Update dependency aiohttp to v3.13.0 #3
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "renovate/aiohttp-3.x"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This MR contains the following updates:
==3.8.3->==3.13.0Release Notes
aio-libs/aiohttp (aiohttp)
v3.13.0Compare Source
===================
Features
Added support for Python 3.14.
Related issues and pull requests on GitHub:
:issue:
10851, :issue:10872.Added support for free-threading in Python 3.14+ -- by :user:
kumaraditya303.Related issues and pull requests on GitHub:
:issue:
11466, :issue:11464.Added support for Zstandard (aka Zstd) compression
-- by :user:
KGuillaume-chaps.Related issues and pull requests on GitHub:
:issue:
11161.Added
StreamReader.total_raw_bytesto check the number of bytes downloaded-- by :user:
robpats.Related issues and pull requests on GitHub:
:issue:
11483.Bug fixes
Fixed pytest plugin to not use deprecated :py:mod:
asynciopolicy APIs.Related issues and pull requests on GitHub:
:issue:
10851.Updated
Content-Dispositionheader parsing to handle trailing semicolons and empty parts-- by :user:
PLPeeters.Related issues and pull requests on GitHub:
:issue:
11243.Fixed saved
CookieJarfailing to be loaded if cookies havepartitionedflag whenhttp.cookiedoes not have partitioned cookies supports. -- by :user:Cycloctane.Related issues and pull requests on GitHub:
:issue:
11523.Improved documentation
Added
Wireupto third-party libraries -- by :user:maldoinc.Related issues and pull requests on GitHub:
:issue:
11233.Packaging updates and notes for downstreams
The
blockbustertest dependency is now optional; the corresponding test fixture is disabled when it is unavailable-- by :user:
musicinybrain.Related issues and pull requests on GitHub:
:issue:
11363.Added
riscv64build to releases -- by :user:eshattow.Related issues and pull requests on GitHub:
:issue:
11425.Contributor-facing changes
Fixed
test_send_compress_textfailing when alternative zlib implementationis used. (
zlib-ngin python 3.14 windows build) -- by :user:Cycloctane.Related issues and pull requests on GitHub:
:issue:
11546.v3.12.15Compare Source
====================
Bug fixes
Fixed :class:
~aiohttp.DigestAuthMiddlewareto preserve the algorithm case from the server's challenge in the authorization response. This improves compatibility with servers that perform case-sensitive algorithm matching (e.g., servers expectingalgorithm=MD5-sessinstead ofalgorithm=MD5-SESS)-- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
11352.Improved documentation
Remove outdated contents of
aiohttp-devtoolsandaiohttp-swaggerfrom Web_advanced docs.
-- by :user:
CycloctaneRelated issues and pull requests on GitHub:
:issue:
11347.Packaging updates and notes for downstreams
Started including the
llhttp:file:LICENSEfile in wheels by addingvendor/llhttp/LICENSEtolicense-filesin :file:setup.cfg-- by :user:threexc.Related issues and pull requests on GitHub:
:issue:
11226.Contributor-facing changes
Updated a regex in
test_aiohttp_request_coroutinefor Python 3.14.Related issues and pull requests on GitHub:
:issue:
11271.v3.12.14Compare Source
====================
Bug fixes
Fixed file uploads failing with HTTP 422 errors when encountering 307/308 redirects, and 301/302 redirects for non-POST methods, by preserving the request body when appropriate per :rfc:
9110#section-15.4.3-3.1-- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
11270.Fixed :py:meth:
ClientSession.close() <aiohttp.ClientSession.close>hanging indefinitely when using HTTPS requests through HTTP proxies -- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
11273.Bumped minimum version of aiosignal to 1.4+ to resolve typing issues -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
11280.Features
Added initial trailer parsing logic to Python HTTP parser -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
11269.Improved documentation
Clarified exceptions raised by
WebSocketResponse.send_frameet al.-- by :user:
DoctorJohn.Related issues and pull requests on GitHub:
:issue:
11234.v3.12.13Compare Source
====================
Bug fixes
Fixed auto-created :py:class:
~aiohttp.TCPConnectornot using the session's event loop when :py:class:~aiohttp.ClientSessionis created without an explicit connector -- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
11147.v3.12.12Compare Source
====================
Bug fixes
Fixed cookie unquoting to properly handle octal escape sequences in cookie values (e.g.,
\012for newline) by vendoring the correct_unquoteimplementation from Python'shttp.cookiesmodule -- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
11173.Fixed
Cookieheader parsing to treat attribute names as regular cookies per :rfc:6265#section-5.4-- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
11178.v3.12.11Compare Source
====================
Features
Improved SSL connection handling by changing the default
ssl_shutdown_timeoutfrom
0.1to0seconds. SSL connections now use Python's default gracefulshutdown during normal operation but are aborted immediately when the connector
is closed, providing optimal behavior for both cases. Also added support for
ssl_shutdown_timeout=0on all Python versions. Previously, this value wasrejected on Python 3.11+ and ignored on earlier versions. Non-zero values on
Python < 3.11 now trigger a
RuntimeWarning-- by :user:bdraco.The
ssl_shutdown_timeoutparameter is now deprecated and will be removed inaiohttp 4.0 as there is no clear use case for changing the default.
Related issues and pull requests on GitHub:
:issue:
11148.Deprecations (removal in next major release)
Improved SSL connection handling by changing the default
ssl_shutdown_timeoutfrom
0.1to0seconds. SSL connections now use Python's default gracefulshutdown during normal operation but are aborted immediately when the connector
is closed, providing optimal behavior for both cases. Also added support for
ssl_shutdown_timeout=0on all Python versions. Previously, this value wasrejected on Python 3.11+ and ignored on earlier versions. Non-zero values on
Python < 3.11 now trigger a
RuntimeWarning-- by :user:bdraco.The
ssl_shutdown_timeoutparameter is now deprecated and will be removed inaiohttp 4.0 as there is no clear use case for changing the default.
Related issues and pull requests on GitHub:
:issue:
11148.v3.12.10Compare Source
====================
Bug fixes
Fixed leak of
aiodns.DNSResolverwhen :py:class:~aiohttp.TCPConnectoris closed and no resolver was passed when creating the connector -- by :user:Tasssadar.This was a regression introduced in version 3.12.0 (:pr:
10897).Related issues and pull requests on GitHub:
:issue:
11150.v3.12.9Compare Source
===================
Bug fixes
Fixed
IOBasePayloadandTextIOPayloadreading entire files into memory when streaming large files -- by :user:bdraco.When using file-like objects with the aiohttp client, the entire file would be read into memory if the file size was provided in the
Content-Lengthheader. This could cause out-of-memory errors when uploading large files. The payload classes now correctly read data in chunks ofREAD_SIZE(64KB) regardless of the total content length.Related issues and pull requests on GitHub:
:issue:
11138.v3.12.8Compare Source
===================
Features
Added preemptive digest authentication to :class:
~aiohttp.DigestAuthMiddleware-- by :user:bdraco.The middleware now reuses authentication credentials for subsequent requests to the same
protection space, improving efficiency by avoiding extra authentication round trips.
This behavior matches how web browsers handle digest authentication and follows
:rfc:
7616#section-3.6.Preemptive authentication is enabled by default but can be disabled by passing
preemptive=Falseto the middleware constructor.Related issues and pull requests on GitHub:
:issue:
11128, :issue:11129.v3.12.7Compare Source
===================
.. warning::
This release fixes an issue where the
quote_cookieparameter was not being properlyrespected for shared cookies (domain="", path=""). If your server does not handle quoted
cookies correctly, you may need to disable cookie quoting by setting
quote_cookie=Falsewhen creating your :class:
~aiohttp.ClientSessionor :class:~aiohttp.CookieJar.See :ref:
aiohttp-client-cookie-quoting-routinefor details.Bug fixes
Fixed cookie parsing to be more lenient when handling cookies with special characters
in names or values. Cookies with characters like
{,}, and/in names are nowaccepted instead of causing a :exc:
~http.cookies.CookieErrorand 500 errors. Additionally,cookies with mismatched quotes in values are now parsed correctly, and quoted cookie
values are now handled consistently whether or not they include special attributes
like
Domain. Also fixed :class:~aiohttp.CookieJarto ensure shared cookies (domain="", path="")respect the
quote_cookieparameter, making cookie quoting behavior consistent forall cookies -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
2683, :issue:5397, :issue:7993, :issue:11112.Fixed an issue where cookies with duplicate names but different domains or paths
were lost when updating the cookie jar. The :class:
~aiohttp.ClientSessioncookie jar now correctly stores all cookies even if they have the same name but
different domain or path, following the :rfc:
6265#section-5.3storage model -- by :user:bdraco.Note that :attr:
ClientResponse.cookies <aiohttp.ClientResponse.cookies>returnsa :class:
~http.cookies.SimpleCookiewhich uses the cookie name as a key, soonly the last cookie with each name is accessible via this interface. All cookies
can be accessed via :meth:
ClientResponse.headers.getall('Set-Cookie') <multidict.MultiDictProxy.getall>if needed.Related issues and pull requests on GitHub:
:issue:
4486, :issue:11105, :issue:11106.Miscellaneous internal changes
Avoided creating closed futures in
ResponseHandlerthat will never be awaited -- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
11107.Downgraded the logging level for connector close errors from ERROR to DEBUG, as these are expected behavior with TLS 1.3 connections -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
11114.v3.12.6Compare Source
===================
Bug fixes
Fixed spurious "Future exception was never retrieved" warnings for connection lost errors when the connector is not closed -- by :user:
bdraco.When connections are lost, the exception is now marked as retrieved since it is always propagated through other means, preventing unnecessary warnings in logs.
Related issues and pull requests on GitHub:
:issue:
11100.v3.12.4Compare Source
===================
Bug fixes
Fixed connector not waiting for connections to close before returning from :meth:
~aiohttp.BaseConnector.close(partial backport of :pr:3733) -- by :user:atemateand :user:bdraco.Related issues and pull requests on GitHub:
:issue:
1925, :issue:11074.v3.12.3Compare Source
===================
Bug fixes
Fixed memory leak in :py:meth:
~aiohttp.CookieJar.filter_cookiesthat caused unbounded memory growthwhen making requests to different URL paths -- by :user:
bdracoand :user:Cycloctane.Related issues and pull requests on GitHub:
:issue:
11052, :issue:11054.v3.12.2Compare Source
===================
Bug fixes
Fixed
Content-Lengthheader not being set to0for non-GET requests withNonebody -- by :user:bdraco.Non-GET requests (
POST,PUT,PATCH,DELETE) withNoneas the body now correctly set theContent-Lengthheader to0, matching the behavior of requests with empty bytes (b""). This regression was introduced in aiohttp 3.12.1.Related issues and pull requests on GitHub:
:issue:
11035.v3.12.1Compare Source
====================
Bug fixes
Fixed :class:
~aiohttp.DigestAuthMiddlewareto preserve the algorithm case from the server's challenge in the authorization response. This improves compatibility with servers that perform case-sensitive algorithm matching (e.g., servers expectingalgorithm=MD5-sessinstead ofalgorithm=MD5-SESS)-- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
11352.Improved documentation
Remove outdated contents of
aiohttp-devtoolsandaiohttp-swaggerfrom Web_advanced docs.
-- by :user:
CycloctaneRelated issues and pull requests on GitHub:
:issue:
11347.Packaging updates and notes for downstreams
Started including the
llhttp:file:LICENSEfile in wheels by addingvendor/llhttp/LICENSEtolicense-filesin :file:setup.cfg-- by :user:threexc.Related issues and pull requests on GitHub:
:issue:
11226.Contributor-facing changes
Updated a regex in
test_aiohttp_request_coroutinefor Python 3.14.Related issues and pull requests on GitHub:
:issue:
11271.v3.12.0Compare Source
===================
Bug fixes
Fixed :py:attr:
~aiohttp.web.WebSocketResponse.preparedproperty to correctly reflect the prepared state, especially during timeout scenarios -- by :user:bdracoRelated issues and pull requests on GitHub:
:issue:
6009, :issue:10988.Response is now always True, instead of using MutableMapping behaviour (False when map is empty)
Related issues and pull requests on GitHub:
:issue:
10119.Fixed connection reuse for file-like data payloads by ensuring buffer
truncation respects content-length boundaries and preventing premature
connection closure race -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
10325, :issue:10915, :issue:10941, :issue:10943.Fixed pytest plugin to not use deprecated :py:mod:
asynciopolicy APIs.Related issues and pull requests on GitHub:
:issue:
10851.Fixed :py:class:
~aiohttp.resolver.AsyncResolvernot using theloopargument in versions 3.x where it should still be supported -- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
10951.Features
Added a comprehensive HTTP Digest Authentication client middleware (DigestAuthMiddleware)
that implements RFC 7616. The middleware supports all standard hash algorithms
(MD5, SHA, SHA-256, SHA-512) with session variants, handles both 'auth' and
'auth-int' quality of protection options, and automatically manages the
authentication flow by intercepting 401 responses and retrying with proper
credentials -- by :user:
feus4177, :user:TimMenninger, and :user:bdraco.Related issues and pull requests on GitHub:
:issue:
2213, :issue:10725.Added client middleware support -- by :user:
bdracoand :user:Dreamsorcerer.This change allows users to add middleware to the client session and requests, enabling features like
authentication, logging, and request/response modification without modifying the core
request logic. Additionally, the
sessionattribute was added toClientRequest,allowing middleware to access the session for making additional requests.
Related issues and pull requests on GitHub:
:issue:
9732, :issue:10902, :issue:10945, :issue:10952, :issue:10959, :issue:10968.Allow user setting zlib compression backend -- by :user:
TimMenningerThis change allows the user to call :func:
aiohttp.set_zlib_backend()with thezlib compression module of their choice. Default behavior continues to use
the builtin
zliblibrary.Related issues and pull requests on GitHub:
:issue:
9798.Added support for overriding the base URL with an absolute one in client sessions
-- by :user:
vivodi.Related issues and pull requests on GitHub:
:issue:
10074.Added
hostparameter toaiohttp_serverfixture -- by :user:christianwbrock.Related issues and pull requests on GitHub:
:issue:
10120.Detect blocking calls in coroutines using BlockBuster -- by :user:
cbornet.Related issues and pull requests on GitHub:
:issue:
10433.Added
socket_factoryto :py:class:aiohttp.TCPConnectorto allow specifying custom socket options-- by :user:
TimMenninger.Related issues and pull requests on GitHub:
:issue:
10474, :issue:10520, :issue:10961, :issue:10962.Started building armv7l manylinux wheels -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
10797.Implemented shared DNS resolver management to fix excessive resolver object creation
when using multiple client sessions. The new
_DNSResolverManagersingleton ensuresonly one
DNSResolverobject is created for default configurations, significantlyreducing resource usage and improving performance for applications using multiple
client sessions simultaneously -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
10847, :issue:10923, :issue:10946.Upgraded to LLHTTP 9.3.0 -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
10972.Optimized small HTTP requests/responses by coalescing headers and body into a single TCP packet -- by :user:
bdraco.This change enhances network efficiency by reducing the number of packets sent for small HTTP payloads, improving latency and reducing overhead. Most importantly, this fixes compatibility with memory-constrained IoT devices that can only perform a single read operation and expect HTTP requests in one packet. The optimization uses zero-copy
writelineswhen coalescing data and works with both regular and chunked transfer encoding.When
aiohttpuses client middleware to communicate with anaiohttpserver, connection reuse is more likely to occur since complete responses arrive in a single packet for small payloads.This aligns
aiohttpwith other popular HTTP clients that already coalesce small requests.Related issues and pull requests on GitHub:
:issue:
10991.Improved documentation
Improved documentation for middleware by adding warnings and examples about
request body stream consumption. The documentation now clearly explains that
request body streams can only be read once and provides best practices for
sharing parsed request data between middleware and handlers -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
2914.Packaging updates and notes for downstreams
Removed non SPDX-license description from
setup.cfg-- by :user:devanshu-ziphq.Related issues and pull requests on GitHub:
:issue:
10662.Added support for building against system
llhttplibrary -- by :user:mgorny.This change adds support for :envvar:
AIOHTTP_USE_SYSTEM_DEPSenvironment variable thatcan be used to build aiohttp against the system install of the
llhttplibrary ratherthan the vendored one.
Related issues and pull requests on GitHub:
:issue:
10759.aiodnsis now installed on Windows with speedups extra -- by :user:bdraco.As of
aiodns3.3.0,SelectorEventLoopis no longer required when usingpycares4.7.0 or later.Related issues and pull requests on GitHub:
:issue:
10823.Fixed compatibility issue with Cython 3.1.1 -- by :user:
bdracoRelated issues and pull requests on GitHub:
:issue:
10877.Contributor-facing changes
Sped up tests by disabling
blockbusterfixture fortest_static_file_hugeandtest_static_file_huge_canceltests -- by :user:dikos1337.Related issues and pull requests on GitHub:
:issue:
9705, :issue:10761.Updated tests to avoid using deprecated :py:mod:
asynciopolicy APIs andmake it compatible with Python 3.14.
Related issues and pull requests on GitHub:
:issue:
10851.Added Winloop to test suite to support in the future -- by :user:
Vizonex.Related issues and pull requests on GitHub:
:issue:
10922.Miscellaneous internal changes
Added support for the
partitionedattribute in theset_cookiemethod.Related issues and pull requests on GitHub:
:issue:
9870.Setting :attr:
aiohttp.web.StreamResponse.last_modifiedto an unsupported type will now raise :exc:TypeErrorinstead of silently failing -- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
10146.v3.11.18Compare Source
====================
Bug fixes
Disabled TLS in TLS warning (when using HTTPS proxies) for uvloop and newer Python versions -- by :user:
lezgomatt.Related issues and pull requests on GitHub:
:issue:
7686.Fixed reading fragmented WebSocket messages when the payload was masked -- by :user:
bdraco.The problem first appeared in 3.11.17
Related issues and pull requests on GitHub:
:issue:
10764.v3.11.17Compare Source
====================
Miscellaneous internal changes
Optimized web server performance when access logging is disabled by reducing time syscalls -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
10713.Improved web server performance when connection can be reused -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
10714.Improved performance of the WebSocket reader -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
10740.Improved performance of the WebSocket reader with large messages -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
10744.v3.11.16Compare Source
====================
Bug fixes
Replaced deprecated
asyncio.iscoroutinefunctionwith its counterpart frominspect-- by :user:
layday.Related issues and pull requests on GitHub:
:issue:
10634.Fixed :class:
multidict.CIMultiDictbeing mutated when passed to :class:aiohttp.web.Response-- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
10672.v3.11.15Compare Source
====================
Bug fixes
Reverted explicitly closing sockets if an exception is raised during
create_connection-- by :user:bdraco.This change originally appeared in aiohttp 3.11.13
Related issues and pull requests on GitHub:
:issue:
10464, :issue:10617, :issue:10656.Miscellaneous internal changes
Improved performance of WebSocket buffer handling -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
10601.Improved performance of serializing headers -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
10625.v3.11.14Compare Source
====================
Bug fixes
Fixed an issue where dns queries were delayed indefinitely when an exception occurred in a
trace.send_dns_cache_miss-- by :user:
logioniz.Related issues and pull requests on GitHub:
:issue:
10529.Fixed DNS resolution on platforms that don't support
socket.AI_ADDRCONFIG-- by :user:maxbachmann.Related issues and pull requests on GitHub:
:issue:
10542.The connector now raises :exc:
aiohttp.ClientConnectionErrorinstead of :exc:OSErrorwhen failing to explicitly close the socket after :py:meth:asyncio.loop.create_connectionfails -- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
10551.Break cyclic references at connection close when there was a traceback -- by :user:
bdraco.Special thanks to :user:
availovfor reporting the issue.Related issues and pull requests on GitHub:
:issue:
10556.Break cyclic references when there is an exception handling a request -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
10569.Features
Improved logging on non-overlapping WebSocket client protocols to include the remote address -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
10564.Miscellaneous internal changes
Improved performance of parsing content types by adding a cache in the same manner currently done with mime types -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
10552.v3.11.13Compare Source
====================
Bug fixes
Reverted explicitly closing sockets if an exception is raised during
create_connection-- by :user:bdraco.This change originally appeared in aiohttp 3.11.13
Related issues and pull requests on GitHub:
:issue:
10464, :issue:10617, :issue:10656.Miscellaneous internal changes
Improved performance of WebSocket buffer handling -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
10601.Improved performance of serializing headers -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
10625.v3.11.12Compare Source
====================
Bug fixes
MultipartForm.decode()now follows RFC1341 7.2.1 with aCRLFafter the boundary-- by :user:
imnotjames.Related issues and pull requests on GitHub:
:issue:
10270.Restored the missing
total_bytesattribute toEmptyStreamReader-- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
10387.Features
Updated :py:func:
~aiohttp.requestto make it accept_RequestOptionskwargs.-- by :user:
Cycloctane.Related issues and pull requests on GitHub:
:issue:
10300.Improved logging of HTTP protocol errors to include the remote address -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
10332.Improved documentation
Added
aiohttp-openmetricsto list of third-party libraries -- by :user:jelmer.Related issues and pull requests on GitHub:
:issue:
10304.Packaging updates and notes for downstreams
Added missing files to the source distribution to fix
Makefiletargets.Added a
cythonize-nodepstarget to run Cython without invoking pip to install dependencies.Related issues and pull requests on GitHub:
:issue:
10366.Started building armv7l musllinux wheels -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
10404.Contributor-facing changes
The CI/CD workflow has been updated to use
upload-artifactv4 anddownload-artifactv4 GitHub Actions -- by :user:silamon.Related issues and pull requests on GitHub:
:issue:
10281.Miscellaneous internal changes
Restored support for zero copy writes when using Python 3.12 versions 3.12.9 and later or Python 3.13.2+ -- by :user:
bdraco.Zero copy writes were previously disabled due to :cve:
2024-12254which is resolved in these Python versions.Related issues and pull requests on GitHub:
:issue:
10137.v3.11.11Compare Source
====================
Bug fixes
Updated :py:meth:
~aiohttp.ClientSession.requestto reuse thequote_cookiesetting fromClientSession._cookie_jarwhen processing cookies parameter.-- by :user:
Cycloctane.Related issues and pull requests on GitHub:
:issue:
10093.Fixed type of
SSLContextfor some static type checkers (e.g. pyright).Related issues and pull requests on GitHub:
:issue:
10099.Updated :meth:
aiohttp.web.StreamResponse.writeannotation to also allow :class:bytearrayand :class:memoryviewas inputs -- by :user:cdce8p.Related issues and pull requests on GitHub:
:issue:
10154.Fixed a hang where a connection previously used for a streaming
download could be returned to the pool in a paused state.
-- by :user:
javitonino.Related issues and pull requests on GitHub:
:issue:
10169.Features
Enabled ALPN on default SSL contexts. This improves compatibility with some
proxies which don't work without this extension.
-- by :user:
Cycloctane.Related issues and pull requests on GitHub:
:issue:
10156.Miscellaneous internal changes
Fixed an infinite loop that can occur when using aiohttp in combination
with
async-solipsism_ -- by :user:bmerry... _async-solipsism: https://github.com/bmerry/async-solipsism
Related issues and pull requests on GitHub:
:issue:
10149.v3.11.10Compare Source
====================
Bug fixes
Fixed race condition in :class:
aiohttp.web.FileResponsethat could have resulted in an incorrect response if the file was replaced on the file system duringprepare-- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
10101, :issue:10113.Replaced deprecated call to :func:
mimetypes.guess_typewith :func:mimetypes.guess_file_typewhen using Python 3.13+ -- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
10102.Disabled zero copy writes in the
StreamWriter-- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
10125.v3.11.9Compare Source
===================
Bug fixes
Fixed invalid method logging unexpected being logged at exception level on subsequent connections -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
10055, :issue:10076.Miscellaneous internal changes
Improved performance of parsing headers when using the C parser -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
10073.v3.11.8Compare Source
===================
Miscellaneous internal changes
Improved performance of creating :class:
aiohttp.ClientResponseobjects when there are no cookies -- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
10029.Improved performance of creating :class:
aiohttp.ClientResponseobjects -- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
10030.Improved performances of creating objects during the HTTP request lifecycle -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
10037.Improved performance of constructing :class:
aiohttp.web.Responsewith headers -- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
10043.Improved performance of making requests when there are no auto headers to skip -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
10049.Downgraded logging of invalid HTTP method exceptions on the first request to debug level -- by :user:
bdraco.HTTP requests starting with an invalid method are relatively common, especially when connected to the public internet, because browsers or other clients may try to speak SSL to a plain-text server or vice-versa. These exceptions can quickly fill the log with noise when nothing is wrong.
Related issues and pull requests on GitHub:
:issue:
10055.v3.11.7Compare Source
===================
Bug fixes
Fixed the HTTP client not considering the connector's
force_closevalue when setting theConnectionheader -- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
10003.Miscellaneous internal changes
Improved performance of serializing HTTP headers -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
10014.v3.11.6Compare Source
===================
Bug fixes
Restored the
force_closemethod to theResponseHandler-- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
9997.v3.11.5Compare Source
===================
Bug fixes
Fixed the
ANYmethod not appearing in :meth:~aiohttp.web.UrlDispatcher.routes-- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
9899, :issue:9987.v3.11.4Compare Source
===================
Bug fixes
Fixed
StaticResourcenot allowing theOPTIONSmethod after callingset_options_route-- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
9972, :issue:9975, :issue:9976.Miscellaneous internal changes
Improved performance of creating web responses when there are no cookies -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
9895.v3.11.3Compare Source
===================
Bug fixes
Removed non-existing
__author__fromdir(aiohttp)-- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
9918.Restored the
FlowControlDataQueueclass -- by :user:bdraco.This class is no longer used internally, and will be permanently removed in the next major version.
Related issues and pull requests on GitHub:
:issue:
9963.Miscellaneous internal changes
Improved performance of resolving resources when multiple methods are registered for the same route -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
9899.v3.11.2Compare Source
===================
Bug fixes
Fixed improperly closed WebSocket connections generating an unhandled exception -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
9883.v3.11.1Compare Source
====================
Bug fixes
Disabled TLS in TLS warning (when using HTTPS proxies) for uvloop and newer Python versions -- by :user:
lezgomatt.Related issues and pull requests on GitHub:
:issue:
7686.Fixed reading fragmented WebSocket messages when the payload was masked -- by :user:
bdraco.The problem first appeared in 3.11.17
Related issues and pull requests on GitHub:
:issue:
10764.v3.11.0Compare Source
===================
Bug fixes
Raise :exc:
aiohttp.ServerFingerprintMismatchexception on client-side if request through http proxy with mismatching server fingerprint digest:aiohttp.ClientSession(headers=headers, connector=TCPConnector(ssl=aiohttp.Fingerprint(mismatch_digest), trust_env=True).request(...)-- by :user:gangj.Related issues and pull requests on GitHub:
:issue:
6652.Modified websocket :meth:
aiohttp.ClientWebSocketResponse.receive_str, :py:meth:aiohttp.ClientWebSocketResponse.receive_bytes, :py:meth:aiohttp.web.WebSocketResponse.receive_str& :py:meth:aiohttp.web.WebSocketResponse.receive_bytesmethods to raise new :py:exc:aiohttp.WSMessageTypeErrorexception, instead of generic :py:exc:TypeError, when websocket messages of incorrect types are received -- by :user:ara-25.Related issues and pull requests on GitHub:
:issue:
6800.Made
TestClient.appaGenericso type checkers will know the correct type (avoiding unneededclient.app is not Nonechecks) -- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8977.Fixed the keep-alive connection pool to be FIFO instead of LIFO -- by :user:
bdraco.Keep-alive connections are more likely to be reused before they disconnect.
Related issues and pull requests on GitHub:
:issue:
9672.Features
Added
strategyparameter to :meth:aiohttp.web.StreamResponse.enable_compressionThe value of this parameter is passed to the :func:
zlib.compressobjfunction, allowing peopleto use a more sufficient compression algorithm for their data served by :mod:
aiohttp.web-- by :user:
shootkinRelated issues and pull requests on GitHub:
:issue:
6257.Added
server_hostnameparameter tows_connect.Related issues and pull requests on GitHub:
:issue:
7941.Exported :py:class:
~aiohttp.ClientWSTimeoutto top-level namespace -- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8612.Added
secure/httponly/samesiteparameters to.del_cookie()-- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8956.Updated :py:class:
~aiohttp.ClientSession's auth logic to include default auth only if the request URL's origin matches _base_url; otherwise, the auth will not be included -- by :user:MaximZemskovRelated issues and pull requests on GitHub:
:issue:
8966, :issue:9466.Added
proxyandproxy_authparameters to :py:class:~aiohttp.ClientSession-- by :user:meshya.Related issues and pull requests on GitHub:
:issue:
9207.Added
default_to_multipartparameter toFormData.Related issues and pull requests on GitHub:
:issue:
9335.Added :py:meth:
~aiohttp.ClientWebSocketResponse.send_frameand :py:meth:~aiohttp.web.WebSocketResponse.send_framefor WebSockets -- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
9348.Updated :py:class:
~aiohttp.ClientSessionto support paths inbase_urlparameter.base_urlpaths must end with a/-- by :user:Cycloctane.Related issues and pull requests on GitHub:
:issue:
9530.Improved performance of reading WebSocket messages with a Cython implementation -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
9543, :issue:9554, :issue:9556, :issue:9558, :issue:9636, :issue:9649, :issue:9781.Added
writer_limitto the :py:class:~aiohttp.web.WebSocketResponseto be able to adjust the limit before the writer forces the buffer to be drained -- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
9572.Added an :attr:
~aiohttp.abc.AbstractAccessLogger.enabledproperty to :class:aiohttp.abc.AbstractAccessLoggerto dynamically check if logging is enabled -- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
9822.Deprecations (removal in next major release)
Deprecate obsolete
timeout: floatandreceive_timeout: Optional[float]in :py:meth:~aiohttp.ClientSession.ws_connect. Change default websocket receive timeout fromNoneto10.0.Related issues and pull requests on GitHub:
:issue:
3945.Removals and backward incompatible breaking changes
Dropped support for Python 3.8 -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8797.Increased minimum yarl version to 1.17.0 -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
8909, :issue:9079, :issue:9305, :issue:9574.Removed the
is_ipv6_addressandis_ip4_addresshelpers are they are no longer used -- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
9344.Changed
ClientRequest.connection_keyto be aNamedTupleto improve client performance -- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
9365.FlowControlDataQueuehas been replaced with theWebSocketDataQueue-- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
9685.Changed
ClientRequest.request_infoto be aNamedTupleto improve client performance -- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
9692.Packaging updates and notes for downstreams
Switched to using the :mod:
propcache <propcache.api>package for property caching-- by :user:
bdraco.The :mod:
propcache <propcache.api>package is derived from the property cachingcode in :mod:
yarland has been broken out to avoid maintaining it for multipleprojects.
Related issues and pull requests on GitHub:
:issue:
9394.Separated
aiohttp.http_websocketinto multiple files to make it easier to maintain -- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
9542, :issue:9552.Contributor-facing changes
Changed diagram images generator from
blockdiagtoGraphViz.Generating documentation now requires the GraphViz executable to be included in $PATH or sphinx build configuration.
Related issues and pull requests on GitHub:
:issue:
9359.Miscellaneous internal changes
Added flake8 settings to avoid some forms of implicit concatenation. -- by :user:
booniepepper.Related issues and pull requests on GitHub:
:issue:
7731.Enabled keep-alive support on proxies (which was originally disabled several years ago) -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8920.Changed web entry point to not listen on TCP when only a Unix path is passed -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
9033.Disabled automatic retries of failed requests in :class:
aiohttp.test_utils.TestClient's client session(which could potentially hide errors in tests) -- by :user:
ShubhAgarwal-dev.Related issues and pull requests on GitHub:
:issue:
9141.Changed web
keepalive_timeoutdefault to around an hour in order to reduce race conditions on reverse proxies -- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
9285.Reduced memory required for stream objects created during the client request lifecycle -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
9407.Improved performance of the internal
DataQueue-- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
9659.Improved performance of calling
receivefor WebSockets for the most common message types -- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
9679.Replace internal helper methods
method_must_be_empty_bodyandstatus_code_must_be_empty_bodywith simplesetlookups -- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
9722.Improved performance of :py:class:
aiohttp.BaseConnectorwhen there is nolimit_per_host-- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
9756.Improved performance of sending HTTP requests when there is no body -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
9757.Improved performance of the
WebsocketWriterwhen the protocol is not paused -- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
9796.Implemented zero copy writes for
StreamWriter-- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
9839.v3.10.11Compare Source
====================
Bug fixes
Authentication provided by a redirect now takes precedence over provided
authwhen making requests with the client -- by :user:PLPeeters.Related issues and pull requests on GitHub:
:issue:
9436.Fixed :py:meth:
WebSocketResponse.close() <aiohttp.web.WebSocketResponse.close>to discard non-close messages within its timeout window after sending close -- by :user:lenard-mosys.Related issues and pull requests on GitHub:
:issue:
9506.Fixed a deadlock that could occur while attempting to get a new connection slot after a timeout -- by :user:
bdraco.The connector was not cancellation-safe.
Related issues and pull requests on GitHub:
:issue:
9670, :issue:9671.Fixed the WebSocket flow control calculation undercounting with multi-byte data -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
9686.Fixed incorrect parsing of chunk extensions with the pure Python parser -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
9851.Fixed system routes polluting the middleware cache -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
9852.Removals and backward incompatible breaking changes
Improved performance of the connector when a connection can be reused -- by :user:
bdraco.If
BaseConnector.connecthas been subclassed and replaced with custom logic, theceil_timeoutmust be added.Related issues and pull requests on GitHub:
:issue:
9600.Miscellaneous internal changes
Improved performance of the client request lifecycle when there are no cookies -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
9470.Improved performance of sending client requests when the writer can finish synchronously -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
9485.Improved performance of serializing HTTP headers -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
9603.Passing
enable_cleanup_closedto :py:class:aiohttp.TCPConnectoris now ignored on Python 3.12.7+ and 3.13.1+ since the underlying bug that caused asyncio to leak SSL connections has been fixed upstream -- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
9726, :issue:9736.v3.10.10Compare Source
====================
Bug fixes
Fixed error messages from :py:class:
~aiohttp.resolver.AsyncResolverbeing swallowed -- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
9451, :issue:9455.Features
Added :exc:
aiohttp.ClientConnectorDNSErrorfor differentiating DNS resolution errors from other connector errors -- by :user:mstojcevich.Related issues and pull requests on GitHub:
:issue:
8455.Miscellaneous internal changes
Simplified DNS resolution throttling code to reduce chance of race conditions -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
9454.v3.10.9Compare Source
===================
Bug fixes
Fixed proxy headers being used in the
ConnectionKeyhash when a proxy was not being used -- by :user:bdraco.If default headers are used, they are also used for proxy headers. This could have led to creating connections that were not needed when one was already available.
Related issues and pull requests on GitHub:
:issue:
9368.Widened the type of the
trace_request_ctxparameter of:meth:
ClientSession.request() <aiohttp.ClientSession.request>and friends-- by :user:
layday.Related issues and pull requests on GitHub:
:issue:
9397.Removals and backward incompatible breaking changes
Fixed failure to try next host after single-host connection timeout -- by :user:
brettdh.The default client :class:
aiohttp.ClientTimeoutparams has changed to include asock_connecttimeout of 30 seconds so that this correct behavior happens by default.Related issues and pull requests on GitHub:
:issue:
7342.Miscellaneous internal changes
Improved performance of resolving hosts with Python 3.12+ -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
9342.Reduced memory required for timer objects created during the client request lifecycle -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
9406.v3.10.8Compare Source
===================
Bug fixes
Fixed cancellation leaking upwards on timeout -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
9326.v3.10.7Compare Source
===================
Bug fixes
Fixed assembling the :class:
~yarl.URLfor web requests when the host contains a non-default port or IPv6 address -- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
9309.Miscellaneous internal changes
Improved performance of determining if a URL is absolute -- by :user:
bdraco.The property :attr:
~yarl.URL.absoluteis more performant than the methodURL.is_absolute()and preferred when newer versions of yarl are used.Related issues and pull requests on GitHub:
:issue:
9171.Replaced code that can now be handled by
yarl-- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
9301.v3.10.6Compare Source
===================
Bug fixes
Added :exc:
aiohttp.ClientConnectionResetError. Client code that previously threw :exc:ConnectionResetErrorwill now throw this -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
9137.Fixed an unclosed transport
ResourceWarningon web handlers -- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8875.Fixed resolve_host() 'Task was destroyed but is pending' errors -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8967.Fixed handling of some file-like objects (e.g.
tarfile.extractfile()) which raiseAttributeErrorinstead ofOSErrorwhenfilenofails for streaming payload data -- by :user:ReallyReivax.Related issues and pull requests on GitHub:
:issue:
6732.Fixed web router not matching pre-encoded URLs (requires yarl 1.9.6+) -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8898, :issue:9267.Fixed an error when trying to add a route for multiple methods with a path containing a regex pattern -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8998.Fixed
Response.textwhen body is aPayload-- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
6485.Fixed compressed requests failing when no body was provided -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
9108.Fixed client incorrectly reusing a connection when the previous message had not been fully sent -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8992.Fixed race condition that could cause server to close connection incorrectly at keepalive timeout -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
9140.Fixed Python parser chunked handling with multiple Transfer-Encoding values -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8823.Fixed error handling after 100-continue so server sends 500 response instead of disconnecting -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8876.Stopped adding a default Content-Type header when response has no content -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8858.Added support for URL credentials with empty (zero-length) username, e.g.
https://:password@host-- by :user:shuckcRelated issues and pull requests on GitHub:
:issue:
6494.Stopped logging exceptions from
web.run_app()that would be raised regardless -- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
6807.Implemented binding to IPv6 addresses in the pytest server fixture.
Related issues and pull requests on GitHub:
:issue:
4650.Fixed the incorrect use of flags for
getnameinfo()in the Resolver --by :user:GitNMLeeLink-Local IPv6 addresses can now be handled by the Resolver correctly.
Related issues and pull requests on GitHub:
:issue:
9032.Fixed StreamResponse.prepared to return True after EOF is sent -- by :user:
arthurdarcet.Related issues and pull requests on GitHub:
:issue:
5343.Changed
make_mocked_request()to use empty payload by default -- by :user:rahulnht.Related issues and pull requests on GitHub:
:issue:
7167.Used more precise type for
ClientResponseError.headers, fixing some type errors when using them -- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8768.Changed behavior when returning an invalid response to send a 500 response -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8845.Fixed response reading from closed session to throw an error immediately instead of timing out -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8878.Fixed
CancelledErrorfrom one cleanup context stopping other contexts from completing -- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8908.Fixed changing scheme/host in
Response.clone()for absolute URLs -- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8990.Fixed
Site.namewhen host is an empty string -- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8929.Updated Python parser to reject messages after a close message, matching C parser behaviour -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
9018.Fixed creation of
SSLContextinside of :py:class:aiohttp.TCPConnectorwith multiple event loops in different threads -- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
9029.Fixed (on Python 3.11+) some edge cases where a task cancellation may get incorrectly suppressed -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
9030.Fixed exception information getting lost on
HttpProcessingError-- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
9052.Fixed
If-None-Matchnot using weak comparison -- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
9063.Fixed badly encoded charset crashing when getting response text instead of falling back to charset detector.
Related issues and pull requests on GitHub:
:issue:
9160.Rejected
\ninreasonvalues to avoid sending broken HTTP messages -- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
9167.Changed :py:meth:
ClientResponse.raise_for_status() <aiohttp.ClientResponse.raise_for_status>to only release the connection when invoked outside anasync withcontext -- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
9239.Features
Improved type on
paramsto match the underlying type allowed byyarl-- by :user:lpetre.Related issues and pull requests on GitHub:
:issue:
8564.Declared Python 3.13 supported -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
8748.Removals and backward incompatible breaking changes
Improved middleware performance -- by :user:
bdraco.The
set_current_appmethod was removed fromUrlMappingMatchInfobecause it is no longer used, and it was unlikely external caller would ever use it.Related issues and pull requests on GitHub:
:issue:
9200.Increased minimum yarl version to 1.12.0 -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
9267.Improved documentation
Clarified that
GracefulExitneeds to be handled inAppRunnerandServerRunnerwhen usinghandle_signals=True. -- by :user:Daste745Related issues and pull requests on GitHub:
:issue:
4414.Clarified that auth parameter in ClientSession will persist and be included with any request to any origin, even during redirects to different origins. -- by :user:
MaximZemskov.Related issues and pull requests on GitHub:
:issue:
6764.Clarified which timeout exceptions happen on which timeouts -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8968.Updated
ClientSessionparameters to match current code -- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8991.Packaging updates and notes for downstreams
Fixed
test_client_session_timeout_zeroto not require internet access -- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
9004.Miscellaneous internal changes
Improved performance of making requests when there are no auto headers to skip -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
8847.Exported
aiohttp.TraceRequestHeadersSentParams-- by :user:Hadock-is-ok.Related issues and pull requests on GitHub:
:issue:
8947.Avoided tracing overhead in the http writer when there are no active traces -- by user:
bdraco.Related issues and pull requests on GitHub:
:issue:
9031.Improved performance of reify Cython implementation -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
9054.Use :meth:
URL.extend_query() <yarl.URL.extend_query>to extend query params (requires yarl 1.11.0+) -- by :user:bdraco.If yarl is older than 1.11.0, the previous slower hand rolled version will be used.
Related issues and pull requests on GitHub:
:issue:
9068.Improved performance of checking if a host is an IP Address -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
9095.Significantly improved performance of middlewares -- by :user:
bdraco.The construction of the middleware wrappers is now cached and is built once per handler instead of on every request.
Related issues and pull requests on GitHub:
:issue:
9158, :issue:9170.Improved performance of web requests -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
9168, :issue:9169, :issue:9172, :issue:9174, :issue:9175, :issue:9241.Improved performance of starting web requests when there is no response prepare hook -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
9173.Significantly improved performance of expiring cookies -- by :user:
bdraco.Expiring cookies has been redesigned to use :mod:
heapqinstead of a linear search, to better scale.Related issues and pull requests on GitHub:
:issue:
9203.Significantly sped up filtering cookies -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
9204.v3.10.5Compare Source
=========================
Bug fixes
Fixed :meth:
aiohttp.ClientResponse.json()not settingstatuswhen :exc:aiohttp.ContentTypeErroris raised -- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
8742.Miscellaneous internal changes
Improved performance of the WebSocket reader -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
8736, :issue:8747.v3.10.4Compare Source
===================
Bug fixes
Fixed decoding base64 chunk in BodyPartReader -- by :user:
hyzyla.Related issues and pull requests on GitHub:
:issue:
3867.Fixed a race closing the server-side WebSocket where the close code would not reach the client -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
8680.Fixed unconsumed exceptions raised by the WebSocket heartbeat -- by :user:
bdraco.If the heartbeat ping raised an exception, it would not be consumed and would be logged as an warning.
Related issues and pull requests on GitHub:
:issue:
8685.Fixed an edge case in the Python parser when chunk separators happen to align with network chunks -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8720.Improved documentation
Added
aiohttp-apischemato supported libraries -- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8700.Miscellaneous internal changes
Improved performance of starting request handlers with Python 3.12+ -- by :user:
bdraco.This change is a followup to :issue:
8661to make the same optimization for Python 3.12+ where the request is connected.Related issues and pull requests on GitHub:
:issue:
8681.v3.10.3Compare Source
========================
Bug fixes
Fixed multipart reading when stream buffer splits the boundary over several read() calls -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8653.Fixed :py:class:
aiohttp.TCPConnectordoing blocking I/O in the event loop to create theSSLContext-- by :user:bdraco.The blocking I/O would only happen once per verify mode. However, it could cause the event loop to block for a long time if the
SSLContextcreation is slow, which is more likely during startup when the disk cache is not yet present.Related issues and pull requests on GitHub:
:issue:
8672.Miscellaneous internal changes
Improved performance of :py:meth:
~aiohttp.ClientWebSocketResponse.receiveand :py:meth:~aiohttp.web.WebSocketResponse.receivewhen there is no timeout. -- by :user:bdraco.The timeout context manager is now avoided when there is no timeout as it accounted for up to 50% of the time spent in the :py:meth:
~aiohttp.ClientWebSocketResponse.receiveand :py:meth:~aiohttp.web.WebSocketResponse.receivemethods.Related issues and pull requests on GitHub:
:issue:
8660.Improved performance of starting request handlers with Python 3.12+ -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
8661.Improved performance of HTTP keep-alive checks -- by :user:
bdraco.Previously, when processing a request for a keep-alive connection, the keep-alive check would happen every second; the check is now rescheduled if it fires too early instead.
Related issues and pull requests on GitHub:
:issue:
8662.Improved performance of generating random WebSocket mask -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
8667.v3.10.2Compare Source
===================
Bug fixes
Fixed server checks for circular symbolic links to be compatible with Python 3.13 -- by :user:
steverep.Related issues and pull requests on GitHub:
:issue:
8565.Fixed request body not being read when ignoring an Upgrade request -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8597.Fixed an edge case where shutdown would wait for timeout when the handler was already completed -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8611.Fixed connecting to
npipe://,tcp://, andunix://urls -- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
8632.Fixed WebSocket ping tasks being prematurely garbage collected -- by :user:
bdraco.There was a small risk that WebSocket ping tasks would be prematurely garbage collected because the event loop only holds a weak reference to the task. The garbage collection risk has been fixed by holding a strong reference to the task. Additionally, the task is now scheduled eagerly with Python 3.12+ to increase the chance it can be completed immediately and avoid having to hold any references to the task.
Related issues and pull requests on GitHub:
:issue:
8641.Fixed incorrectly following symlinks for compressed file variants -- by :user:
steverep.Related issues and pull requests on GitHub:
:issue:
8652.Removals and backward incompatible breaking changes
Removed
Request.wait_for_disconnection(), which was mistakenly added briefly in 3.10.0 -- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8636.Contributor-facing changes
Fixed monkey patches for
Path.stat()andPath.is_dir()for Python 3.13 compatibility -- by :user:steverep.Related issues and pull requests on GitHub:
:issue:
8551.Miscellaneous internal changes
Improved WebSocket performance when messages are sent or received frequently -- by :user:
bdraco.The WebSocket heartbeat scheduling algorithm was improved to reduce the
asyncioscheduling overhead by decreasing the number ofasyncio.TimerHandlecreations and cancellations.Related issues and pull requests on GitHub:
:issue:
8608.Minor improvements to various type annotations -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8634.v3.10.1Compare Source
====================
Bug fixes
Authentication provided by a redirect now takes precedence over provided
authwhen making requests with the client -- by :user:PLPeeters.Related issues and pull requests on GitHub:
:issue:
9436.Fixed :py:meth:
WebSocketResponse.close() <aiohttp.web.WebSocketResponse.close>to discard non-close messages within its timeout window after sending close -- by :user:lenard-mosys.Related issues and pull requests on GitHub:
:issue:
9506.Fixed a deadlock that could occur while attempting to get a new connection slot after a timeout -- by :user:
bdraco.The connector was not cancellation-safe.
Related issues and pull requests on GitHub:
:issue:
9670, :issue:9671.Fixed the WebSocket flow control calculation undercounting with multi-byte data -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
9686.Fixed incorrect parsing of chunk extensions with the pure Python parser -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
9851.Fixed system routes polluting the middleware cache -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
9852.Removals and backward incompatible breaking changes
Improved performance of the connector when a connection can be reused -- by :user:
bdraco.If
BaseConnector.connecthas been subclassed and replaced with custom logic, theceil_timeoutmust be added.Related issues and pull requests on GitHub:
:issue:
9600.Miscellaneous internal changes
Improved performance of the client request lifecycle when there are no cookies -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
9470.Improved performance of sending client requests when the writer can finish synchronously -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
9485.Improved performance of serializing HTTP headers -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
9603.Passing
enable_cleanup_closedto :py:class:aiohttp.TCPConnectoris now ignored on Python 3.12.7+ and 3.13.1+ since the underlying bug that caused asyncio to leak SSL connections has been fixed upstream -- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
9726, :issue:9736.v3.10.0Compare Source
========================
Bug fixes
Fixed server response headers for
Content-TypeandContent-Encodingforstatic compressed files -- by :user:
steverep.Server will now respond with a
Content-Typeappropriate for the compressedfile (e.g.
"application/gzip"), and omit theContent-Encodingheader.Users should expect that most clients will no longer decompress such responses
by default.
Related issues and pull requests on GitHub:
:issue:
4462.Fixed duplicate cookie expiration calls in the CookieJar implementation
Related issues and pull requests on GitHub:
:issue:
7784.Adjusted
FileResponseto check file existence and access when preparing the response -- by :user:steverep.The :py:class:
~aiohttp.web.FileResponseclass was modified to respond with403 Forbidden or 404 Not Found as appropriate. Previously, it would cause a
server error if the path did not exist or could not be accessed. Checks for
existence, non-regular files, and permissions were expected to be done in the
route handler. For static routes, this now permits a compressed file to exist
without its uncompressed variant and still be served. In addition, this
changes the response status for files without read permission to 403, and for
non-regular files from 404 to 403 for consistency.
Related issues and pull requests on GitHub:
:issue:
8182.Fixed
AsyncResolverto matchThreadedResolverbehavior-- by :user:
bdraco.On system with IPv6 support, the :py:class:
~aiohttp.resolver.AsyncResolverwould not fallbackto providing A records when AAAA records were not available.
Additionally, unlike the :py:class:
~aiohttp.resolver.ThreadedResolver, the :py:class:~aiohttp.resolver.AsyncResolverdid not handle link-local addresses correctly.
This change makes the behavior consistent with the :py:class:
~aiohttp.resolver.ThreadedResolver.Related issues and pull requests on GitHub:
:issue:
8270.Fixed
ws_connectnot respectingreceive_timeout`` on WS(S) connection. -- by :user:arcivanov`.Related issues and pull requests on GitHub:
:issue:
8444.Removed blocking I/O in the event loop for static resources and refactored
exception handling -- by :user:
steverep.File system calls when handling requests for static routes were moved to a
separate thread to potentially improve performance. Exception handling
was tightened in order to only return 403 Forbidden or 404 Not Found responses
for expected scenarios; 500 Internal Server Error would be returned for any
unknown errors.
Related issues and pull requests on GitHub:
:issue:
8507.Features
Added a Request.wait_for_disconnection() method, as means of allowing request handlers to be notified of premature client disconnections.
Related issues and pull requests on GitHub:
:issue:
2492.Added 5 new exceptions: :py:exc:
~aiohttp.InvalidUrlClientError, :py:exc:~aiohttp.RedirectClientError,:py:exc:
~aiohttp.NonHttpUrlClientError, :py:exc:~aiohttp.InvalidUrlRedirectClientError,:py:exc:
~aiohttp.NonHttpUrlRedirectClientError:py:exc:
~aiohttp.InvalidUrlRedirectClientError, :py:exc:~aiohttp.NonHttpUrlRedirectClientErrorare raised instead of :py:exc:
ValueErroror :py:exc:~aiohttp.InvalidURLwhen the redirect URL is invalid. Classes:py:exc:
~aiohttp.InvalidUrlClientError, :py:exc:~aiohttp.RedirectClientError,:py:exc:
~aiohttp.NonHttpUrlClientErrorare base for them.The :py:exc:
~aiohttp.InvalidURLnow exposes adescriptionproperty with the text explanation of the error details.-- by :user:
setla, :user:AraHaan, and :user:bdracoRelated issues and pull requests on GitHub:
:issue:
2507, :issue:3315, :issue:6722, :issue:8481, :issue:8482.Added a feature to retry closed connections automatically for idempotent methods. -- by :user:
DreamsorcererRelated issues and pull requests on GitHub:
:issue:
7297.Implemented filter_cookies() with domain-matching and path-matching on the keys, instead of testing every single cookie.
This may break existing cookies that have been saved with
CookieJar.save(). Cookies can be migrated with this script::Related issues and pull requests on GitHub:
:issue:
7583, :issue:8535.Separated connection and socket timeout errors, from ServerTimeoutError.
Related issues and pull requests on GitHub:
:issue:
7801.Implemented happy eyeballs
Related issues and pull requests on GitHub:
:issue:
7954.Added server capability to check for static files with Brotli compression via a
.brextension -- by :user:steverep.Related issues and pull requests on GitHub:
:issue:
8062.Removals and backward incompatible breaking changes
The shutdown logic in 3.9 waited on all tasks, which caused issues with some libraries.
In 3.10 we've changed this logic to only wait on request handlers. This means that it's
important for developers to correctly handle the lifecycle of background tasks using a
library such as
aiojobs. If an application is usinghandler_cancellation=Truethenit is also a good idea to ensure that any :func:
asyncio.shieldcalls are replaced with:func:
aiojobs.aiohttp.shield.Please read the updated documentation on these points:
https://docs.aiohttp.org/en/stable/web_advanced.html#graceful-shutdown
https://docs.aiohttp.org/en/stable/web_advanced.html#web-handler-cancellation
-- by :user:
DreamsorcererRelated issues and pull requests on GitHub:
:issue:
8495.Improved documentation
Added documentation for
aiohttp.web.FileResponse.Related issues and pull requests on GitHub:
:issue:
3958.Improved the docs for the
sslparams.Related issues and pull requests on GitHub:
:issue:
8403.Contributor-facing changes
Enabled HTTP parser tests originally intended for 3.9.2 release -- by :user:
pajod.Related issues and pull requests on GitHub:
:issue:
8088.Miscellaneous internal changes
Improved URL handler resolution time by indexing resources in the UrlDispatcher.
For applications with a large number of handlers, this should increase performance significantly.
-- by :user:
bdracoRelated issues and pull requests on GitHub:
:issue:
7829.Added
nacl_middleware <https://github.com/CosmicDNA/nacl_middleware>_ to the list of middlewares in the third party section of the documentation.Related issues and pull requests on GitHub:
:issue:
8346.Minor improvements to static typing -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8364.Added a 3.11-specific overloads to
ClientSession-- by :user:max-muoto.Related issues and pull requests on GitHub:
:issue:
8463.Simplified path checks for
UrlDispatcher.add_static()method -- by :user:steverep.Related issues and pull requests on GitHub:
:issue:
8491.Avoided creating a future on every websocket receive -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
8498.Updated identity checks for all
WSMsgTypetype compares -- by :user:bdraco.Related issues and pull requests on GitHub:
:issue:
8501.When using Python 3.12 or later, the writer is no longer scheduled on the event loop if it can finish synchronously. Avoiding event loop scheduling reduces latency and improves performance. -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
8510.Restored :py:class:
~aiohttp.resolver.AsyncResolverto be the default resolver. -- by :user:bdraco.:py:class:
~aiohttp.resolver.AsyncResolverwas disabled by default becauseof IPv6 compatibility issues. These issues have been resolved and
:py:class:
~aiohttp.resolver.AsyncResolveris again now the default resolver.Related issues and pull requests on GitHub:
:issue:
8522.v3.9.5Compare Source
==================
Bug fixes
Fixed "Unclosed client session" when initialization of
:py:class:
~aiohttp.ClientSessionfails -- by :user:NewGlad.Related issues and pull requests on GitHub:
:issue:
8253.Fixed regression (from :pr:
8280) with addingContent-Dispositionto theform-datapart after appending to writer -- by :user:
Dreamsorcerer/:user:Olegt0rr.Related issues and pull requests on GitHub:
:issue:
8332.Added default
Content-Dispositioninmultipart/form-dataresponses to avoid brokenform-data responses -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8335.v3.9.4Compare Source
==================
Bug fixes
The asynchronous internals now set the underlying causes
when assigning exceptions to the future objects
-- by :user:
webknjaz.Related issues and pull requests on GitHub:
:issue:
8089.Treated values of
Accept-Encodingheader as case-insensitive when checkingfor gzip files -- by :user:
steverep.Related issues and pull requests on GitHub:
:issue:
8104.Improved the DNS resolution performance on cache hit -- by :user:
bdraco.This is achieved by avoiding an :mod:
asynciotask creation in this case.Related issues and pull requests on GitHub:
:issue:
8163.Changed the type annotations to allow
dicton :meth:aiohttp.MultipartWriter.append,:meth:
aiohttp.MultipartWriter.append_jsonand:meth:
aiohttp.MultipartWriter.append_form-- by :user:cakemannyRelated issues and pull requests on GitHub:
:issue:
7741.Ensure websocket transport is closed when client does not close it
-- by :user:
bdraco.The transport could remain open if the client did not close it. This
change ensures the transport is closed when the client does not close
it.
Related issues and pull requests on GitHub:
:issue:
8200.Leave websocket transport open if receive times out or is cancelled
-- by :user:
bdraco.This restores the behavior prior to the change in #7978.
Related issues and pull requests on GitHub:
:issue:
8251.Fixed content not being read when an upgrade request was not supported with the pure Python implementation.
-- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
8252.Fixed a race condition with incoming connections during server shutdown -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8271.Fixed
multipart/form-datacompliance with :rfc:7578-- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8280.Fixed blocking I/O in the event loop while processing files in a POST request
-- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
8283.Escaped filenames in static view -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
8317.Fixed the pure python parser to mark a connection as closing when a
response has no length -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8320.Features
Upgraded llhttp to 9.2.1, and started rejecting obsolete line folding
in Python parser to match -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8146, :issue:8292.Deprecations (removal in next major release)
Deprecated
content_transfer_encodingparameter in :py:meth:FormData.add_field() <aiohttp.FormData.add_field>-- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8280.Improved documentation
Added a note about canceling tasks to avoid delaying server shutdown -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8267.Contributor-facing changes
The pull request template is now asking the contributors to
answer a question about the long-term maintenance challenges
they envision as a result of merging their patches
-- by :user:
webknjaz.Related issues and pull requests on GitHub:
:issue:
8099.Updated CI and documentation to use NPM clean install and upgrade
node to version 18 -- by :user:
steverep.Related issues and pull requests on GitHub:
:issue:
8116.A pytest fixture
hello_txtwas introduced to aidstatic file serving tests in
:file:
test_web_sendfile_functional.py. It dynamicallyprovisions
hello.txtfile variants shared across thetests in the module.
-- by :user:
steverepRelated issues and pull requests on GitHub:
:issue:
8136.Packaging updates and notes for downstreams
Added an
internalpytest marker for tests which should be skippedby packagers (use
-m 'not internal'to disable them) -- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8299.v3.9.3Compare Source
==================
Bug fixes
Fixed backwards compatibility breakage (in 3.9.2) of
sslparameter when set outsideof
ClientSession(e.g. directly inTCPConnector) -- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
8097, :issue:8098.Miscellaneous internal changes
Improved test suite handling of paths and temp files to consistently use pathlib and pytest fixtures.
Related issues and pull requests on GitHub:
:issue:
3957.v3.9.2Compare Source
==================
Bug fixes
Fixed server-side websocket connection leak.
Related issues and pull requests on GitHub:
:issue:
7978.Fixed
web.FileResponsedoing blocking I/O in the event loop.Related issues and pull requests on GitHub:
:issue:
8012.Fixed double compress when compression enabled and compressed file exists in server file responses.
Related issues and pull requests on GitHub:
:issue:
8014.Added runtime type check for
ClientSessiontimeoutparameter.Related issues and pull requests on GitHub:
:issue:
8021.Fixed an unhandled exception in the Python HTTP parser on header lines starting with a colon -- by :user:
pajod.Invalid request lines with anything but a dot between the HTTP major and minor version are now rejected.
Invalid header field names containing question mark or slash are now rejected.
Such requests are incompatible with :rfc:
9110#section-5.6.2and are not known to be of any legitimate use.Related issues and pull requests on GitHub:
:issue:
8074.Improved validation of paths for static resources requests to the server -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
8079.Features
Added support for passing :py:data:
Truetosslparameter inClientSessionwhiledeprecating :py:data:
None-- by :user:xiangyan99.Related issues and pull requests on GitHub:
:issue:
7698.Breaking changes
Fixed an unhandled exception in the Python HTTP parser on header lines starting with a colon -- by :user:
pajod.Invalid request lines with anything but a dot between the HTTP major and minor version are now rejected.
Invalid header field names containing question mark or slash are now rejected.
Such requests are incompatible with :rfc:
9110#section-5.6.2and are not known to be of any legitimate use.Related issues and pull requests on GitHub:
:issue:
8074.Improved documentation
Fixed examples of
fallback_charset_resolverfunction in the :doc:client_advanceddocument. -- by :user:henry0312.Related issues and pull requests on GitHub:
:issue:
7995.The Sphinx setup was updated to avoid showing the empty
changelog draft section in the tagged release documentation
builds on Read The Docs -- by :user:
webknjaz.Related issues and pull requests on GitHub:
:issue:
8067.Packaging updates and notes for downstreams
The changelog categorization was made clearer. The
contributors can now mark their fragment files more
accurately -- by :user:
webknjaz.The new category tags are:
Related issues and pull requests on GitHub:
:issue:
8066.Contributor-facing changes
Updated :ref:
contributing/Tests coverage <aiohttp-contributing>section to show how we usecodecov-- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
7916.The changelog categorization was made clearer. The
contributors can now mark their fragment files more
accurately -- by :user:
webknjaz.The new category tags are:
Related issues and pull requests on GitHub:
:issue:
8066.Miscellaneous internal changes
Replaced all
tmpdirfixtures withtmp_pathin test suite.Related issues and pull requests on GitHub:
:issue:
3551.v3.9.1Compare Source
==================
Bugfixes
Fixed importing aiohttp under PyPy on Windows.
#​7848 <https://github.com/aio-libs/aiohttp/issues/7848>_Fixed async concurrency safety in websocket compressor.
#​7865 <https://github.com/aio-libs/aiohttp/issues/7865>_Fixed
ClientResponse.close()releasing the connection instead of closing.#​7869 <https://github.com/aio-libs/aiohttp/issues/7869>_Fixed a regression where connection may get closed during upgrade. -- by :user:
Dreamsorcerer#​7879 <https://github.com/aio-libs/aiohttp/issues/7879>_Fixed messages being reported as upgraded without an Upgrade header in Python parser. -- by :user:
Dreamsorcerer#​7895 <https://github.com/aio-libs/aiohttp/issues/7895>_v3.9.0Compare Source
==================
Features
Introduced
AppKeyfor static typing support ofApplicationstorage.See https://docs.aiohttp.org/en/stable/web_advanced.html#application-s-config
#​5864 <https://github.com/aio-libs/aiohttp/issues/5864>_Added a graceful shutdown period which allows pending tasks to complete before the application's cleanup is called.
The period can be adjusted with the
shutdown_timeoutparameter. -- by :user:Dreamsorcerer.See https://docs.aiohttp.org/en/latest/web_advanced.html#graceful-shutdown
#​7188 <https://github.com/aio-libs/aiohttp/issues/7188>_Added
handler_cancellation <https://docs.aiohttp.org/en/stable/web_advanced.html#web-handler-cancellation>_ parameter to cancel web handler on client disconnection. -- by :user:mosquitoThis (optionally) reintroduces a feature removed in a previous release.
Recommended for those looking for an extra level of protection against denial-of-service attacks.
#​7056 <https://github.com/aio-libs/aiohttp/issues/7056>_Added support for setting response header parameters
max_line_sizeandmax_field_size.#​2304 <https://github.com/aio-libs/aiohttp/issues/2304>_Added
auto_decompressparameter toClientSession.requestto overrideClientSession._auto_decompress. -- by :user:Daste745#​3751 <https://github.com/aio-libs/aiohttp/issues/3751>_Changed
raise_for_statusto allow a coroutine.#​3892 <https://github.com/aio-libs/aiohttp/issues/3892>_Added client brotli compression support (optional with runtime check).
#​5219 <https://github.com/aio-libs/aiohttp/issues/5219>_Added
client_max_sizetoBaseRequest.clone()to allow overriding the request body size. -- :user:anesabml.#​5704 <https://github.com/aio-libs/aiohttp/issues/5704>_Added a middleware type alias
aiohttp.typedefs.Middleware.#​5898 <https://github.com/aio-libs/aiohttp/issues/5898>_Exported
HTTPMovewhich can be used to catch any redirection requestthat has a location -- :user:
dreamsorcerer.#​6594 <https://github.com/aio-libs/aiohttp/issues/6594>_Changed the
pathparameter inweb.run_app()to accept apathlib.Pathobject.#​6839 <https://github.com/aio-libs/aiohttp/issues/6839>_Performance: Skipped filtering
CookieJarwhen the jar is empty or all cookies have expired.#​7819 <https://github.com/aio-libs/aiohttp/issues/7819>_Performance: Only check origin if insecure scheme and there are origins to treat as secure, in
CookieJar.filter_cookies().#​7821 <https://github.com/aio-libs/aiohttp/issues/7821>_Performance: Used timestamp instead of
datetimeto achieve faster cookie expiration inCookieJar.#​7824 <https://github.com/aio-libs/aiohttp/issues/7824>_Added support for passing a custom server name parameter to HTTPS connection.
#​7114 <https://github.com/aio-libs/aiohttp/issues/7114>_Added support for using Basic Auth credentials from :file:
.netrcfile when making HTTP requests with the:py:class:
~aiohttp.ClientSessiontrust_envargument is set toTrue. -- by :user:yuvipanda.#​7131 <https://github.com/aio-libs/aiohttp/issues/7131>_Turned access log into no-op when the logger is disabled.
#​7240 <https://github.com/aio-libs/aiohttp/issues/7240>_Added typing information to
RawResponseMessage. -- by :user:Gobot1234#​7365 <https://github.com/aio-libs/aiohttp/issues/7365>_Removed
async-timeoutfor Python 3.11+ (replaced withasyncio.timeout()on newer releases).#​7502 <https://github.com/aio-libs/aiohttp/issues/7502>_Added support for
brotlicffias an alternative tobrotli(fixing Brotli support on PyPy).#​7611 <https://github.com/aio-libs/aiohttp/issues/7611>_Added
WebSocketResponse.get_extra_info()to access a protocol transport's extra info.#​7078 <https://github.com/aio-libs/aiohttp/issues/7078>_Allow
linkargument to be set to None/empty in HTTP 451 exception.#​7689 <https://github.com/aio-libs/aiohttp/issues/7689>_Bugfixes
Implemented stripping the trailing dots from fully-qualified domain names in
Hostheaders and TLS context when acting as an HTTP client.This allows the client to connect to URLs with FQDN host name like
https://example.com./.-- by :user:
martin-sucha.#​3636 <https://github.com/aio-libs/aiohttp/issues/3636>_Fixed client timeout not working when incoming data is always available without waiting. -- by :user:
Dreamsorcerer.#​5854 <https://github.com/aio-libs/aiohttp/issues/5854>_Fixed
readuntilto work with a delimiter of more than one character.#​6701 <https://github.com/aio-libs/aiohttp/issues/6701>_Added
__repr__toEmptyStreamReaderto avoidAttributeError.#​6916 <https://github.com/aio-libs/aiohttp/issues/6916>_Fixed bug when using
TCPConnectorwithttl_dns_cache=0.#​7014 <https://github.com/aio-libs/aiohttp/issues/7014>_Fixed response returned from expect handler being thrown away. -- by :user:
Dreamsorcerer#​7025 <https://github.com/aio-libs/aiohttp/issues/7025>_Avoided raising
UnicodeDecodeErrorin multipart and in HTTP headers parsing.#​7044 <https://github.com/aio-libs/aiohttp/issues/7044>_Changed
sock_readtimeout to start after writing has finished, avoiding read timeouts caused by an unfinished write. -- by :user:dtrifiro#​7149 <https://github.com/aio-libs/aiohttp/issues/7149>_Fixed missing query in tracing method URLs when using
yarl1.9+.#​7259 <https://github.com/aio-libs/aiohttp/issues/7259>_Changed max 32-bit timestamp to an aware datetime object, for consistency with the non-32-bit one, and to avoid a
DeprecationWarningon Python 3.12.#​7302 <https://github.com/aio-libs/aiohttp/issues/7302>_Fixed
EmptyStreamReader.iter_chunks()never ending. -- by :user:mind1m#​7616 <https://github.com/aio-libs/aiohttp/issues/7616>_Fixed a rare
RuntimeError: await wasn't used with futureexception. -- by :user:stalkerg#​7785 <https://github.com/aio-libs/aiohttp/issues/7785>_Fixed issue with insufficient HTTP method and version validation.
#​7700 <https://github.com/aio-libs/aiohttp/issues/7700>_Added check to validate that absolute URIs have schemes.
#​7712 <https://github.com/aio-libs/aiohttp/issues/7712>_Fixed unhandled exception when Python HTTP parser encounters unpaired Unicode surrogates.
#​7715 <https://github.com/aio-libs/aiohttp/issues/7715>_Updated parser to disallow invalid characters in header field names and stop accepting LF as a request line separator.
#​7719 <https://github.com/aio-libs/aiohttp/issues/7719>_Fixed Python HTTP parser not treating 204/304/1xx as an empty body.
#​7755 <https://github.com/aio-libs/aiohttp/issues/7755>_Ensure empty body response for 1xx/204/304 per RFC 9112 sec 6.3.
#​7756 <https://github.com/aio-libs/aiohttp/issues/7756>_Fixed an issue when a client request is closed before completing a chunked payload. -- by :user:
Dreamsorcerer#​7764 <https://github.com/aio-libs/aiohttp/issues/7764>_Edge Case Handling for ResponseParser for missing reason value.
#​7776 <https://github.com/aio-libs/aiohttp/issues/7776>_Fixed
ClientWebSocketResponse.close_codebeing erroneously set toNonewhen there are concurrent async tasks receiving data and closing the connection.#​7306 <https://github.com/aio-libs/aiohttp/issues/7306>_Added HTTP method validation.
#​6533 <https://github.com/aio-libs/aiohttp/issues/6533>_Fixed arbitrary sequence types being allowed to inject values via version parameter. -- by :user:
Dreamsorcerer#​7835 <https://github.com/aio-libs/aiohttp/issues/7835>_Performance: Fixed increase in latency with small messages from websocket compression changes.
#​7797 <https://github.com/aio-libs/aiohttp/issues/7797>_Improved Documentation
Fixed the
ClientResponse.release's type in the doc. Changed fromcomethodtomethod.#​5836 <https://github.com/aio-libs/aiohttp/issues/5836>_Added information on behavior of base_url parameter in
ClientSession.#​6647 <https://github.com/aio-libs/aiohttp/issues/6647>_Fixed
ClientResponseErrordocs.#​6700 <https://github.com/aio-libs/aiohttp/issues/6700>_Updated Redis code examples to follow the latest API.
#​6907 <https://github.com/aio-libs/aiohttp/issues/6907>_Added a note about possibly needing to update headers when using
on_response_prepare. -- by :user:Dreamsorcerer#​7283 <https://github.com/aio-libs/aiohttp/issues/7283>_Completed
trust_envparameter description to honorwss_proxy,ws_proxyorno_proxyenv.#​7325 <https://github.com/aio-libs/aiohttp/issues/7325>_Expanded SSL documentation with more examples (e.g. how to use certifi). -- by :user:
Dreamsorcerer#​7334 <https://github.com/aio-libs/aiohttp/issues/7334>_Fix, update, and improve client exceptions documentation.
#​7733 <https://github.com/aio-libs/aiohttp/issues/7733>_Deprecations and Removals
Added
shutdown_timeoutparameter toBaseRunner, whiledeprecating
shutdown_timeoutparameter fromBaseSite. -- by :user:Dreamsorcerer#​7718 <https://github.com/aio-libs/aiohttp/issues/7718>_Dropped Python 3.6 support.
#​6378 <https://github.com/aio-libs/aiohttp/issues/6378>_Dropped Python 3.7 support. -- by :user:
Dreamsorcerer#​7336 <https://github.com/aio-libs/aiohttp/issues/7336>_Removed support for abandoned
tokioevent loop. -- by :user:Dreamsorcerer#​7281 <https://github.com/aio-libs/aiohttp/issues/7281>_Misc
Made
printargument inrun_app()optional.#​3690 <https://github.com/aio-libs/aiohttp/issues/3690>_Improved performance of
ceil_timeoutin some cases.#​6316 <https://github.com/aio-libs/aiohttp/issues/6316>_Changed importing Gunicorn to happen on-demand, decreasing import time by ~53%. -- :user:
Dreamsorcerer#​6591 <https://github.com/aio-libs/aiohttp/issues/6591>_Improved import time by replacing
http.serverwithhttp.HTTPStatus.#​6903 <https://github.com/aio-libs/aiohttp/issues/6903>_Fixed annotation of
sslparameter to disallowTrue. -- by :user:Dreamsorcerer.#​7335 <https://github.com/aio-libs/aiohttp/issues/7335>_v3.8.6Compare Source
==================
Security bugfixes
Upgraded the vendored copy of llhttp_ to v9.1.3 -- by :user:
DreamsorcererThanks to :user:
kenballusfor reporting this, seehttps://github.com/aio-libs/aiohttp/security/advisories/GHSA-pjjw-qhg8-p2p9.
.. _llhttp: https://llhttp.org
#​7647 <https://github.com/aio-libs/aiohttp/issues/7647>_Updated Python parser to comply with RFCs 9110/9112 -- by :user:
DreamorcererThanks to :user:
kenballusfor reporting this, seehttps://github.com/aio-libs/aiohttp/security/advisories/GHSA-gfw2-4jvh-wgfg.
#​7663 <https://github.com/aio-libs/aiohttp/issues/7663>_Deprecation
Added
fallback_charset_resolverparameter inClientSessionto allow a user-suppliedcharacter set detection function.
Character set detection will no longer be included in 3.9 as a default. If this feature is needed,
please use
fallback_charset_resolver <https://docs.aiohttp.org/en/stable/client_advanced.html#character-set-detection>_.#​7561 <https://github.com/aio-libs/aiohttp/issues/7561>_Features
Enabled lenient response parsing for more flexible parsing in the client
(this should resolve some regressions when dealing with badly formatted HTTP responses). -- by :user:
Dreamsorcerer#​7490 <https://github.com/aio-libs/aiohttp/issues/7490>_Bugfixes
Fixed
PermissionErrorwhen.netrcis unreadable due to permissions.#​7237 <https://github.com/aio-libs/aiohttp/issues/7237>_Fixed output of parsing errors pointing to a
\n. -- by :user:Dreamsorcerer#​7468 <https://github.com/aio-libs/aiohttp/issues/7468>_Fixed
GunicornWebWorkermax_requests_jitter not working.#​7518 <https://github.com/aio-libs/aiohttp/issues/7518>_Fixed sorting in
filter_cookiesto use cookie with longest path. -- by :user:marq24.#​7577 <https://github.com/aio-libs/aiohttp/issues/7577>_Fixed display of
BadStatusLinemessages from llhttp_. -- by :user:Dreamsorcerer#​7651 <https://github.com/aio-libs/aiohttp/issues/7651>_v3.8.5Compare Source
==================
Security bugfixes
Upgraded the vendored copy of llhttp_ to v8.1.1 -- by :user:
webknjazand :user:
Dreamsorcerer.Thanks to :user:
sethmlarsonfor reporting this and providing us withcomprehensive reproducer, workarounds and fixing details! For more
information, see
https://github.com/aio-libs/aiohttp/security/advisories/GHSA-45c4-8wx5-qw6w.
.. _llhttp: https://llhttp.org
#​7346 <https://github.com/aio-libs/aiohttp/issues/7346>_Features
Added information to C parser exceptions to show which character caused the error. -- by :user:
Dreamsorcerer#​7366 <https://github.com/aio-libs/aiohttp/issues/7366>_Bugfixes
Fixed a transport is :data:
Noneerror -- by :user:Dreamsorcerer.#​3355 <https://github.com/aio-libs/aiohttp/issues/3355>_v3.8.4Compare Source
==================
Bugfixes
#​6638 <https://github.com/aio-libs/aiohttp/issues/6638>_ConnectionResetErrornot being raised after client disconnection in SSL environments.#​7180 <https://github.com/aio-libs/aiohttp/issues/7180>_Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever MR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this MR and you won't be reminded about this update again.
This MR has been generated by Renovate Bot.
Automated review (posted as
hermes).What it does —
Update dependency aiohttp to v3.13.0Touches 1 file(s), +1/-1.
Files:
a/requirements.txt,b/requirements.txtKey changed lines:
aiohttp==3.13.0State — author
Ghost(the original GitLab Renovate account was deleted in the migration, so this re-attributed to the deleted-user placeholder), opened 2025-10-10, mergeable=True, repo archived=False.Verdict — repo is live; worth a human look before merging.
Closing as part of the archived-repo cleanup: this repository is archived, so this pull request cannot be merged.
Pull request closed