Repository navigation
Fetch the pinned commit for Composer branch downloads - #430
Open
pinguinfuss wants to merge 4 commits into
Open
pinguinfuss wants to merge 4 commits into
pinguinfuss wants to merge 4 commits into
Conversation
The download handler resolved a version's dist URL from the current metadata and cached the archive under whatever file name the client asked for. A lock file pinning an older commit of a branch like dev-master got the branch head, stored and served as that older commit. Downloads now fetch the commit the file name stands for when the dist URL ends in a commit hash (GitHub zipballs, Bitbucket archives), and return 404 for other names the metadata no longer lists.
Proxy versions before the .zip suffix handed out GitHub zipball URLs ending in the bare commit hash. Lock files written back then still ask for those names, and the new file name check turned them into 404s.
A tagged release lists one commit and lock files ask for that one. Rebuilding the URL for any requested commit let a client store another commit, even one from a fork, as the release, and the browse view could then show it.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Found while working on Composer retention (#306).
For branch versions like
dev-master, the download handler fetched whatever commit the metadata lists now and cached it under the file name the client asked for. Acomposer.lockpinning an older commit got the current head, cached under the old commit's name. GitHub zipballs have no shasum, so Composer doesn't notice.Now the requested file has to match the metadata. For branches with commit-hash dist URLs (GitHub, Bitbucket), the proxy fetches the requested commit, as Composer would without the proxy. Tagged releases only get the listed commit. Anything else returns a 404 instead of the wrong archive. Bare hashes without
.zip, from proxy versions before 0.2.1, still work.Not fixed here:
archive.zipdev-feature/x) don't match the download route