🗃️ Turn-key solution for signed & secure file-uploads to an S3 compliant storage service such as R2, AWS, or Minio. Built for Next.js. Generates signed URLs for uploading files directly to your storage service and optionally integrates with a database to store additional metadata about your files.
MIT License
83
stars
4
forks
source link
chore(deps): bump wrangler from 3.18.0 to 3.22.4 in /examples/next-upload-example #34
#46994b4c1416 Thanks @mrbbot! - fix: prevent repeated reloads with circular service bindings
wrangler@3.19.0 introduced a bug where starting multiple wrangler dev sessions with service bindings to each other resulted in a reload loop. This change ensures Wrangler only reloads when dependent wrangler dev sessions start/stop.
wrangler@3.22.3
Patch Changes
#469393e88c43 Thanks @mrbbot! - fix: ensure wrangler dev exits with code 0 on clean exit
Previously, wrangler dev would exit with a non-zero exit code when pressing CTRL+C or x. This change ensures wrangler exits with code 0 in these cases.
#4630037de5ec Thanks @petebacondarwin! - fix: ensure User Worker gets the correct Host header in wrangler dev local mode
Some full-stack frameworks, such as Next.js, check that the Host header for a server
side action request matches the host where the application is expected to run.
In wrangler dev we have a Proxy Worker in between the browser and the actual User Worker.
This Proxy Worker is forwarding on the request from the browser, but then the actual User
Worker is running on a different host:port combination than that which the browser thinks
it should be on. This was causing the framework to think the request is malicious and blocking
it.
Now we update the request's Host header to that passed from the Proxy Worker in a custom MF-Original-Url
header, but only do this if the request also contains a shared secret between the Proxy Worker
and User Worker, which is passed via the MF-Proxy-Shared-Secret header. This last feature is to
prevent a malicious website from faking the Host header in a request directly to the User Worker.
Previously, pressing CTRL+C or x when running wrangler pages dev wouldn't actually exit wrangler. You'd need to press CTRL+C a second time to exit the process. This change ensures wrangler exits the first time.
#4696624084c4 Thanks @mrbbot! - fix: include additional modules in largest dependencies warning
If your Worker fails to deploy because it's too large, Wrangler will display of list of your Worker's largest dependencies. Previously, this just included JavaScript dependencies. This change ensures additional module dependencies (e.g. WebAssembly, text blobs, etc.) are included when computing this list.
#46994b4c1416 Thanks @mrbbot! - fix: prevent repeated reloads with circular service bindings
wrangler@3.19.0 introduced a bug where starting multiple wrangler dev sessions with service bindings to each other resulted in a reload loop. This change ensures Wrangler only reloads when dependent wrangler dev sessions start/stop.
3.22.3
Patch Changes
#469393e88c43 Thanks @mrbbot! - fix: ensure wrangler dev exits with code 0 on clean exit
Previously, wrangler dev would exit with a non-zero exit code when pressing CTRL+C or x. This change ensures wrangler exits with code 0 in these cases.
#4630037de5ec Thanks @petebacondarwin! - fix: ensure User Worker gets the correct Host header in wrangler dev local mode
Some full-stack frameworks, such as Next.js, check that the Host header for a server
side action request matches the host where the application is expected to run.
In wrangler dev we have a Proxy Worker in between the browser and the actual User Worker.
This Proxy Worker is forwarding on the request from the browser, but then the actual User
Worker is running on a different host:port combination than that which the browser thinks
it should be on. This was causing the framework to think the request is malicious and blocking
it.
Now we update the request's Host header to that passed from the Proxy Worker in a custom MF-Original-Url
header, but only do this if the request also contains a shared secret between the Proxy Worker
and User Worker, which is passed via the MF-Proxy-Shared-Secret header. This last feature is to
prevent a malicious website from faking the Host header in a request directly to the User Worker.
Previously, pressing CTRL+C or x when running wrangler pages dev wouldn't actually exit wrangler. You'd need to press CTRL+C a second time to exit the process. This change ensures wrangler exits the first time.
#4696624084c4 Thanks @mrbbot! - fix: include additional modules in largest dependencies warning
If your Worker fails to deploy because it's too large, Wrangler will display of list of your Worker's largest dependencies. Previously, this just included JavaScript dependencies. This change ensures additional module dependencies (e.g. WebAssembly, text blobs, etc.) are included when computing this list.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/TimMikeladze/next-upload/network/alerts).
Bumps wrangler from 3.18.0 to 3.22.4.
Release notes
Sourced from wrangler's releases.
... (truncated)
Changelog
Sourced from wrangler's changelog.
... (truncated)
Commits
86d90fa
Version Packages (#4708)4b4c141
fix: prevent repeated reloads with circular service bindings (#4699)ff19681
[wrangler] Add better printing for complex unsafe metadata (#2820)c2c35a5
Version Packages (#4691)93e88c4
[wrangler] fix: ensurewrangler (pages) dev
exits cleanly (#4693)624084c
fix: include additional modules inlargest dependencies
warning (#4696)0f8a03c
fix: ensure API failures withoutmessages
logged correctly (#4695)037de5e
fix: miniflare now sets the "Host" header to match the upstream URL (#4630)259b5a6
Version Packages (#4655)4233e51
[wrangler] fix: apply source mapping to deployment validation errors (#4600)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show