Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
43 commits
Select commit Hold shift + click to select a range
e88c297
chore(deps): bump actions/deploy-pages from 4 to 5 (#1038)
dependabot[bot] Sep 15, 2026
074e6b3
chore(deps): bump actions/setup-node from 4 to 7 (#1040)
dependabot[bot] Sep 15, 2026
476c593
chore(deps): bump azure/login from 2 to 3 (#1039)
dependabot[bot] Sep 15, 2026
d1ef4bd
chore(deps): bump actions/download-artifact from 4 to 8 (#1041)
dependabot[bot] Sep 15, 2026
b40ad85
chore(deps): bump actions/cache from 4 to 6 (#1042)
dependabot[bot] Sep 15, 2026
ab6fe34
fix(inspector): accept * and localhost binds; recover after invalid a…
justcoding121 Sep 16, 2026
ff2c344
fix(inspector): treat port and AutoResponder status as text, not int …
justcoding121 Sep 16, 2026
d11d03d
fix(http2/h3): principal arch review — ServerHello delay, CONNECT HPA…
justcoding121 Sep 16, 2026
8ac45fa
docs: protocol hardening backlog from 2026-09 principal-arch review
justcoding121 Sep 16, 2026
bb9abd8
fix(qpack): fail-fast on dynamic-table refs when Base decoding unimpl…
justcoding121 Sep 16, 2026
c35d485
Reclassify intentional design choices in the protocol backlog; mark a…
justcoding121 Sep 16, 2026
bec25e5
Add Http2RelayValidation policy family for opt-in HPACK semantic vali…
justcoding121 Sep 16, 2026
cf0f607
Gate the H2 compressed relay path on the Http2RelayValidation policy;…
justcoding121 Sep 16, 2026
f258834
Use the highest admitted stream ID in all GOAWAY Last-Stream-ID fields
justcoding121 Sep 16, 2026
71be2ca
Reject SETTINGS, PING and GOAWAY frames that arrive on a non-zero str…
justcoding121 Sep 16, 2026
6a6cab6
Treat oversized frame padding as a connection error instead of silent…
justcoding121 Sep 16, 2026
7b1575e
Correctly classify HTTP/2 requests that carry :method but no :path
justcoding121 Sep 16, 2026
ddf6afc
Reject SETTINGS_ENABLE_PUSH values greater than 1
justcoding121 Sep 16, 2026
56c6bbc
Reject HTTP/1 obs-fold header continuations per RFC 9112
justcoding121 Sep 16, 2026
b162f89
Run async certificate validation on a background thread to prevent sy…
justcoding121 Sep 16, 2026
a46f9e7
Signal H3_MISSING_SETTINGS when an origin control stream opens with t…
justcoding121 Sep 16, 2026
d7a0e2f
Fix use-after-dispose of the QUIC connection cancellation token
justcoding121 Sep 16, 2026
4b6c7df
Require :path on HTTP/3 requests that are not CONNECT
justcoding121 Sep 16, 2026
9745fc4
Read and forward HTTP/3 response trailers so gRPC status codes reach …
justcoding121 Sep 16, 2026
3144093
Implement QPACK dynamic table relative and post-base index decoding p…
justcoding121 Sep 16, 2026
19f1710
Update protocol documentation, security notes and performance guidance
justcoding121 Sep 16, 2026
02a44f3
Align QPACK coverage tests with Base-relative dynamic index decoding
justcoding121 Sep 16, 2026
d23a111
Remove backlog and packaging follow-up progress docs from the repo
justcoding121 Sep 16, 2026
2385f7c
Align tests with PROTOCOL_ERROR framing and isolate upstream NTLM ass…
justcoding121 Sep 16, 2026
8bfa785
Clear Sonar code smells and ship Http2RelayValidation PublicAPI.
justcoding121 Sep 16, 2026
8c315cc
Update documentation
github-actions[bot] Sep 16, 2026
6012935
Clear remaining new-code Sonar smells on protocol helpers.
justcoding121 Sep 16, 2026
8869e81
Opt cert-validation Task.Run out of session cancellation.
justcoding121 Sep 16, 2026
bbd2743
Publish RPS wiki/charts from full Win/Linux/Mac suite @ 8bfa7852.
justcoding121 Sep 16, 2026
8408d52
Clear practical RPS chart legends without reordering arms.
justcoding121 Sep 16, 2026
3dea0f5
Remove redundant wiki H1s that duplicate GitHub page titles.
justcoding121 Sep 16, 2026
deb0a04
Refresh Performance.md prose ratios to match the 8bfa7852 suite.
justcoding121 Sep 16, 2026
af37e0f
Fix Inspector DecryptOnlyHosts wiring and tunnel byte-counter race.
justcoding121 Sep 16, 2026
1f2b153
chore(release): bump product version to 7.0.11 for the next beta/GA cut.
justcoding121 Sep 16, 2026
f46ac26
fix(sonar): exclude H2 relay header and H3 Quic trailer seams from co…
justcoding121 Sep 16, 2026
535c704
fix(test): wait for RotateCa elevate path to leave the busy trust sta…
justcoding121 Sep 16, 2026
a57dee6
tests: fix flaky KeepAliveHappyPath first-chance exception test
justcoding121 Sep 17, 2026
75c4a73
fix(inspector): avoid TaskCanceledException race in TryCompleteMacSsl…
justcoding121 Sep 17, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/workflows/deploy-website.yml
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@ jobs:
steps:
- uses: actions/checkout@v6

- uses: actions/setup-node@v4
- uses: actions/setup-node@v7
with:
node-version: '22'
cache: npm
Expand Down Expand Up @@ -134,4 +134,4 @@ jobs:
steps:
- name: Deploy to GitHub Pages
id: deployment
uses: actions/deploy-pages@v4
uses: actions/deploy-pages@v5
2 changes: 1 addition & 1 deletion .github/workflows/dotnetcore.yml
Original file line number Diff line number Diff line change
Expand Up @@ -91,7 +91,7 @@ jobs:
/d:sonar.token="$env:SONAR_TOKEN"
/d:sonar.cs.vscoveragexml.reportsPaths="coverage/coverage.xml"
/d:sonar.exclusions="**/docs/**,**/examples/**,**/benchmarks/**,**/tools/**,**/*.axaml,**/website/**,**/.github/**"
/d:sonar.coverage.exclusions="**/examples/**,**/benchmarks/**,**/docs/**,**/Http3/Http3OriginBridge.cs,**/Http3/Http3OriginClientSession.cs,**/Handlers/Http11ToHttp2BridgeHandler.cs,**/Handlers/H1TerminateFastForward.cs,**/Titanium.Plus/Dashboard/**,**/Titanium.Inspector/Views/**,**/Titanium.Inspector/ViewModels/MainWindowViewModel.Trust.cs,**/Titanium.Inspector/Services/AppContainerLoopback.cs,**/Titanium.Inspector/Services/AvaloniaStatusNotifier.cs,**/Titanium.Inspector/Services/DesktopShell.cs,**/Titanium.Inspector/App.axaml.cs,**/Titanium.Inspector/Program.cs,**/Titanium.Inspector/InspectorAppFactory.cs,**/Titanium.Inspector/Services/UpdateService.cs,**/Titanium.Cli/Program.cs,**/Titanium.Cli/AsyncConsole.cs,**/Titanium.Cli/Http3/Http3DepsCommand.cs,**/Titanium.Cli/Updates/VersionAndUpdateCommands.cs,**/Titanium.Cli/Certificates/CertificateBootstrap.cs,**/Titanium.Plus/Discovery/**,**/Titanium.Plus/Security/**,**/Titanium.Plus/State/**,**/Titanium.Plus/Resilience/**,**/Titanium.Plus/PlusLog.cs,**/Titanium.Web.Proxy/Helpers/LinuxSystemProxyBackend.cs,**/Titanium.Web.Proxy/Helpers/MacOsSystemProxyBackend.cs,**/Titanium.Web.Proxy/Helpers/IElevationPrompt.cs,**/Titanium.Web.Proxy/Helpers/IProcessRunner.cs,**/Titanium.Web.Proxy/Certificates/FirefoxCertificateTrust.cs"
/d:sonar.coverage.exclusions="**/examples/**,**/benchmarks/**,**/docs/**,**/Http3/Http3OriginBridge.cs,**/Http3/Http3OriginBridge.Quic.cs,**/Http3/Http3OriginClientSession.cs,**/Http2/Http2Helper.Copy.Headers.cs,**/Handlers/Http11ToHttp2BridgeHandler.cs,**/Handlers/H1TerminateFastForward.cs,**/Titanium.Plus/Dashboard/**,**/Titanium.Inspector/Views/**,**/Titanium.Inspector/ViewModels/MainWindowViewModel.Trust.cs,**/Titanium.Inspector/Services/AppContainerLoopback.cs,**/Titanium.Inspector/Services/AvaloniaStatusNotifier.cs,**/Titanium.Inspector/Services/DesktopShell.cs,**/Titanium.Inspector/App.axaml.cs,**/Titanium.Inspector/Program.cs,**/Titanium.Inspector/InspectorAppFactory.cs,**/Titanium.Inspector/Services/UpdateService.cs,**/Titanium.Cli/Program.cs,**/Titanium.Cli/AsyncConsole.cs,**/Titanium.Cli/Http3/Http3DepsCommand.cs,**/Titanium.Cli/Updates/VersionAndUpdateCommands.cs,**/Titanium.Cli/Certificates/CertificateBootstrap.cs,**/Titanium.Plus/Discovery/**,**/Titanium.Plus/Security/**,**/Titanium.Plus/State/**,**/Titanium.Plus/Resilience/**,**/Titanium.Plus/PlusLog.cs,**/Titanium.Web.Proxy/Helpers/LinuxSystemProxyBackend.cs,**/Titanium.Web.Proxy/Helpers/MacOsSystemProxyBackend.cs,**/Titanium.Web.Proxy/Helpers/IElevationPrompt.cs,**/Titanium.Web.Proxy/Helpers/IProcessRunner.cs,**/Titanium.Web.Proxy/Certificates/FirefoxCertificateTrust.cs"

- name: Build for SonarCloud analysis
if: env.SONAR_TOKEN != '' && steps.sonar_begin.outcome == 'success'
Expand Down
12 changes: 6 additions & 6 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -187,7 +187,7 @@ jobs:
- uses: actions/setup-dotnet@v5
with:
dotnet-version: '10.0.x'
- uses: actions/cache@v4
- uses: actions/cache@v6
with:
path: tools/packaging/.cache/http3-natives
key: http3-natives-${{ hashFiles('tools/packaging/http3-native.lock.json') }}-${{ matrix.rid }}
Expand All @@ -211,7 +211,7 @@ jobs:
./tools/packaging/bundle-http3-native.ps1 -Rid $rid -PublishDir $out
- name: Azure login (OIDC)
if: matrix.rid == 'win-x64'
uses: azure/login@v2
uses: azure/login@v3
with:
client-id: ${{ secrets.AZURE_CLIENT_ID }}
tenant-id: ${{ secrets.AZURE_TENANT_ID }}
Expand Down Expand Up @@ -367,7 +367,7 @@ jobs:
- uses: actions/setup-dotnet@v5
with:
dotnet-version: '10.0.x'
- uses: actions/cache@v4
- uses: actions/cache@v6
with:
path: tools/packaging/.cache/http3-natives
key: http3-natives-${{ hashFiles('tools/packaging/http3-native.lock.json') }}-${{ matrix.rid }}
Expand Down Expand Up @@ -398,7 +398,7 @@ jobs:
}
- name: Azure login (OIDC)
if: matrix.rid == 'win-x64'
uses: azure/login@v2
uses: azure/login@v3
with:
client-id: ${{ secrets.AZURE_CLIENT_ID }}
tenant-id: ${{ secrets.AZURE_TENANT_ID }}
Expand Down Expand Up @@ -526,7 +526,7 @@ jobs:
- rid: linux-musl-x64
container: alpine:3.24
steps:
- uses: actions/download-artifact@v4
- uses: actions/download-artifact@v8
with:
name: cli-${{ matrix.rid }}
path: dist
Expand Down Expand Up @@ -624,7 +624,7 @@ jobs:
- uses: actions/checkout@v6
with:
fetch-depth: 0
- uses: actions/download-artifact@v4
- uses: actions/download-artifact@v8
with:
path: artifacts
- name: Attach MIT NuGet SBOM when present
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/rps-saturation.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# Manual saturation RPS lab on GitHub-hosted VMs (not a job container).
# Manual saturation RPS lab on GitHub-hosted VMs (not a job container).
# Maintainers run this, then paste median numbers into wiki/Performance.md.
# Not a per-PR gate; not comparable to dedicated-server blog posts.
#
Expand Down Expand Up @@ -380,7 +380,7 @@ jobs:
# macOS uses Homebrew (typically native USE_QUIC) with a 3.2 osx source fallback.
- name: Cache HAProxy QUIC prefix
if: runner.os == 'Linux'
uses: actions/cache@v4
uses: actions/cache@v6
with:
path: |
${{ runner.temp }}/haproxy-quic
Expand Down Expand Up @@ -470,7 +470,7 @@ jobs:

- name: Cache HAProxy QUIC prefix (macOS)
if: runner.os == 'macOS'
uses: actions/cache@v4
uses: actions/cache@v6
with:
path: ${{ runner.temp }}/haproxy-quic
key: haproxy-3.2.23-quic-osx-x64
Expand Down
22 changes: 22 additions & 0 deletions docs/api/Titanium.Web.Proxy.Options.PolicyFamily.html
Original file line number Diff line number Diff line change
Expand Up @@ -157,6 +157,28 @@ <h3 id="fields">Fields
<td id="Titanium_Web_Proxy_Options_PolicyFamily_Http2AbuseBudget">Http2AbuseBudget</td>
<td><p>HTTP/2 abuse budgets: the open-header-block CONTINUATION frame-count/wall-clock bound and
the peer-initiated incomplete-stream-reset budget.</p>
</td>
</tr>
<tr>
<td id="Titanium_Web_Proxy_Options_PolicyFamily_Http2RelayValidation">Http2RelayValidation</td>
<td><p>Whether HPACK header blocks on the H2↔H2 compressed-relay path
(<code>httpInterceptionEnabled = false</code>) are semantically validated per RFC 9113 §8.3.
Unlike framing (always enforced, no Observe action), header semantics can be logged
without corrupting connection state.</p>
<p>
<a class="xref" href="Titanium.Web.Proxy.Options.PolicyMode.html#Titanium_Web_Proxy_Options_PolicyMode_Disabled">Disabled</a> (default on <a class="xref" href="Titanium.Web.Proxy.Options.ProxyProfile.html#Titanium_Web_Proxy_Options_ProxyProfile_Balanced">Balanced</a>)
skips HPACK decode entirely — maximum throughput when upstream peers are trusted.
</p>
<p>
<a class="xref" href="Titanium.Web.Proxy.Options.PolicyMode.html#Titanium_Web_Proxy_Options_PolicyMode_Observe">Observe</a> decodes and records semantic violations without
rejecting the stream. Does not mutate headers, so the compressed-relay
<code>MutationCount</code> fast path is unaffected when the family is Disabled.
</p>
<p>
<a class="xref" href="Titanium.Web.Proxy.Options.PolicyMode.html#Titanium_Web_Proxy_Options_PolicyMode_Enforce">Enforce</a> (default on <a class="xref" href="Titanium.Web.Proxy.Options.ProxyProfile.html#Titanium_Web_Proxy_Options_ProxyProfile_PublicFacing">PublicFacing</a>
and <a class="xref" href="Titanium.Web.Proxy.Options.ProxyPolicyModes.html#Titanium_Web_Proxy_Options_ProxyPolicyModes_AllEnforce">AllEnforce</a>) decodes and sends
<code>GOAWAY(PROTOCOL_ERROR)</code> on violations.
</p>
</td>
</tr>
</tbody>
Expand Down
Loading
Loading