, enabling features like authentication, logging, and request/response modification without modifying the core request logic. Additionally, the session attribute was added to ClientRequest, allowing middleware to access the session for making additional requests.
Related issues and pull requests on GitHub: #9732, #10902, #10945, #10952, #10959, #10968.
Allow user setting zlib compression backend -- by TimMenninger
This change allows the user to call aiohttp.set_zlib_backend() with the zlib compression module of their choice. Default behavior continues to use the builtin zlib library.
Related issues and pull requests on GitHub: #9798.
Added support for overriding the base URL with an absolute one in client sessions -- by vivodi.
Related issues and pull requests on GitHub: #10074.
Added host parameter to aiohttp_server fixture -- by christianwbrock.
Related issues and pull requests on GitHub: #10120.
Detect blocking calls in coroutines using BlockBuster -- by cbornet.
Related issues and pull requests on GitHub: #10433.
Added socket_factory to aiohttp.TCPConnector to allow specifying custom socket options -- by TimMenninger.
Related issues and pull requests on GitHub: #10474, #10520, #10961, #10962.
Started building armv7l manylinux wheels -- by bdraco.
Related issues and pull requests on GitHub: #10797.
Implemented shared DNS resolver management to fix excessive resolver object creation when using multiple client sessions. The new _DNSResolverManager singleton ensures only one DNSResolver object is created for default configurations, significantly reducing resource usage and improving performance for applications using multiple client sessions simultaneously -- by bdraco.
Related issues and pull requests on GitHub: #10847, #10923, #10946.
Upgraded to LLHTTP 9.3.0 -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #10972.
Improved documentation for middleware by adding warnings and examples about request body stream consumption. The documentation now clearly explains that request body streams can only be read once and provides best practices for sharing parsed request data between middleware and handlers -- by bdraco.
Related issues and pull requests on GitHub: #2914.
Removed non SPDX-license description from setup.cfg -- by devanshu-ziphq.
Related issues and pull requests on GitHub: #10662.
Added support for building against system llhttp library -- by mgorny.
This change adds support for AIOHTTP_USE_SYSTEM_DEPS environment variable that can be used to build aiohttp against the system install of the llhttp library rather than the vendored one.
Related issues and pull requests on GitHub: #10759.
aiodns is now installed on Windows with speedups extra -- by bdraco.
As of aiodns 3.3.0, SelectorEventLoop is no longer required when using pycares 4.7.0 or later.
Related issues and pull requests on GitHub: #10823.
Fixed compatibility issue with Cython 3.1.1 -- by bdraco
Related issues and pull requests on GitHub: #10877.
Sped up tests by disabling blockbuster fixture for test_static_file_huge and test_static_file_huge_cancel tests -- by dikos1337.
Related issues and pull requests on GitHub: #9705, #10761.
Updated tests to avoid using deprecated asyncio policy APIs and make it compatible with Python 3.14.
Related issues and pull requests on GitHub: #10851.
Added Winloop to test suite to support in the future -- by Vizonex.
Related issues and pull requests on GitHub: #10922.
Added support for the partitioned attribute in the set_cookie method.
Related issues and pull requests on GitHub: #9870.
Setting aiohttp.web.StreamResponse.last_modified to an unsupported type will now raise TypeError instead of silently failing -- by bdraco.
Related issues and pull requests on GitHub: #10146.
Fixed pytest plugin to not use deprecated mod:asyncio policy APIs.
Response is now always True, instead of using MutableMapping behaviour (False when map is empty)
Related issues and pull requests on GitHub: #10119.
Fixed connection reuse for file-like data payloads by ensuring buffer truncation respects content-length boundaries and preventing premature connection closure race -- by bdraco.
Related issues and pull requests on GitHub: #10325, #10915, #10941, #10943.
Fixed pytest plugin to not use deprecated asyncio policy APIs.
Related issues and pull requests on GitHub: #10851.
Fixed ~aiohttp.resolver.AsyncResolver not using the loop argument in versions 3.x where it should still be supported -- by bdraco.
Related issues and pull requests on GitHub: #10951.
Added a comprehensive HTTP Digest Authentication client middleware (DigestAuthMiddleware) that implements RFC 7616. The middleware supports all standard hash algorithms (MD5, SHA, SHA-256, SHA-512) with session variants, handles both 'auth' and 'auth-int' quality of protection options, and automatically manages the authentication flow by intercepting 401 responses and retrying with proper credentials -- by feus4177, TimMenninger, and bdraco.
Related issues and pull requests on GitHub: #2213, #10725.
Added client middleware support -- by bdraco and Dreamsorcerer.
This change allows users to add middleware to the client session and requests, enabling features like authentication, logging, and request/response modification without modifying the core request logic. Additionally, the session attribute was added to ClientRequest, allowing middleware to access the session for making additional requests.
Related issues and pull requests on GitHub: #9732, #10902, #10952.
Allow user setting zlib compression backend -- by TimMenninger
This change allows the user to call aiohttp.set_zlib_backend() with the zlib compression module of their choice. Default behavior continues to use the builtin zlib library.
Related issues and pull requests on GitHub: #9798.
Added support for overriding the base URL with an absolute one in client sessions -- by vivodi.
Related issues and pull requests on GitHub: #10074.
Added host parameter to aiohttp_server fixture -- by christianwbrock.
Related issues and pull requests on GitHub: #10120.
Detect blocking calls in coroutines using BlockBuster -- by cbornet.
Related issues and pull requests on GitHub: #10433.
Added socket_factory to aiohttp.TCPConnector to allow specifying custom socket options -- by TimMenninger.
Related issues and pull requests on GitHub: #10474, #10520.
Started building armv7l manylinux wheels -- by bdraco.
Related issues and pull requests on GitHub: #10797.
Implemented shared DNS resolver management to fix excessive resolver object creation when using multiple client sessions. The new _DNSResolverManager singleton ensures only one DNSResolver object is created for default configurations, significantly reducing resource usage and improving performance for applications using multiple client sessions simultaneously -- by bdraco.
Related issues and pull requests on GitHub: #10847, #10923, #10946.
Removed non SPDX-license description from setup.cfg -- by devanshu-ziphq.
Related issues and pull requests on GitHub: #10662.
Added support for building against system llhttp library -- by mgorny.
This change adds support for AIOHTTP_USE_SYSTEM_DEPS environment variable that can be used to build aiohttp against the system install of the llhttp library rather than the vendored one.
Related issues and pull requests on GitHub: #10759.
aiodns is now installed on Windows with speedups extra -- by bdraco.
As of aiodns 3.3.0, SelectorEventLoop is no longer required when using pycares 4.7.0 or later.
Related issues and pull requests on GitHub: #10823.
Fixed compatibility issue with Cython 3.1.1 -- by bdraco
Related issues and pull requests on GitHub: #10877.
Sped up tests by disabling blockbuster fixture for test_static_file_huge and test_static_file_huge_cancel tests -- by dikos1337.
Related issues and pull requests on GitHub: #9705, #10761.
Updated tests to avoid using deprecated asyncio policy APIs and make it compatible with Python 3.14.
Related issues and pull requests on GitHub: #10851.
Added Winloop to test suite to support in the future -- by Vizonex.
Related issues and pull requests on GitHub: #10922.
Added support for the partitioned attribute in the set_cookie method.
Related issues and pull requests on GitHub: #9870.
Setting aiohttp.web.StreamResponse.last_modified to an unsupported type will now raise TypeError instead of silently failing -- by bdraco.
Related issues and pull requests on GitHub: #10146.
Fixed pytest plugin to not use deprecated mod:asyncio policy APIs.
Response is now always True, instead of using MutableMapping behaviour (False when map is empty)
Related issues and pull requests on GitHub: #10119.
Fixed connection reuse for file-like data payloads by ensuring buffer truncation respects content-length boundaries and preventing premature connection closure race -- by bdraco.
Related issues and pull requests on GitHub: #10325, #10915, #10941, #10943.
Fixed pytest plugin to not use deprecated asyncio policy APIs.
Related issues and pull requests on GitHub: #10851.
Added a comprehensive HTTP Digest Authentication client middleware (DigestAuthMiddleware) that implements RFC 7616. The middleware supports all standard hash algorithms (MD5, SHA, SHA-256, SHA-512) with session variants, handles both 'auth' and 'auth-int' quality of protection options, and automatically manages the authentication flow by intercepting 401 responses and retrying with proper credentials -- by feus4177, TimMenninger, and bdraco.
Related issues and pull requests on GitHub: #2213, #10725.
Added client middleware support -- by bdraco and Dreamsorcerer.
This change allows users to add middleware to the client session and requests, enabling features like authentication, logging, and request/response modification without modifying the core request logic. Additionally, the session attribute was added to ClientRequest, allowing middleware to access the session for making additional requests.
Related issues and pull requests on GitHub: #9732, #10902.
Allow user setting zlib compression backend -- by TimMenninger
This change allows the user to call aiohttp.set_zlib_backend() with the zlib compression module of their choice. Default behavior continues to use the builtin zlib library.
Related issues and pull requests on GitHub: #9798.
Added support for overriding the base URL with an absolute one in client sessions -- by vivodi.
Related issues and pull requests on GitHub: #10074.
Added host parameter to aiohttp_server fixture -- by christianwbrock.
Related issues and pull requests on GitHub: #10120.
Detect blocking calls in coroutines using BlockBuster -- by cbornet.
Related issues and pull requests on GitHub: #10433.
Added socket_factory to aiohttp.TCPConnector to allow specifying custom socket options -- by TimMenninger.
Related issues and pull requests on GitHub: #10474, #10520.
Started building armv7l manylinux wheels -- by bdraco.
Related issues and pull requests on GitHub: #10797.
Implemented shared DNS resolver management to fix excessive resolver object creation when using multiple client sessions. The new _DNSResolverManager singleton ensures only one DNSResolver object is created for default configurations, significantly reducing resource usage and improving performance for applications using multiple client sessions simultaneously -- by bdraco.
Related issues and pull requests on GitHub: #10847, #10923, #10946.
Removed non SPDX-license description from setup.cfg -- by devanshu-ziphq.
Related issues and pull requests on GitHub: #10662.
Added support for building against system llhttp library -- by mgorny.
This change adds support for AIOHTTP_USE_SYSTEM_DEPS environment variable that can be used to build aiohttp against the system install of the llhttp library rather than the vendored one.
Related issues and pull requests on GitHub: #10759.
aiodns is now installed on Windows with speedups extra -- by bdraco.
As of aiodns 3.3.0, SelectorEventLoop is no longer required when using pycares 4.7.0 or later.
Related issues and pull requests on GitHub: #10823.
Fixed compatibility issue with Cython 3.1.1 -- by bdraco
Related issues and pull requests on GitHub: #10877.
Sped up tests by disabling blockbuster fixture for test_static_file_huge and test_static_file_huge_cancel tests -- by dikos1337.
Related issues and pull requests on GitHub: #9705, #10761.
Updated tests to avoid using deprecated asyncio policy APIs and make it compatible with Python 3.14.
Related issues and pull requests on GitHub: #10851.
Added Winloop to test suite to support in the future -- by Vizonex.
Related issues and pull requests on GitHub: #10922.
Added support for the partitioned attribute in the set_cookie method.
Related issues and pull requests on GitHub: #9870.
Setting aiohttp.web.StreamResponse.last_modified to an unsupported type will now raise TypeError instead of silently failing -- by bdraco.
Related issues and pull requests on GitHub: #10146.
Fixed pytest plugin to not use deprecated mod:asyncio policy APIs.
Response is now always True, instead of using MutableMapping behaviour (False when map is empty)
Related issues and pull requests on GitHub: #10119.
Fixed connection reuse for file-like data payloads by ensuring buffer truncation respects content-length boundaries and preventing premature connection closure race -- by bdraco.
Related issues and pull requests on GitHub: #10325, #10915.
Fixed pytest plugin to not use deprecated asyncio policy APIs.
Related issues and pull requests on GitHub: #10851.
Added a comprehensive HTTP Digest Authentication client middleware (DigestAuthMiddleware) that implements RFC 7616. The middleware supports all standard hash algorithms (MD5, SHA, SHA-256, SHA-512) with session variants, handles both 'auth' and 'auth-int' quality of protection options, and automatically manages the authentication flow by intercepting 401 responses and retrying with proper credentials -- by feus4177, TimMenninger, and bdraco.
Related issues and pull requests on GitHub: #2213, #10725.
Added client middleware support -- by bdraco and Dreamsorcerer.
This change allows users to add middleware to the client session and requests, enabling features like authentication, logging, and request/response modification without modifying the core request logic. Additionally, the session attribute was added to ClientRequest, allowing middleware to access the session for making additional requests.
Related issues and pull requests on GitHub: #9732, #10902.
Allow user setting zlib compression backend -- by TimMenninger
This change allows the user to call aiohttp.set_zlib_backend() with the zlib compression module of their choice. Default behavior continues to use the builtin zlib library.
Related issues and pull requests on GitHub: #9798.
Added support for overriding the base URL with an absolute one in client sessions -- by vivodi.
Related issues and pull requests on GitHub: #10074.
Added host parameter to aiohttp_server fixture -- by christianwbrock.
Related issues and pull requests on GitHub: #10120.
Detect blocking calls in coroutines using BlockBuster -- by cbornet.
Related issues and pull requests on GitHub: #10433.
Added socket_factory to aiohttp.TCPConnector to allow specifying custom socket options -- by TimMenninger.
Related issues and pull requests on GitHub: #10474, #10520.
Started building armv7l manylinux wheels -- by bdraco.
Related issues and pull requests on GitHub: #10797.
Implemented shared DNS resolver management to fix excessive resolver object creation when using multiple client sessions. The new _DNSResolverManager singleton ensures only one DNSResolver object is created for default configurations, significantly reducing resource usage and improving performance for applications using multiple client sessions simultaneously -- by bdraco.
Related issues and pull requests on GitHub: #10847, #10923.
Removed non SPDX-license description from setup.cfg -- by devanshu-ziphq.
Related issues and pull requests on GitHub: #10662.
Added support for building against system llhttp library -- by mgorny.
This change adds support for AIOHTTP_USE_SYSTEM_DEPS environment variable that can be used to build aiohttp against the system install of the llhttp library rather than the vendored one.
Related issues and pull requests on GitHub: #10759.
aiodns is now installed on Windows with speedups extra -- by bdraco.
As of aiodns 3.3.0, SelectorEventLoop is no longer required when using pycares 4.7.0 or later.
Related issues and pull requests on GitHub: #10823.
Fixed compatibility issue with Cython 3.1.1 -- by bdraco
Related issues and pull requests on GitHub: #10877.
Sped up tests by disabling blockbuster fixture for test_static_file_huge and test_static_file_huge_cancel tests -- by dikos1337.
Related issues and pull requests on GitHub: #9705, #10761.
Updated tests to avoid using deprecated asyncio policy APIs and make it compatible with Python 3.14.
Related issues and pull requests on GitHub: #10851.
Added Winloop to test suite to support in the future -- by Vizonex.
Related issues and pull requests on GitHub: #10922.
Added support for the partitioned attribute in the set_cookie method.
Related issues and pull requests on GitHub: #9870.
Setting aiohttp.web.StreamResponse.last_modified to an unsupported type will now raise TypeError instead of silently failing -- by bdraco.
Related issues and pull requests on GitHub: #10146.
Fixed pytest plugin to not use deprecated mod:asyncio policy APIs.
Response is now always True, instead of using MutableMapping behaviour (False when map is empty)
Related issues and pull requests on GitHub: #10119.
Fixed pytest plugin to not use deprecated asyncio policy APIs.
Related issues and pull requests on GitHub: #10851.
Added a comprehensive HTTP Digest Authentication client middleware (DigestAuthMiddleware) that implements RFC 7616. The middleware supports all standard hash algorithms (MD5, SHA, SHA-256, SHA-512) with session variants, handles both 'auth' and 'auth-int' quality of protection options, and automatically manages the authentication flow by intercepting 401 responses and retrying with proper credentials -- by feus4177, TimMenninger, and bdraco.
Related issues and pull requests on GitHub: #2213, #10725.
Added client middleware support -- by bdraco and Dreamsorcerer.
This change allows users to add middleware to the client session and requests, enabling features like authentication, logging, and request/response modification without modifying the core request logic. Additionally, the session attribute was added to ClientRequest, allowing middleware to access the session for making additional requests.
Related issues and pull requests on GitHub: #9732, #10902.
Allow user setting zlib compression backend -- by TimMenninger
This change allows the user to call aiohttp.set_zlib_backend() with the zlib compression module of their choice. Default behavior continues to use the builtin zlib library.
Related issues and pull requests on GitHub: #9798.
Added support for overriding the base URL with an absolute one in client sessions -- by vivodi.
Related issues and pull requests on GitHub: #10074.
Added host parameter to aiohttp_server fixture -- by christianwbrock.
Related issues and pull requests on GitHub: #10120.
Detect blocking calls in coroutines using BlockBuster -- by cbornet.
Related issues and pull requests on GitHub: #10433.
Added socket_factory to aiohttp.TCPConnector to allow specifying custom socket options -- by TimMenninger.
Related issues and pull requests on GitHub: #10474, #10520.
Started building armv7l manylinux wheels -- by bdraco.
Related issues and pull requests on GitHub: #10797.
Implemented shared DNS resolver management to fix excessive resolver object creation when using multiple client sessions. The new _DNSResolverManager singleton ensures only one DNSResolver object is created for default configurations, significantly reducing resource usage and improving performance for applications using multiple client sessions simultaneously -- by bdraco.
Related issues and pull requests on GitHub: #10847.
Removed non SPDX-license description from setup.cfg -- by devanshu-ziphq.
Related issues and pull requests on GitHub: #10662.
aiodns is now installed on Windows with speedups extra -- by bdraco.
As of aiodns 3.3.0, SelectorEventLoop is no longer required when using pycares 4.7.0 or later.
Related issues and pull requests on GitHub: #10823.
Fixed compatibility issue with Cython 3.1.1 -- by bdraco
Related issues and pull requests on GitHub: #10877.
Sped up tests by disabling blockbuster fixture for test_static_file_huge and test_static_file_huge_cancel tests -- by dikos1337.
Related issues and pull requests on GitHub: #9705, #10761.
Updated tests to avoid using deprecated asyncio policy APIs and make it compatible with Python 3.14.
Related issues and pull requests on GitHub: #10851.
Added support for the partitioned attribute in the set_cookie method.
Related issues and pull requests on GitHub: #9870.
Setting aiohttp.web.StreamResponse.last_modified to an unsupported type will now raise TypeError instead of silently failing -- by bdraco.
Related issues and pull requests on GitHub: #10146.
Disabled TLS in TLS warning (when using HTTPS proxies) for uvloop and newer Python versions -- by lezgomatt.
Disabled TLS in TLS warning (when using HTTPS proxies) for uvloop and newer Python versions -- by :user:lezgomatt.
Related issues and pull requests on GitHub: #7686.
Fixed reading fragmented WebSocket messages when the payload was masked -- by :user:bdraco.
The problem first appeared in 3.11.17
Related issues and pull requests on GitHub: #10764.
Optimized web server performance when access logging is disabled by reducing time syscalls -- by bdraco.
Optimized web server performance when access logging is disabled by reducing time syscalls -- by :user:bdraco.
Related issues and pull requests on GitHub: #10713.
Improved web server performance when connection can be reused -- by :user:bdraco.
Related issues and pull requests on GitHub: #10714.
Improved performance of the WebSocket reader -- by :user:bdraco.
Related issues and pull requests on GitHub: #10740.
Improved performance of the WebSocket reader with large messages -- by :user:bdraco.
Related issues and pull requests on GitHub: #10744.
Replaced deprecated asyncio.iscoroutinefunction with its counterpart from inspect -- by layday.
Replaced deprecated asyncio.iscoroutinefunction with its counterpart from inspect -- by layday.
Related issues and pull requests on GitHub: #10634.
Fixed multidict.CIMultiDict being mutated when passed to aiohttp.web.Response -- by bdraco.
Related issues and pull requests on GitHub: #10672.
Reverted explicitly closing sockets if an exception is raised during create_connection -- by bdraco.
Reverted explicitly closing sockets if an exception is raised during create_connection -- by :user:bdraco.
This change originally appeared in aiohttp 3.11.13
Related issues and pull requests on GitHub: #10464, #10617, #10656.
Improved performance of WebSocket buffer handling -- by :user:bdraco.
Related issues and pull requests on GitHub: #10601.
Improved performance of serializing headers -- by :user:bdraco.
Related issues and pull requests on GitHub: #10625.
Fixed an issue where dns queries were delayed indefinitely when an exception occurred in a trace.send_dns_cache_miss -- by logioniz.
Fixed an issue where dns queries were delayed indefinitely when an exception occurred in a trace.send_dns_cache_miss -- by logioniz.
Related issues and pull requests on GitHub: #10529.
Fixed DNS resolution on platforms that don't support socket.AI_ADDRCONFIG -- by maxbachmann.
Related issues and pull requests on GitHub: #10542.
The connector now raises aiohttp.ClientConnectionError instead of OSError when failing to explicitly close the socket after asyncio.loop.create_connection fails -- by bdraco.
Related issues and pull requests on GitHub: #10551.
Break cyclic references at connection close when there was a traceback -- by bdraco.
Special thanks to availov for reporting the issue.
Related issues and pull requests on GitHub: #10556.
Break cyclic references when there is an exception handling a request -- by bdraco.
Related issues and pull requests on GitHub: #10569.
Improved logging on non-overlapping WebSocket client protocols to include the remote address -- by bdraco.
Related issues and pull requests on GitHub: #10564.
Improved performance of parsing content types by adding a cache in the same manner currently done with mime types -- by bdraco.
Related issues and pull requests on GitHub: #10552.
Removed a break statement inside the finally block in class:~aiohttp.web.RequestHandler -- by Cycloctane.
Removed a break statement inside the finally block in ~aiohttp.web.RequestHandler -- by Cycloctane.
Related issues and pull requests on GitHub: #10434.
Changed connection creation to explicitly close sockets if an exception is raised in the event loop's create_connection method -- by top-oai.
Related issues and pull requests on GitHub: #10464.
Fixed test test_write_large_payload_deflate_compression_data_in_eof_writelines failing with Python 3.12.9+ or 3.13.2+ -- by bdraco.
Related issues and pull requests on GitHub: #10423.
Added human-readable error messages to the exceptions for WebSocket disconnects due to PONG not being received -- by bdraco.
Previously, the error messages were empty strings, which made it hard to determine what went wrong.
Related issues and pull requests on GitHub: #10422.
MultipartForm.decode() now follows RFC1341 7.2.1 with a CRLF after the boundary -- by imnotjames.
MultipartForm.decode() now follows RFC1341 7.2.1 with a CRLF after the boundary -- by imnotjames.
Related issues and pull requests on GitHub: #10270.
Restored the missing total_bytes attribute to EmptyStreamReader -- by bdraco.
Related issues and pull requests on GitHub: #10387.
Updated ~aiohttp.request to make it accept _RequestOptions kwargs. -- by Cycloctane.
Related issues and pull requests on GitHub: #10300.
Improved logging of HTTP protocol errors to include the remote address -- by bdraco.
Related issues and pull requests on GitHub: #10332.
Added aiohttp-openmetrics to list of third-party libraries -- by jelmer.
Related issues and pull requests on GitHub: #10304.
Added missing files to the source distribution to fix Makefile targets. Added a cythonize-nodeps target to run Cython without invoking pip to install dependencies.
Related issues and pull requests on GitHub: #10366.
Started building armv7l musllinux wheels -- by bdraco.
Related issues and pull requests on GitHub: #10404.
The CI/CD workflow has been updated to use upload-artifact v4 and download-artifact v4 GitHub Actions -- by silamon.
Related issues and pull requests on GitHub: #10281.
Restored support for zero copy writes when using Python 3.12 versions 3.12.9 and later or Python 3.13.2+ -- by bdraco.
Zero copy writes were previously disabled due to 2024-12254 which is resolved in these Python versions.
Related issues and pull requests on GitHub: #10137.
Updated meth:~aiohttp.ClientSession.request to reuse the quote_cookie setting from ClientSession._cookie_jar when processing cookies parameter. -- by
Updated ~aiohttp.ClientSession.request to reuse the quote_cookie setting from ClientSession._cookie_jar when processing cookies parameter. -- by Cycloctane.
Related issues and pull requests on GitHub: #10093.
Fixed type of SSLContext for some static type checkers (e.g. pyright).
Related issues and pull requests on GitHub: #10099.
Updated aiohttp.web.StreamResponse.write annotation to also allow bytearray and memoryview as inputs -- by cdce8p.
Related issues and pull requests on GitHub: #10154.
Fixed a hang where a connection previously used for a streaming download could be returned to the pool in a paused state. -- by javitonino.
Related issues and pull requests on GitHub: #10169.
Enabled ALPN on default SSL contexts. This improves compatibility with some proxies which don't work without this extension. -- by Cycloctane.
Related issues and pull requests on GitHub: #10156.
Fixed an infinite loop that can occur when using aiohttp in combination with async-solipsism -- by bmerry.
Related issues and pull requests on GitHub: #10149.
Replaced deprecated call to mimetypes.guess_type with mimetypes.guess_file_type when using Python 3.13+ -- by bdraco.
Fixed race condition in aiohttp.web.FileResponse that could have resulted in an incorrect response if the file was replaced on the file system during prepare -- by bdraco.
Related issues and pull requests on GitHub: #10101, #10113.
Replaced deprecated call to mimetypes.guess_type with mimetypes.guess_file_type when using Python 3.13+ -- by bdraco.
Related issues and pull requests on GitHub: #10102.
Disabled zero copy writes in the StreamWriter -- by bdraco.
Related issues and pull requests on GitHub: #10125.
Fixed invalid method logging unexpected being logged at exception level on subsequent connections -- by bdraco.
Fixed invalid method logging unexpected being logged at exception level on subsequent connections -- by :user:bdraco.
Related issues and pull requests on GitHub: #10055, #10076.
Improved performance of parsing headers when using the C parser -- by :user:bdraco.
Related issues and pull requests on GitHub: #10073.
Improved performance of creating aiohttp.ClientResponse objects when there are no cookies -- by bdraco.
Improved performance of creating aiohttp.ClientResponse objects when there are no cookies -- by bdraco.
Related issues and pull requests on GitHub: #10029.
Improved performance of creating aiohttp.ClientResponse objects -- by bdraco.
Related issues and pull requests on GitHub: #10030.
Improved performances of creating objects during the HTTP request lifecycle -- by bdraco.
Related issues and pull requests on GitHub: #10037.
Improved performance of constructing aiohttp.web.Response with headers -- by bdraco.
Related issues and pull requests on GitHub: #10043.
Improved performance of making requests when there are no auto headers to skip -- by bdraco.
Related issues and pull requests on GitHub: #10049.
Downgraded logging of invalid HTTP method exceptions on the first request to debug level -- by bdraco.
HTTP requests starting with an invalid method are relatively common, especially when connected to the public internet, because browsers or other clients may try to speak SSL to a plain-text server or vice-versa. These exceptions can quickly fill the log with noise when nothing is wrong.
Related issues and pull requests on GitHub: #10055.
Fixed the HTTP client not considering the connector's force_close value when setting the Connection header -- by bdraco.
Fixed the HTTP client not considering the connector's force_close value when setting the Connection header -- by :user:bdraco.
Related issues and pull requests on GitHub: #10003.
Improved performance of serializing HTTP headers -- by :user:bdraco.
Related issues and pull requests on GitHub: #10014.
Restored the force_close method to the ResponseHandler -- by bdraco.
Restored the force_close method to the ResponseHandler -- by :user:bdraco.
Related issues and pull requests on GitHub: #9997.
Fixed the ANY method not appearing in ~aiohttp.web.UrlDispatcher.routes -- by bdraco.
Fixed the ANY method not appearing in ~aiohttp.web.UrlDispatcher.routes -- by bdraco.
Related issues and pull requests on GitHub: #9899, #9987.
Fixed StaticResource not allowing the OPTIONS method after calling set_options_route -- by bdraco.
Fixed StaticResource not allowing the OPTIONS method after calling set_options_route -- by :user:bdraco.
Related issues and pull requests on GitHub: #9972, #9975, #9976.
Improved performance of creating web responses when there are no cookies -- by :user:bdraco.
Related issues and pull requests on GitHub: #9895.
Removed non-existing __author__ from dir(aiohttp) -- by Dreamsorcerer.
Removed non-existing __author__ from dir(aiohttp) -- by :user:Dreamsorcerer.
Related issues and pull requests on GitHub: #9918.
Restored the FlowControlDataQueue class -- by :user:bdraco.
This class is no longer used internally, and will be permanently removed in the next major version.
Related issues and pull requests on GitHub: #9963.
Improved performance of resolving resources when multiple methods are registered for the same route -- by :user:bdraco.
Related issues and pull requests on GitHub: #9899.
Fixed improperly closed WebSocket connections generating an unhandled exception -- by bdraco.
Fixed improperly closed WebSocket connections generating an unhandled exception -- by :user:bdraco.
Related issues and pull requests on GitHub: #9883.
Added a backward compatibility layer to aiohttp.RequestInfo to allow creating these objects without a real_url -- by bdraco.
Added a backward compatibility layer to aiohttp.RequestInfo to allow creating these objects without a real_url -- by bdraco.
Related issues and pull requests on GitHub: #9873.
Removals and backward incompatible breaking changes
Raise aiohttp.ServerFingerprintMismatch exception on client-side if request through http proxy with mismatching server fingerprint digest: aiohttp.ClientSession(headers=headers, connector=TCPConnector(ssl=aiohttp.Fingerprint(mismatch_digest), trust_env=True).request(...) -- by gangj.
Related issues and pull requests on GitHub: #6652.
Modified websocket aiohttp.ClientWebSocketResponse.receive_str, aiohttp.ClientWebSocketResponse.receive_bytes, aiohttp.web.WebSocketResponse.receive_str & aiohttp.web.WebSocketResponse.receive_bytes methods to raise new aiohttp.WSMessageTypeError exception, instead of generic TypeError, when websocket messages of incorrect types are received -- by ara-25.
Related issues and pull requests on GitHub: #6800.
Made TestClient.app a Generic so type checkers will know the correct type (avoiding unneeded client.app is not None checks) -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8977.
Fixed the keep-alive connection pool to be FIFO instead of LIFO -- by bdraco.
Keep-alive connections are more likely to be reused before they disconnect.
Related issues and pull requests on GitHub: #9672.
Added strategy parameter to aiohttp.web.StreamResponse.enable_compression The value of this parameter is passed to the zlib.compressobj function, allowing people to use a more sufficient compression algorithm for their data served by aiohttp.web -- by shootkin
Related issues and pull requests on GitHub: #6257.
Added server_hostname parameter to ws_connect.
Related issues and pull requests on GitHub: #7941.
Exported ~aiohttp.ClientWSTimeout to top-level namespace -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8612.
Added secure/httponly/samesite parameters to .del_cookie() -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8956.
Updated ~aiohttp.ClientSession's auth logic to include default auth only if the request URL's origin matches _base_url; otherwise, the auth will not be included -- by MaximZemskov
Related issues and pull requests on GitHub: #8966, #9466.
Added proxy and proxy_auth parameters to ~aiohttp.ClientSession -- by meshya.
Related issues and pull requests on GitHub: #9207.
Added default_to_multipart parameter to FormData.
Related issues and pull requests on GitHub: #9335.
Added ~aiohttp.ClientWebSocketResponse.send_frame and ~aiohttp.web.WebSocketResponse.send_frame for WebSockets -- by bdraco.
Related issues and pull requests on GitHub: #9348.
Updated ~aiohttp.ClientSession to support paths in base_url parameter. base_url paths must end with a / -- by Cycloctane.
Related issues and pull requests on GitHub: #9530.
Improved performance of reading WebSocket messages with a Cython implementation -- by bdraco.
Related issues and pull requests on GitHub: #9543, #9554, #9556, #9558, #9636, #9649, #9781.
Added writer_limit to the ~aiohttp.web.WebSocketResponse to be able to adjust the limit before the writer forces the buffer to be drained -- by bdraco.
Related issues and pull requests on GitHub: #9572.
Added an ~aiohttp.abc.AbstractAccessLogger.enabled property to aiohttp.abc.AbstractAccessLogger to dynamically check if logging is enabled -- by bdraco.
Related issues and pull requests on GitHub: #9822.
Deprecate obsolete timeout: float and receive_timeout: Optional[float] in ~aiohttp.ClientSession.ws_connect. Change default websocket receive timeout from None to 10.0.
Related issues and pull requests on GitHub: #3945.
Dropped support for Python 3.8 -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8797.
Increased minimum yarl version to 1.17.0 -- by bdraco.
Related issues and pull requests on GitHub: #8909, #9079, #9305, #9574.
Removed the is_ipv6_address and is_ip4_address helpers are they are no longer used -- by bdraco.
Related issues and pull requests on GitHub: #9344.
Changed ClientRequest.connection_key to be a NamedTuple to improve client performance -- by bdraco.
Related issues and pull requests on GitHub: #9365.
FlowControlDataQueue has been replaced with the WebSocketDataQueue -- by bdraco.
Related issues and pull requests on GitHub: #9685.
Changed ClientRequest.request_info to be a NamedTuple to improve client performance -- by bdraco.
Related issues and pull requests on GitHub: #9692.
Switched to using the propcache package for property caching -- by bdraco.
The propcache package is derived from the property caching code in yarl and has been broken out to avoid maintaining it for multiple projects.
Related issues and pull requests on GitHub: #9394.
Separated aiohttp.http_websocket into multiple files to make it easier to maintain -- by bdraco.
Related issues and pull requests on GitHub: #9542, #9552.
Changed diagram images generator from blockdiag to GraphViz. Generating documentation now requires the GraphViz executable to be included in $PATH or sphinx build configuration.
Related issues and pull requests on GitHub: #9359.
Added flake8 settings to avoid some forms of implicit concatenation. -- by booniepepper.
Related issues and pull requests on GitHub: #7731.
Enabled keep-alive support on proxies (which was originally disabled several years ago) -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8920.
Changed web entry point to not listen on TCP when only a Unix path is passed -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #9033.
Disabled automatic retries of failed requests in aiohttp.test_utils.TestClient's client session (which could potentially hide errors in tests) -- by ShubhAgarwal-dev.
Related issues and pull requests on GitHub: #9141.
Changed web keepalive_timeout default to around an hour in order to reduce race conditions on reverse proxies -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #9285.
Reduced memory required for stream objects created during the client request lifecycle -- by bdraco.
Related issues and pull requests on GitHub: #9407.
Improved performance of the internal DataQueue -- by bdraco.
Related issues and pull requests on GitHub: #9659.
Improved performance of calling receive for WebSockets for the most common message types -- by bdraco.
Related issues and pull requests on GitHub: #9679.
Replace internal helper methods method_must_be_empty_body and status_code_must_be_empty_body with simple set lookups -- by bdraco.
Related issues and pull requests on GitHub: #9722.
Improved performance of aiohttp.BaseConnector when there is no limit_per_host -- by bdraco.
Related issues and pull requests on GitHub: #9756.
Improved performance of sending HTTP requests when there is no body -- by bdraco.
Related issues and pull requests on GitHub: #9757.
Improved performance of the WebsocketWriter when the protocol is not paused -- by bdraco.
Related issues and pull requests on GitHub: #9796.
Implemented zero copy writes for StreamWriter -- by bdraco.
Related issues and pull requests on GitHub: #9839.
Removals and backward incompatible breaking changes
Raise aiohttp.ServerFingerprintMismatch exception on client-side if request through http proxy with mismatching server fingerprint digest: aiohttp.ClientSession(headers=headers, connector=TCPConnector(ssl=aiohttp.Fingerprint(mismatch_digest), trust_env=True).request(...) -- by gangj.
Related issues and pull requests on GitHub: #6652.
Modified websocket aiohttp.ClientWebSocketResponse.receive_str, aiohttp.ClientWebSocketResponse.receive_bytes, aiohttp.web.WebSocketResponse.receive_str & aiohttp.web.WebSocketResponse.receive_bytes methods to raise new aiohttp.WSMessageTypeError exception, instead of generic TypeError, when websocket messages of incorrect types are received -- by ara-25.
Related issues and pull requests on GitHub: #6800.
Made TestClient.app a Generic so type checkers will know the correct type (avoiding unneeded client.app is not None checks) -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8977.
Authentication provided by a redirect now takes precedence over provided auth when making requests with the client -- by PLPeeters.
Related issues and pull requests on GitHub: #9436.
Fixed WebSocketResponse.close() to discard non-close messages within its timeout window after sending close -- by lenard-mosys.
Related issues and pull requests on GitHub: #9506.
Fixed a deadlock that could occur while attempting to get a new connection slot after a timeout -- by bdraco.
The connector was not cancellation-safe.
Related issues and pull requests on GitHub: #9670, #9671.
Fixed the keep-alive connection pool to be FIFO instead of LIFO -- by bdraco.
Keep-alive connections are more likely to be reused before they disconnect.
Related issues and pull requests on GitHub: #9672.
Fixed the WebSocket flow control calculation undercounting with multi-byte data -- by bdraco.
Related issues and pull requests on GitHub: #9686.
Added strategy parameter to aiohttp.web.StreamResponse.enable_compression The value of this parameter is passed to the zlib.compressobj function, allowing people to use a more sufficient compression algorithm for their data served by aiohttp.web -- by shootkin
Related issues and pull requests on GitHub: #6257.
Added server_hostname parameter to ws_connect.
Related issues and pull requests on GitHub: #7941.
Exported ~aiohttp.ClientWSTimeout to top-level namespace -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8612.
Added secure/httponly/samesite parameters to .del_cookie() -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8956.
Updated ~aiohttp.ClientSession's auth logic to include default auth only if the request URL's origin matches _base_url; otherwise, the auth will not be included -- by MaximZemskov
Related issues and pull requests on GitHub: #8966, #9466.
Added proxy and proxy_auth parameters to ~aiohttp.ClientSession -- by meshya.
Related issues and pull requests on GitHub: #9207.
Added default_to_multipart parameter to FormData.
Related issues and pull requests on GitHub: #9335.
Added ~aiohttp.ClientWebSocketResponse.send_frame and ~aiohttp.web.WebSocketResponse.send_frame for WebSockets -- by bdraco.
Related issues and pull requests on GitHub: #9348.
Updated ~aiohttp.ClientSession to support paths in base_url parameter. base_url paths must end with a / -- by Cycloctane.
Related issues and pull requests on GitHub: #9530.
Improved performance of reading WebSocket messages with a Cython implementation -- by bdraco.
Related issues and pull requests on GitHub: #9543, #9554, #9556, #9558, #9636, #9649, #9781.
Added writer_limit to the ~aiohttp.web.WebSocketResponse to be able to adjust the limit before the writer forces the buffer to be drained -- by bdraco.
Related issues and pull requests on GitHub: #9572.
Added an ~aiohttp.abc.AbstractAccessLogger.enabled property to aiohttp.abc.AbstractAccessLogger to dynamically check if logging is enabled -- by bdraco.
Related issues and pull requests on GitHub: #9822.
Deprecate obsolete timeout: float and receive_timeout: Optional[float] in ~aiohttp.ClientSession.ws_connect. Change default websocket receive timeout from None to 10.0.
Related issues and pull requests on GitHub: #3945.
Dropped support for Python 3.8 -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8797.
Increased minimum yarl version to 1.17.0 -- by bdraco.
Related issues and pull requests on GitHub: #8909, #9079, #9305, #9574.
Removed the is_ipv6_address and is_ip4_address helpers are they are no longer used -- by bdraco.
Related issues and pull requests on GitHub: #9344.
Changed ClientRequest.connection_key to be a NamedTuple to improve client performance -- by bdraco.
Related issues and pull requests on GitHub: #9365.
Improved performance of the connector when a connection can be reused -- by bdraco.
If BaseConnector.connect has been subclassed and replaced with custom logic, the ceil_timeout must be added.
Related issues and pull requests on GitHub: #9600.
FlowControlDataQueue has been replaced with the WebSocketDataQueue -- by bdraco.
Related issues and pull requests on GitHub: #9685.
Changed ClientRequest.request_info to be a NamedTuple to improve client performance -- by bdraco.
Related issues and pull requests on GitHub: #9692.
Switched to using the propcache package for property caching -- by bdraco.
The propcache package is derived from the property caching code in yarl and has been broken out to avoid maintaining it for multiple projects.
Related issues and pull requests on GitHub: #9394.
Separated aiohttp.http_websocket into multiple files to make it easier to maintain -- by bdraco.
Related issues and pull requests on GitHub: #9542, #9552.
Changed diagram images generator from blockdiag to GraphViz. Generating documentation now requires the GraphViz executable to be included in $PATH or sphinx build configuration.
Related issues and pull requests on GitHub: #9359.
Added flake8 settings to avoid some forms of implicit concatenation. -- by booniepepper.
Related issues and pull requests on GitHub: #7731.
Enabled keep-alive support on proxies (which was originally disabled several years ago) -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8920.
Changed web entry point to not listen on TCP when only a Unix path is passed -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #9033.
Disabled automatic retries of failed requests in aiohttp.test_utils.TestClient's client session (which could potentially hide errors in tests) -- by ShubhAgarwal-dev.
Related issues and pull requests on GitHub: #9141.
Changed web keepalive_timeout default to around an hour in order to reduce race conditions on reverse proxies -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #9285.
Reduced memory required for stream objects created during the client request lifecycle -- by bdraco.
Related issues and pull requests on GitHub: #9407.
Improved performance of the client request lifecycle when there are no cookies -- by bdraco.
Related issues and pull requests on GitHub: #9470.
Improved performance of sending client requests when the writer can finish synchronously -- by bdraco.
Related issues and pull requests on GitHub: #9485.
Improved performance of serializing HTTP headers -- by bdraco.
Related issues and pull requests on GitHub: #9603.
Improved performance of the internal DataQueue -- by bdraco.
Related issues and pull requests on GitHub: #9659.
Improved performance of calling receive for WebSockets for the most common message types -- by bdraco.
Related issues and pull requests on GitHub: #9679.
Replace internal helper methods method_must_be_empty_body and status_code_must_be_empty_body with simple set lookups -- by bdraco.
Related issues and pull requests on GitHub: #9722.
Passing enable_cleanup_closed to aiohttp.TCPConnector is now ignored on Python 3.12.7+ and 3.13.1+ since the underlying bug that caused asyncio to leak SSL connections has been fixed upstream -- by bdraco.
Related issues and pull requests on GitHub: #9726, #9736.
Improved performance of aiohttp.BaseConnector when there is no limit_per_host -- by bdraco.
Related issues and pull requests on GitHub: #9756.
Improved performance of sending HTTP requests when there is no body -- by bdraco.
Related issues and pull requests on GitHub: #9757.
Improved performance of the WebsocketWriter when the protocol is not paused -- by bdraco.
Related issues and pull requests on GitHub: #9796.
Implemented zero copy writes for StreamWriter -- by bdraco.
Related issues and pull requests on GitHub: #9839.
Removals and backward incompatible breaking changes
Raise aiohttp.ServerFingerprintMismatch exception on client-side if request through http proxy with mismatching server fingerprint digest: aiohttp.ClientSession(headers=headers, connector=TCPConnector(ssl=aiohttp.Fingerprint(mismatch_digest), trust_env=True).request(...) -- by gangj.
Related issues and pull requests on GitHub: #6652.
Modified websocket aiohttp.ClientWebSocketResponse.receive_str, aiohttp.ClientWebSocketResponse.receive_bytes, aiohttp.web.WebSocketResponse.receive_str & aiohttp.web.WebSocketResponse.receive_bytes methods to raise new aiohttp.WSMessageTypeError exception, instead of generic TypeError, when websocket messages of incorrect types are received -- by ara-25.
Related issues and pull requests on GitHub: #6800.
Made TestClient.app a Generic so type checkers will know the correct type (avoiding unneeded client.app is not None checks) -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8977.
Authentication provided by a redirect now takes precedence over provided auth when making requests with the client -- by PLPeeters.
Related issues and pull requests on GitHub: #9436.
Fixed WebSocketResponse.close() to discard non-close messages within its timeout window after sending close -- by lenard-mosys.
Related issues and pull requests on GitHub: #9506.
Fixed a deadlock that could occur while attempting to get a new connection slot after a timeout -- by bdraco.
The connector was not cancellation-safe.
Related issues and pull requests on GitHub: #9670, #9671.
Fixed the keep-alive connection pool to be FIFO instead of LIFO -- by bdraco.
Keep-alive connections are more likely to be reused before they disconnect.
Related issues and pull requests on GitHub: #9672.
Fixed the WebSocket flow control calculation undercounting with multi-byte data -- by bdraco.
Related issues and pull requests on GitHub: #9686.
Added strategy parameter to aiohttp.web.StreamResponse.enable_compression The value of this parameter is passed to the zlib.compressobj function, allowing people to use a more sufficient compression algorithm for their data served by aiohttp.web -- by shootkin
Related issues and pull requests on GitHub: #6257.
Added server_hostname parameter to ws_connect.
Related issues and pull requests on GitHub: #7941.
Exported ~aiohttp.ClientWSTimeout to top-level namespace -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8612.
Added secure/httponly/samesite parameters to .del_cookie() -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8956.
Updated ~aiohttp.ClientSession's auth logic to include default auth only if the request URL's origin matches _base_url; otherwise, the auth will not be included -- by MaximZemskov
Related issues and pull requests on GitHub: #8966, #9466.
Added proxy and proxy_auth parameters to ~aiohttp.ClientSession -- by meshya.
Related issues and pull requests on GitHub: #9207.
Added default_to_multipart parameter to FormData.
Related issues and pull requests on GitHub: #9335.
Added ~aiohttp.ClientWebSocketResponse.send_frame and ~aiohttp.web.WebSocketResponse.send_frame for WebSockets -- by bdraco.
Related issues and pull requests on GitHub: #9348.
Updated ~aiohttp.ClientSession to support paths in base_url parameter. base_url paths must end with a / -- by Cycloctane.
Related issues and pull requests on GitHub: #9530.
Improved performance of reading WebSocket messages with a Cython implementation -- by bdraco.
Related issues and pull requests on GitHub: #9543, #9554, #9556, #9558, #9636, #9649, #9781.
Added writer_limit to the ~aiohttp.web.WebSocketResponse to be able to adjust the limit before the writer forces the buffer to be drained -- by bdraco.
Related issues and pull requests on GitHub: #9572.
Deprecate obsolete timeout: float and receive_timeout: Optional[float] in ~aiohttp.ClientSession.ws_connect. Change default websocket receive timeout from None to 10.0.
Related issues and pull requests on GitHub: #3945.
Dropped support for Python 3.8 -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8797.
Increased minimum yarl version to 1.17.0 -- by bdraco.
Related issues and pull requests on GitHub: #8909, #9079, #9305, #9574.
Removed the is_ipv6_address and is_ip4_address helpers are they are no longer used -- by bdraco.
Related issues and pull requests on GitHub: #9344.
Changed ClientRequest.connection_key to be a NamedTuple to improve client performance -- by bdraco.
Related issues and pull requests on GitHub: #9365.
Improved performance of the connector when a connection can be reused -- by bdraco.
If BaseConnector.connect has been subclassed and replaced with custom logic, the ceil_timeout must be added.
Related issues and pull requests on GitHub: #9600.
FlowControlDataQueue has been replaced with the WebSocketDataQueue -- by bdraco.
Related issues and pull requests on GitHub: #9685.
Changed ClientRequest.request_info to be a NamedTuple to improve client performance -- by bdraco.
Related issues and pull requests on GitHub: #9692.
Switched to using the propcache package for property caching -- by bdraco.
The propcache package is derived from the property caching code in yarl and has been broken out to avoid maintaining it for multiple projects.
Related issues and pull requests on GitHub: #9394.
Separated aiohttp.http_websocket into multiple files to make it easier to maintain -- by bdraco.
Related issues and pull requests on GitHub: #9542, #9552.
Changed diagram images generator from blockdiag to GraphViz. Generating documentation now requires the GraphViz executable to be included in $PATH or sphinx build configuration.
Related issues and pull requests on GitHub: #9359.
Added flake8 settings to avoid some forms of implicit concatenation. -- by booniepepper.
Related issues and pull requests on GitHub: #7731.
Enabled keep-alive support on proxies (which was originally disabled several years ago) -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8920.
Changed web entry point to not listen on TCP when only a Unix path is passed -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #9033.
Disabled automatic retries of failed requests in aiohttp.test_utils.TestClient's client session (which could potentially hide errors in tests) -- by ShubhAgarwal-dev.
Related issues and pull requests on GitHub: #9141.
Changed web keepalive_timeout default to around an hour in order to reduce race conditions on reverse proxies -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #9285.
Reduced memory required for stream objects created during the client request lifecycle -- by bdraco.
Related issues and pull requests on GitHub: #9407.
Improved performance of the client request lifecycle when there are no cookies -- by bdraco.
Related issues and pull requests on GitHub: #9470.
Improved performance of sending client requests when the writer can finish synchronously -- by bdraco.
Related issues and pull requests on GitHub: #9485.
Improved performance of serializing HTTP headers -- by bdraco.
Related issues and pull requests on GitHub: #9603.
Improved performance of the internal DataQueue -- by bdraco.
Related issues and pull requests on GitHub: #9659.
Improved performance of calling receive for WebSockets for the most common message types -- by bdraco.
Related issues and pull requests on GitHub: #9679.
Replace internal helper methods method_must_be_empty_body and status_code_must_be_empty_body with simple set lookups -- by bdraco.
Related issues and pull requests on GitHub: #9722.
Passing enable_cleanup_closed to aiohttp.TCPConnector is now ignored on Python 3.12.7+ and 3.13.1+ since the underlying bug that caused asyncio to leak SSL connections has been fixed upstream -- by bdraco.
Related issues and pull requests on GitHub: #9726, #9736.
Improved performance of aiohttp.BaseConnector when there is no limit_per_host -- by bdraco.
Related issues and pull requests on GitHub: #9756.
Improved performance of sending HTTP requests when there is no body -- by bdraco.
Related issues and pull requests on GitHub: #9757.
Removals and backward incompatible breaking changes
Raise aiohttp.ServerFingerprintMismatch exception on client-side if request through http proxy with mismatching server fingerprint digest: aiohttp.ClientSession(headers=headers, connector=TCPConnector(ssl=aiohttp.Fingerprint(mismatch_digest), trust_env=True).request(...) -- by gangj.
Related issues and pull requests on GitHub: #6652.
Modified websocket aiohttp.ClientWebSocketResponse.receive_str, aiohttp.ClientWebSocketResponse.receive_bytes, aiohttp.web.WebSocketResponse.receive_str & aiohttp.web.WebSocketResponse.receive_bytes methods to raise new aiohttp.WSMessageTypeError exception, instead of generic TypeError, when websocket messages of incorrect types are received -- by ara-25.
Related issues and pull requests on GitHub: #6800.
Made TestClient.app a Generic so type checkers will know the correct type (avoiding unneeded client.app is not None checks) -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8977.
Authentication provided by a redirect now takes precedence over provided auth when making requests with the client -- by PLPeeters.
Related issues and pull requests on GitHub: #9436.
Fixed WebSocketResponse.close() to discard non-close messages within its timeout window after sending close -- by lenard-mosys.
Related issues and pull requests on GitHub: #9506.
Fixed a deadlock that could occur while attempting to get a new connection slot after a timeout -- by bdraco.
The connector was not cancellation-safe.
Related issues and pull requests on GitHub: #9670, #9671.
Fixed the keep-alive connection pool to be FIFO instead of LIFO -- by bdraco.
Keep-alive connections are more likely to be reused before they disconnect.
Related issues and pull requests on GitHub: #9672.
Fixed the WebSocket flow control calculation undercounting with multi-byte data -- by bdraco.
Related issues and pull requests on GitHub: #9686.
Added strategy parameter to aiohttp.web.StreamResponse.enable_compression The value of this parameter is passed to the zlib.compressobj function, allowing people to use a more sufficient compression algorithm for their data served by aiohttp.web -- by shootkin
Related issues and pull requests on GitHub: #6257.
Added server_hostname parameter to ws_connect.
Related issues and pull requests on GitHub: #7941.
Exported ~aiohttp.ClientWSTimeout to top-level namespace -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8612.
Added secure/httponly/samesite parameters to .del_cookie() -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8956.
Updated ~aiohttp.ClientSession's auth logic to include default auth only if the request URL's origin matches _base_url; otherwise, the auth will not be included -- by MaximZemskov
Related issues and pull requests on GitHub: #8966, #9466.
Added proxy and proxy_auth parameters to ~aiohttp.ClientSession -- by meshya.
Related issues and pull requests on GitHub: #9207.
Added default_to_multipart parameter to FormData.
Related issues and pull requests on GitHub: #9335.
Added ~aiohttp.ClientWebSocketResponse.send_frame and ~aiohttp.web.WebSocketResponse.send_frame for WebSockets -- by bdraco.
Related issues and pull requests on GitHub: #9348.
Updated ~aiohttp.ClientSession to support paths in base_url parameter. base_url paths must end with a / -- by Cycloctane.
Related issues and pull requests on GitHub: #9530.
Improved performance of reading WebSocket messages with a Cython implementation -- by bdraco.
Related issues and pull requests on GitHub: #9543, #9554, #9556, #9558, #9636, #9649.
Added writer_limit to the ~aiohttp.web.WebSocketResponse to be able to adjust the limit before the writer forces the buffer to be drained -- by bdraco.
Related issues and pull requests on GitHub: #9572.
Deprecate obsolete timeout: float and receive_timeout: Optional[float] in ~aiohttp.ClientSession.ws_connect. Change default websocket receive timeout from None to 10.0.
Related issues and pull requests on GitHub: #3945.
Dropped support for Python 3.8 -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8797.
Increased minimum yarl version to 1.17.0 -- by bdraco.
Related issues and pull requests on GitHub: #8909, #9079, #9305, #9574.
Removed the is_ipv6_address and is_ip4_address helpers are they are no longer used -- by bdraco.
Related issues and pull requests on GitHub: #9344.
Changed ClientRequest.connection_key to be a NamedTuple to improve client performance -- by bdraco.
Related issues and pull requests on GitHub: #9365.
Improved performance of the connector when a connection can be reused -- by bdraco.
If BaseConnector.connect has been subclassed and replaced with custom logic, the ceil_timeout must be added.
Related issues and pull requests on GitHub: #9600.
Changed ClientRequest.request_info to be a NamedTuple to improve client performance -- by bdraco.
Related issues and pull requests on GitHub: #9692.
Switched to using the propcache package for property caching -- by bdraco.
The propcache package is derived from the property caching code in yarl and has been broken out to avoid maintaining it for multiple projects.
Related issues and pull requests on GitHub: #9394.
Separated aiohttp.http_websocket into multiple files to make it easier to maintain -- by bdraco.
Related issues and pull requests on GitHub: #9542, #9552.
Changed diagram images generator from blockdiag to GraphViz. Generating documentation now requires the GraphViz executable to be included in $PATH or sphinx build configuration.
Related issues and pull requests on GitHub: #9359.
Added flake8 settings to avoid some forms of implicit concatenation. -- by booniepepper.
Related issues and pull requests on GitHub: #7731.
Enabled keep-alive support on proxies (which was originally disabled several years ago) -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8920.
Changed web entry point to not listen on TCP when only a Unix path is passed -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #9033.
Disabled automatic retries of failed requests in aiohttp.test_utils.TestClient's client session (which could potentially hide errors in tests) -- by ShubhAgarwal-dev.
Related issues and pull requests on GitHub: #9141.
Changed web keepalive_timeout default to around an hour in order to reduce race conditions on reverse proxies -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #9285.
Reduced memory required for stream objects created during the client request lifecycle -- by bdraco.
Related issues and pull requests on GitHub: #9407.
Improved performance of the client request lifecycle when there are no cookies -- by bdraco.
Related issues and pull requests on GitHub: #9470.
Improved performance of sending client requests when the writer can finish synchronously -- by bdraco.
Related issues and pull requests on GitHub: #9485.
Improved performance of serializing HTTP headers -- by bdraco.
Related issues and pull requests on GitHub: #9603.
Improved performance of the internal DataQueue -- by bdraco.
Related issues and pull requests on GitHub: #9659.
Improved performance of calling receive for WebSockets for the most common message types -- by bdraco.
Related issues and pull requests on GitHub: #9679.
Replace internal helper methods method_must_be_empty_body and status_code_must_be_empty_body with simple set lookups -- by bdraco.
Related issues and pull requests on GitHub: #9722.
Passing enable_cleanup_closed to aiohttp.TCPConnector is now ignored on Python 3.12.7+ and 3.13.1+ since the underlying bug that caused asyncio to leak SSL connections has been fixed upstream -- by bdraco.
Related issues and pull requests on GitHub: #9726, #9736.
Improved performance of aiohttp.BaseConnector when there is no limit_per_host -- by bdraco.
Related issues and pull requests on GitHub: #9756.
Improved performance of sending HTTP requests when there is no body -- by bdraco.
Related issues and pull requests on GitHub: #9757.
Removals and backward incompatible breaking changes
Raise aiohttp.ServerFingerprintMismatch exception on client-side if request through http proxy with mismatching server fingerprint digest: aiohttp.ClientSession(headers=headers, connector=TCPConnector(ssl=aiohttp.Fingerprint(mismatch_digest), trust_env=True).request(...) -- by gangj.
Related issues and pull requests on GitHub: #6652.
Modified websocket aiohttp.ClientWebSocketResponse.receive_str, aiohttp.ClientWebSocketResponse.receive_bytes, aiohttp.web.WebSocketResponse.receive_str & aiohttp.web.WebSocketResponse.receive_bytes methods to raise new aiohttp.WSMessageTypeError exception, instead of generic TypeError, when websocket messages of incorrect types are received -- by ara-25.
Related issues and pull requests on GitHub: #6800.
Made TestClient.app a Generic so type checkers will know the correct type (avoiding unneeded client.app is not None checks) -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8977.
Authentication provided by a redirect now takes precedence over provided auth when making requests with the client -- by PLPeeters.
Related issues and pull requests on GitHub: #9436.
Fixed WebSocketResponse.close() to discard non-close messages within its timeout window after sending close -- by lenard-mosys.
Related issues and pull requests on GitHub: #9506.
Fixed a deadlock that could occur while attempting to get a new connection slot after a timeout -- by bdraco.
The connector was not cancellation-safe.
Related issues and pull requests on GitHub: #9670, #9671.
Fixed the keep-alive connection pool to be FIFO instead of LIFO -- by bdraco.
Keep-alive connections are more likely to be reused before they disconnect.
Related issues and pull requests on GitHub: #9672.
Fixed the WebSocket flow control calculation undercounting with multi-byte data -- by bdraco.
Related issues and pull requests on GitHub: #9686.
Added strategy parameter to aiohttp.web.StreamResponse.enable_compression The value of this parameter is passed to the zlib.compressobj function, allowing people to use a more sufficient compression algorithm for their data served by aiohttp.web -- by shootkin
Related issues and pull requests on GitHub: #6257.
Added server_hostname parameter to ws_connect.
Related issues and pull requests on GitHub: #7941.
Exported ~aiohttp.ClientWSTimeout to top-level namespace -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8612.
Added secure/httponly/samesite parameters to .del_cookie() -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8956.
Updated ~aiohttp.ClientSession's auth logic to include default auth only if the request URL's origin matches _base_url; otherwise, the auth will not be included -- by MaximZemskov
Related issues and pull requests on GitHub: #8966, #9466.
Added proxy and proxy_auth parameters to ~aiohttp.ClientSession -- by meshya.
Related issues and pull requests on GitHub: #9207.
Added default_to_multipart parameter to FormData.
Related issues and pull requests on GitHub: #9335.
Added ~aiohttp.ClientWebSocketResponse.send_frame and ~aiohttp.web.WebSocketResponse.send_frame for WebSockets -- by bdraco.
Related issues and pull requests on GitHub: #9348.
Updated ~aiohttp.ClientSession to support paths in base_url parameter. base_url paths must end with a / -- by Cycloctane.
Related issues and pull requests on GitHub: #9530.
Improved performance of reading WebSocket messages with a Cython implementation -- by bdraco.
Related issues and pull requests on GitHub: #9543, #9554, #9556, #9558, #9636, #9649.
Added writer_limit to the ~aiohttp.web.WebSocketResponse to be able to adjust the limit before the writer forces the buffer to be drained -- by bdraco.
Related issues and pull requests on GitHub: #9572.
Deprecate obsolete timeout: float and receive_timeout: Optional[float] in ~aiohttp.ClientSession.ws_connect. Change default websocket receive timeout from None to 10.0.
Related issues and pull requests on GitHub: #3945.
Dropped support for Python 3.8 -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8797.
Increased minimum yarl version to 1.17.0 -- by bdraco.
Related issues and pull requests on GitHub: #8909, #9079, #9305, #9574.
Removed the is_ipv6_address and is_ip4_address helpers are they are no longer used -- by bdraco.
Related issues and pull requests on GitHub: #9344.
Changed ClientRequest.connection_key to be a NamedTuple to improve client performance -- by bdraco.
Related issues and pull requests on GitHub: #9365.
Improved performance of the connector when a connection can be reused -- by bdraco.
If BaseConnector.connect has been subclassed and replaced with custom logic, the ceil_timeout must be added.
Related issues and pull requests on GitHub: #9600.
Changed ClientRequest.request_info to be a NamedTuple to improve client performance -- by bdraco.
Related issues and pull requests on GitHub: #9692.
Switched to using the propcache package for property caching -- by bdraco.
The propcache package is derived from the property caching code in yarl and has been broken out to avoid maintaining it for multiple projects.
Related issues and pull requests on GitHub: #9394.
Separated aiohttp.http_websocket into multiple files to make it easier to maintain -- by bdraco.
Related issues and pull requests on GitHub: #9542, #9552.
Changed diagram images generator from blockdiag to GraphViz. Generating documentation now requires the GraphViz executable to be included in $PATH or sphinx build configuration.
Related issues and pull requests on GitHub: #9359.
Added flake8 settings to avoid some forms of implicit concatenation. -- by booniepepper.
Related issues and pull requests on GitHub: #7731.
Enabled keep-alive support on proxies (which was originally disabled several years ago) -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8920.
Changed web entry point to not listen on TCP when only a Unix path is passed -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #9033.
Disabled automatic retries of failed requests in aiohttp.test_utils.TestClient's client session (which could potentially hide errors in tests) -- by ShubhAgarwal-dev.
Related issues and pull requests on GitHub: #9141.
Changed web keepalive_timeout default to around an hour in order to reduce race conditions on reverse proxies -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #9285.
Reduced memory required for stream objects created during the client request lifecycle -- by bdraco.
Related issues and pull requests on GitHub: #9407.
Improved performance of the client request lifecycle when there are no cookies -- by bdraco.
Related issues and pull requests on GitHub: #9470.
Improved performance of sending client requests when the writer can finish synchronously -- by bdraco.
Related issues and pull requests on GitHub: #9485.
Improved performance of serializing HTTP headers -- by bdraco.
Related issues and pull requests on GitHub: #9603.
Improved performance of the internal DataQueue -- by bdraco.
Related issues and pull requests on GitHub: #9659.
Improved performance of calling receive for WebSockets for the most common message types -- by bdraco.
Related issues and pull requests on GitHub: #9679.
Replace internal helper methods method_must_be_empty_body and status_code_must_be_empty_body with simple set lookups -- by bdraco.
Related issues and pull requests on GitHub: #9722.
Passing enable_cleanup_closed to aiohttp.TCPConnector is now ignored on Python 3.12.7+ and 3.13.1+ since the underlying bug that caused asyncio to leak SSL connections has been fixed upstream -- by bdraco.
Related issues and pull requests on GitHub: #9726, #9736.
Improved performance of aiohttp.BaseConnector when there is no limit_per_host -- by bdraco.
Related issues and pull requests on GitHub: #9756.
Improved performance of sending HTTP requests when there is no body -- by bdraco.
Related issues and pull requests on GitHub: #9757.
aiohttp 3.10.0 yarl 1.9.5 
aiohttp 3.11.0b0 yarl 1.17.0 
aiohttp 3.11.0b5 yarl 1.17.1 
Removals and backward incompatible breaking changes
Raise aiohttp.ServerFingerprintMismatch exception on client-side if request through http proxy with mismatching server fingerprint digest: aiohttp.ClientSession(headers=headers, connector=TCPConnector(ssl=aiohttp.Fingerprint(mismatch_digest), trust_env=True).request(...) -- by gangj.
Related issues and pull requests on GitHub: #6652.
Modified websocket aiohttp.ClientWebSocketResponse.receive_str, aiohttp.ClientWebSocketResponse.receive_bytes, aiohttp.web.WebSocketResponse.receive_str & aiohttp.web.WebSocketResponse.receive_bytes methods to raise new aiohttp.WSMessageTypeError exception, instead of generic TypeError, when websocket messages of incorrect types are received -- by ara-25.
Related issues and pull requests on GitHub: #6800.
Made TestClient.app a Generic so type checkers will know the correct type (avoiding unneeded client.app is not None checks) -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8977.
Authentication provided by a redirect now takes precedence over provided auth when making requests with the client -- by PLPeeters.
Related issues and pull requests on GitHub: #9436.
Fixed WebSocketResponse.close() to discard non-close messages within its timeout window after sending close -- by lenard-mosys.
Related issues and pull requests on GitHub: #9506.
Fixed a deadlock that could occur while attempting to get a new connection slot after a timeout -- by bdraco.
The connector was not cancellation-safe.
Related issues and pull requests on GitHub: #9670, #9671.
Fixed the keep-alive connection pool to be FIFO instead of LIFO -- by bdraco.
Keep-alive connections are more likely to be reused before they disconnect.
Related issues and pull requests on GitHub: #9672.
Fixed the WebSocket flow control calculation undercounting with multi-byte data -- by bdraco.
Related issues and pull requests on GitHub: #9686.
Added strategy parameter to aiohttp.web.StreamResponse.enable_compression The value of this parameter is passed to the zlib.compressobj function, allowing people to use a more sufficient compression algorithm for their data served by aiohttp.web -- by shootkin
Related issues and pull requests on GitHub: #6257.
Added server_hostname parameter to ws_connect.
Related issues and pull requests on GitHub: #7941.
Exported ~aiohttp.ClientWSTimeout to top-level namespace -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8612.
Added secure/httponly/samesite parameters to .del_cookie() -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8956.
Updated ~aiohttp.ClientSession's auth logic to include default auth only if the request URL's origin matches _base_url; otherwise, the auth will not be included -- by MaximZemskov
Related issues and pull requests on GitHub: #8966, #9466.
Added proxy and proxy_auth parameters to ~aiohttp.ClientSession -- by meshya.
Related issues and pull requests on GitHub: #9207.
Added default_to_multipart parameter to FormData.
Related issues and pull requests on GitHub: #9335.
Added ~aiohttp.ClientWebSocketResponse.send_frame and ~aiohttp.web.WebSocketResponse.send_frame for WebSockets -- by bdraco.
Related issues and pull requests on GitHub: #9348.
Updated ~aiohttp.ClientSession to support paths in base_url parameter. base_url paths must end with a / -- by Cycloctane.
Related issues and pull requests on GitHub: #9530.
Improved performance of reading WebSocket messages with a Cython implementation -- by bdraco.
Related issues and pull requests on GitHub: #9543, #9554, #9556, #9558, #9636, #9649.
Added writer_limit to the ~aiohttp.web.WebSocketResponse to be able to adjust the limit before the writer forces the buffer to be drained -- by bdraco.
Related issues and pull requests on GitHub: #9572.
Deprecate obsolete timeout: float and receive_timeout: Optional[float] in ~aiohttp.ClientSession.ws_connect. Change default websocket receive timeout from None to 10.0.
Related issues and pull requests on GitHub: #3945.
Dropped support for Python 3.8 -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8797.
Increased minimum yarl version to 1.17.0 -- by bdraco.
Related issues and pull requests on GitHub: #8909, #9079, #9305, #9574.
Removed the is_ipv6_address and is_ip4_address helpers are they are no longer used -- by bdraco.
Related issues and pull requests on GitHub: #9344.
Changed ClientRequest.connection_key to be a NamedTuple to improve client performance -- by bdraco.
Related issues and pull requests on GitHub: #9365.
Improved performance of the connector when a connection can be reused -- by bdraco.
If BaseConnector.connect has been subclassed and replaced with custom logic, the ceil_timeout must be added.
Related issues and pull requests on GitHub: #9600.
Changed ClientRequest.request_info to be a NamedTuple to improve client performance -- by bdraco.
Related issues and pull requests on GitHub: #9692.
Switched to using the propcache package for property caching -- by bdraco.
The propcache package is derived from the property caching code in yarl and has been broken out to avoid maintaining it for multiple projects.
Related issues and pull requests on GitHub: #9394.
Separated aiohttp.http_websocket into multiple files to make it easier to maintain -- by bdraco.
Related issues and pull requests on GitHub: #9542, #9552.
Changed diagram images generator from blockdiag to GraphViz. Generating documentation now requires the GraphViz executable to be included in $PATH or sphinx build configuration.
Related issues and pull requests on GitHub: #9359.
Added flake8 settings to avoid some forms of implicit concatenation. -- by booniepepper.
Related issues and pull requests on GitHub: #7731.
Enabled keep-alive support on proxies (which was originally disabled several years ago) -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8920.
Changed web entry point to not listen on TCP when only a Unix path is passed -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #9033.
Disabled automatic retries of failed requests in aiohttp.test_utils.TestClient's client session (which could potentially hide errors in tests) -- by ShubhAgarwal-dev.
Related issues and pull requests on GitHub: #9141.
Changed web keepalive_timeout default to around an hour in order to reduce race conditions on reverse proxies -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #9285.
Reduced memory required for stream objects created during the client request lifecycle -- by bdraco.
Related issues and pull requests on GitHub: #9407.
Improved performance of the client request lifecycle when there are no cookies -- by bdraco.
Related issues and pull requests on GitHub: #9470.
Improved performance of sending client requests when the writer can finish synchronously -- by bdraco.
Related issues and pull requests on GitHub: #9485.
Improved performance of serializing HTTP headers -- by bdraco.
Related issues and pull requests on GitHub: #9603.
Improved performance of the internal DataQueue -- by bdraco.
Related issues and pull requests on GitHub: #9659.
Improved performance of calling receive for WebSockets for the most common message types -- by bdraco.
Related issues and pull requests on GitHub: #9679.
aiohttp 3.10.0 yarl 1.9.5 
aiohttp 3.11.0b0 yarl 1.17.0 
aiohttp 3.11.0b4 yarl 1.17.1 
Removals and backward incompatible breaking changes
Raise aiohttp.ServerFingerprintMismatch exception on client-side if request through http proxy with mismatching server fingerprint digest: aiohttp.ClientSession(headers=headers, connector=TCPConnector(ssl=aiohttp.Fingerprint(mismatch_digest), trust_env=True).request(...) -- by gangj.
Related issues and pull requests on GitHub: #6652.
Modified websocket aiohttp.ClientWebSocketResponse.receive_str, aiohttp.ClientWebSocketResponse.receive_bytes, aiohttp.web.WebSocketResponse.receive_str & aiohttp.web.WebSocketResponse.receive_bytes methods to raise new aiohttp.WSMessageTypeError exception, instead of generic TypeError, when websocket messages of incorrect types are received -- by ara-25.
Related issues and pull requests on GitHub: #6800.
Made TestClient.app a Generic so type checkers will know the correct type (avoiding unneeded client.app is not None checks) -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8977.
Authentication provided by a redirect now takes precedence over provided auth when making requests with the client -- by PLPeeters.
Related issues and pull requests on GitHub: #9436.
Fixed a deadlock that could occur while attempting to get a new connection slot after a timeout -- by bdraco.
The connector was not cancellation-safe.
Related issues and pull requests on GitHub: #9670, #9671.
Fixed the keep-alive connection pool to be FIFO instead of LIFO -- by bdraco.
Keep-alive connections are more likely to be reused before they disconnect.
Related issues and pull requests on GitHub: #9672.
Added strategy parameter to aiohttp.web.StreamResponse.enable_compression The value of this parameter is passed to the zlib.compressobj function, allowing people to use a more sufficient compression algorithm for their data served by aiohttp.web -- by shootkin
Related issues and pull requests on GitHub: #6257.
Added server_hostname parameter to ws_connect.
Related issues and pull requests on GitHub: #7941.
Exported ~aiohttp.ClientWSTimeout to top-level namespace -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8612.
Added secure/httponly/samesite parameters to .del_cookie() -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8956.
Updated ~aiohttp.ClientSession's auth logic to include default auth only if the request URL's origin matches _base_url; otherwise, the auth will not be included -- by MaximZemskov
Related issues and pull requests on GitHub: #8966, #9466.
Added proxy and proxy_auth parameters to ~aiohttp.ClientSession -- by meshya.
Related issues and pull requests on GitHub: #9207.
Added default_to_multipart parameter to FormData.
Related issues and pull requests on GitHub: #9335.
Added ~aiohttp.ClientWebSocketResponse.send_frame and ~aiohttp.web.WebSocketResponse.send_frame for WebSockets -- by bdraco.
Related issues and pull requests on GitHub: #9348.
Updated ~aiohttp.ClientSession to support paths in base_url parameter. base_url paths must end with a / -- by Cycloctane.
Related issues and pull requests on GitHub: #9530.
Improved performance of reading WebSocket messages with a Cython implementation -- by bdraco.
Related issues and pull requests on GitHub: #9543, #9554, #9556, #9558, #9636, #9649.
Added writer_limit to the ~aiohttp.web.WebSocketResponse to be able to adjust the limit before the writer forces the buffer to be drained -- by bdraco.
Related issues and pull requests on GitHub: #9572.
Deprecate obsolete timeout: float and receive_timeout: Optional[float] in ~aiohttp.ClientSession.ws_connect. Change default websocket receive timeout from None to 10.0.
Related issues and pull requests on GitHub: #3945.
Dropped support for Python 3.8 -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8797.
Increased minimum yarl version to 1.17.0 -- by bdraco.
Related issues and pull requests on GitHub: #8909, #9079, #9305, #9574.
Removed the is_ipv6_address and is_ip4_address helpers are they are no longer used -- by bdraco.
Related issues and pull requests on GitHub: #9344.
Changed ClientRequest.connection_key to be a NamedTuple to improve client performance -- by bdraco.
Related issues and pull requests on GitHub: #9365.
Improved performance of the connector when a connection can be reused -- by bdraco.
If BaseConnector.connect has been subclassed and replaced with custom logic, the ceil_timeout must be added.
Related issues and pull requests on GitHub: #9600.
Switched to using the propcache package for property caching -- by bdraco.
The propcache package is derived from the property caching code in yarl and has been broken out to avoid maintaining it for multiple projects.
Related issues and pull requests on GitHub: #9394.
Separated aiohttp.http_websocket into multiple files to make it easier to maintain -- by bdraco.
Related issues and pull requests on GitHub: #9542, #9552.
Changed diagram images generator from blockdiag to GraphViz. Generating documentation now requires the GraphViz executable to be included in $PATH or sphinx build configuration.
Related issues and pull requests on GitHub: #9359.
Added flake8 settings to avoid some forms of implicit concatenation. -- by booniepepper.
Related issues and pull requests on GitHub: #7731.
Enabled keep-alive support on proxies (which was originally disabled several years ago) -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #8920.
Changed web entry point to not listen on TCP when only a Unix path is passed -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #9033.
Disabled automatic retries of failed requests in aiohttp.test_utils.TestClient's client session (which could potentially hide errors in tests) -- by ShubhAgarwal-dev.
Related issues and pull requests on GitHub: #9141.
Changed web keepalive_timeout default to around an hour in order to reduce race conditions on reverse proxies -- by Dreamsorcerer.
Related issues and pull requests on GitHub: #9285.
Reduced memory required for stream objects created during the client request lifecycle -- by bdraco.
Related issues and pull requests on GitHub: #9407.
Improved performance of the client request lifecycle when there are no cookies -- by bdraco.
Related issues and pull requests on GitHub: #9470.
Improved performance of sending client requests when the writer can finish synchronously -- by bdraco.
Related issues and pull requests on GitHub: #9485.
Improved performance of serializing HTTP headers -- by bdraco.
Related issues and pull requests on GitHub: #9603.
Improved performance of the internal DataQueue -- by bdraco.
Related issues and pull requests on GitHub: #9659.
Improved performance of calling receive for WebSockets for the most common message types -- by bdraco.
Related issues and pull requests on GitHub: #9679.
## Performance
WebSocket reader performance has improved ~10% since b2
aiohttp 3.10.0 yarl 1.9.5 
aiohttp 3.11.0b0 yarl 1.17.0 
aiohttp 3.11.0b1 yarl 1.17.1 (no change from b1/b2) 
Your coding agent can read these notes before it upgrades. Set up the MCP server →