<turbo-stream action="append" target="posts_list"><template>    <div class="postbit" id="389990" data-post-id="389990">
  <section>
    <div class="post-wrap">


					<div class="post-header">
		        <div class="user-avatar">
		          <img alt="wojtekmach" src="https://forum.elixirforum.com/user_avatar/forum.elixirforum.com/wojtekmach/120/999_2.png" width="120" height="120" />
		        </div>
					
						<div class="user-details">
		          <div class="user-name">
		            <h3>
                  wojtekmach
                    <span class="op-star" title="Thread Starter">
                      <img alt="OP" class="op-star-icon" src="/assets/thread-icons/thread-icon-thread-starter-df91e872.png" />
                    </span>
                  </h3>
		          </div>
						
			          <div class="user-title">
									<span>Hex Core Team</span>
			          </div>
						</div>
					
					</div>

	        <div class="thread-main">
	            <div class="post-body" data-turbo="false">
								<p>Correct, if someone opts in and ends up hitting a malicious server, there are no other mitigations at the moment for eagerly reading response body, ie just Req.get. When using streaming, via into: fun, one can keep an accumulator of read bytes and and bail; automatic decompression for :into was never available in the first place (that’s something I plan to allow in future release however).</p>
<p>Im planning to revamp streaming from into: fun to an explicit Req.stream(req, acc, fun), and allow streaming decompression AND decoding. And a :max_body_size option, which I think will have to default to :infinity however, so at least that’d be an easy knob to turn. Stay tuned.</p> 
	            </div>

	            <div class="base-line">
	                <div class="thread-counters">
	                    <span class="thread-count count-likes js-likers-trigger" title="Likes" data-post-id="389990" data-batch-url="/posts/batch_likers">
                        2
                      </span>
                      <!-- <span class="thread-count js-solved-indicator" title="Marked as solution"></span> -->
	                </div>
	                <div class="go-to-post">
	                  <a title="Go to post" alt="Go to post" href="https://forum.elixirforum.com/t/req-a-batteries-included-http-client-for-elixir/48494/62">Post #61</a>
	                </div>
	            </div>
              <div id="likers-container-389990" 
                   class="likers-container"
                   data-first-post="false"
                   data-batch-url="/posts/batch_likers">
                   <div class="likers-placeholder" 
                     data-likers-post-id="389990"
                     data-batch-url="/posts/batch_likers">
                  <div class="post-likers"></div>
                </div>
              </div>
	        </div>
			

    </div>

    <div class="triangle-top-right type-standard-post cat-standard-post" title="Post #61"></div>
  </section>
</div>
    <div class="postbit" id="389991" data-post-id="389991">
  <section>
    <div class="post-wrap">


					<div class="post-header">
		        <div class="user-avatar">
		          <img alt="dimitarvp" src="https://forum.elixirforum.com/user_avatar/forum.elixirforum.com/dimitarvp/120/38664_2.png" width="120" height="120" />
		        </div>
					
						<div class="user-details">
		          <div class="user-name">
		            <h3>
                  dimitarvp
                  </h3>
		          </div>
						
						</div>
					
					</div>

	        <div class="thread-main">
	            <div class="post-body" data-turbo="false">
								<aside class="quote group-Hex-Core-Team" data-username="wojtekmach" data-post="62" data-topic="48494">
<div class="title">
<div class="quote-controls"></div>
<img alt="" width="24" height="24" src="https://forum.elixirforum.com/user_avatar/forum.elixirforum.com/wojtekmach/48/999_2.png" class="avatar"> wojtekmach:</div>
<blockquote>
<p>Im planning to revamp streaming from into: fun to an explicit Req.stream(req, acc, fun), and allow streaming decompression AND decoding.</p>
</blockquote>
</aside>
<p>That’s what my eternally-upcoming SQLite3 library is doing. I found it the better pattern. It’s actually dual-use: I have a higher-level helper that supplies the functions (private inside the library) and it also allows you to plug functions to the lower-level streaming function.</p>
<aside class="quote group-Hex-Core-Team" data-username="wojtekmach" data-post="62" data-topic="48494">
<div class="title">
<div class="quote-controls"></div>
<img alt="" width="24" height="24" src="https://forum.elixirforum.com/user_avatar/forum.elixirforum.com/wojtekmach/48/999_2.png" class="avatar"> wojtekmach:</div>
<blockquote>
<p>When using streaming, via into: fun, one can keep an accumulator of read bytes and and bail</p>
</blockquote>
</aside>
<p>Yeah, best security measure against bloated payloads are conservative limits that the user/client of the library enforces themselves. We’re about to open our service to much more webhooks and I’d really love to start using Req with that upcoming feature. Currently we are using Tesla (with Finch below) as we can plug anything and everything. We probably can make it work just fine with Req as well but I’d feel much better if you made this particular thing a first-class feature and vetted it.</p>
<p>Looking forward. Thanks again for relentlessly working on this library (and many others).</p> 
	            </div>

	            <div class="base-line">
	                <div class="thread-counters">
	                    <span class="thread-count count-likes js-likers-trigger" title="Likes" data-post-id="389991" data-batch-url="/posts/batch_likers">
                        0
                      </span>
                      <!-- <span class="thread-count js-solved-indicator" title="Marked as solution"></span> -->
	                </div>
	                <div class="go-to-post">
	                  <a title="Go to post" alt="Go to post" href="https://forum.elixirforum.com/t/req-a-batteries-included-http-client-for-elixir/48494/63">Post #62</a>
	                </div>
	            </div>
              <div id="likers-container-389991" 
                   class="likers-container"
                   data-first-post="false"
                   data-batch-url="/posts/batch_likers">
                   <div class="likers-placeholder" 
                     data-likers-post-id="389991"
                     data-batch-url="/posts/batch_likers">
                  <div class="post-likers"></div>
                </div>
              </div>
	        </div>
			

    </div>

    <div class="triangle-top-right type-standard-post cat-standard-post" title="Post #62"></div>
  </section>
</div>
    <div class="postbit" id="389997" data-post-id="389997">
  <section>
    <div class="post-wrap">


					<div class="post-header">
		        <div class="user-avatar">
		          <img alt="jswanner" src="https://forum.elixirforum.com/user_avatar/forum.elixirforum.com/jswanner/120/24585_2.png" width="120" height="120" />
		        </div>
					
						<div class="user-details">
		          <div class="user-name">
		            <h3>
                  jswanner
                  </h3>
		          </div>
						
						</div>
					
					</div>

	        <div class="thread-main">
	            <div class="post-body" data-turbo="false">
								<aside class="quote group-Hex-Core-Team" data-username="wojtekmach" data-post="62" data-topic="48494">
<div class="title">
<div class="quote-controls"></div>
<img alt="" width="24" height="24" src="https://forum.elixirforum.com/user_avatar/forum.elixirforum.com/wojtekmach/48/999_2.png" class="avatar"> wojtekmach:</div>
<blockquote>
<p>Im planning to revamp streaming from into: fun to an explicit Req.stream(req, acc, fun)</p>
</blockquote>
</aside>
<p>You’ve made me very curious about your plans here, <a class="mention" href="/u/wojtekmach" rel="nofollow">@wojtekmach</a></p>
<p>Echoing <a class="mention" href="/u/dimitarvp" rel="nofollow">@dimitarvp</a>: thanks for all your work addressing the CVEs and the latest releases!</p> 
	            </div>

	            <div class="base-line">
	                <div class="thread-counters">
	                    <span class="thread-count count-likes js-likers-trigger" title="Likes" data-post-id="389997" data-batch-url="/posts/batch_likers">
                        0
                      </span>
                      <!-- <span class="thread-count js-solved-indicator" title="Marked as solution"></span> -->
	                </div>
	                <div class="go-to-post">
	                  <a title="Go to post" alt="Go to post" href="https://forum.elixirforum.com/t/req-a-batteries-included-http-client-for-elixir/48494/64">Post #63</a>
	                </div>
	            </div>
              <div id="likers-container-389997" 
                   class="likers-container"
                   data-first-post="false"
                   data-batch-url="/posts/batch_likers">
                   <div class="likers-placeholder" 
                     data-likers-post-id="389997"
                     data-batch-url="/posts/batch_likers">
                  <div class="post-likers"></div>
                </div>
              </div>
	        </div>
			

    </div>

    <div class="triangle-top-right type-standard-post cat-standard-post" title="Post #63"></div>
  </section>
</div>
    <div class="postbit" id="392890" data-post-id="392890">
  <section>
    <div class="post-wrap">


					<div class="post-header">
		        <div class="user-avatar">
		          <img alt="wojtekmach" src="https://forum.elixirforum.com/user_avatar/forum.elixirforum.com/wojtekmach/120/999_2.png" width="120" height="120" />
		        </div>
					
						<div class="user-details">
		          <div class="user-name">
		            <h3>
                  wojtekmach
                    <span class="op-star" title="Thread Starter">
                      <img alt="OP" class="op-star-icon" src="/assets/thread-icons/thread-icon-thread-starter-df91e872.png" />
                    </span>
                  </h3>
		          </div>
						
			          <div class="user-title">
									<span>Hex Core Team</span>
			          </div>
						</div>
					
					</div>

	        <div class="thread-main">
	            <div class="post-body" data-turbo="false">
								<p>Hey everyone, Req v0.8-rc.0 is out! It’s a release candidate because there have been a lot of internal changes and some user-facing ones. I’m looking forward to any feedback and please try out the RC on your projects, especially the brand new <a href="https://hexdocs.pm/req/0.8.0-rc.0/Req.html#stream/4" rel="noopener nofollow ugc"><code>Req.stream/4</code></a> API!</p>
<pre data-code-wrap="elixir"><code class="lang-elixir">{:req, "~&gt; 0.8.0-rc", override: true}
</code></pre>
<hr>
<p>(From the <a href="https://github.com/wojtekmach/req/blob/main/CHANGELOG.md" rel="noopener nofollow ugc">changelog</a>)</p>
<p>Req v0.8 brings more ergonomic streaming with <a href="https://hexdocs.pm/req/0.8.0-rc.0/Req.html#stream/4" rel="noopener nofollow ugc"><code>Req.stream/4</code></a>, streaming decompression and decoding, automatic NDJSON &amp; SSE decoding, and more.</p>
<p>Req v0.8 has revamped internals though most end-users should be unaffected. Req’s initial design included response/error steps which are now deprecated as we couldn’t use them for extensible streaming decoding. Instead, we’re adding step <em>wrappers</em>. See <a rel="nofollow">“Steps &amp; Step Wrappers” section</a> in <a href="https://hexdocs.pm/req/0.8.0-rc.0/Req.Request.html" rel="noopener nofollow ugc"><code>Req.Request</code></a> module documentation for more information.</p>
<p>Req v0.8 requires Elixir 1.18+.</p>
<h3><a name="p-392890-enhancements-1" class="anchor" href="#p-392890-enhancements-1" aria-label="Heading link" rel="nofollow"></a>Enhancements</h3>
<ul>
<li>
<p><a href="https://hexdocs.pm/req/0.8.0-rc.0/Req.html" rel="noopener nofollow ugc"><code>Req</code></a>: Add <a href="https://hexdocs.pm/req/0.8.0-rc.0/Req.html#stream/4" rel="noopener nofollow ugc"><code>Req.stream/4</code></a>.</p>
</li>
<li>
<p><a href="https://hexdocs.pm/req/0.8.0-rc.0/Req.html" rel="noopener nofollow ugc"><code>Req</code></a>: Allow setting private through options, e.g.: <code>Req.new(private: %{foo: :bar})</code>.</p>
</li>
<li>
<p><a href="https://hexdocs.pm/req/0.8.0-rc.0/Req.html" rel="noopener nofollow ugc"><code>Req</code></a>: Support request body streaming with <code>body: fun</code>.</p>
</li>
<li>
<p><a href="https://hexdocs.pm/req/0.8.0-rc.0/Req.Response.html" rel="noopener nofollow ugc"><code>Req.Response</code></a>: Add <code>resp.request</code>. This is useful to inspect the final request after all steps have executed.</p>
</li>
<li>
<p><a href="https://hexdocs.pm/req/0.8.0-rc.0/Req.Decompress.html" rel="noopener nofollow ugc"><code>Req.Decompress</code></a>: Support <code>into: collectable</code>.</p>
</li>
<li>
<p><a href="https://hexdocs.pm/req/0.8.0-rc.0/Req.Decode.html" rel="noopener nofollow ugc"><code>Req.Decode</code></a>: Support NDJSON.</p>
</li>
<li>
<p><a href="https://hexdocs.pm/req/0.8.0-rc.0/Req.Decode.html" rel="noopener nofollow ugc"><code>Req.Decode</code></a>: Support SSE.</p>
</li>
<li>
<p><a href="https://hexdocs.pm/req/0.8.0-rc.0/Req.Decode.html" rel="noopener nofollow ugc"><code>Req.Decode</code></a>: Support <code>decoders: [{content_type, decoder}]</code>, for example: <code>[{"application/x-amz-json-1.0", :json}]</code>.</p>
</li>
<li>
<p><a href="https://hexdocs.pm/req/0.8.0-rc.0/Req.Decode.html" rel="noopener nofollow ugc"><code>Req.Decode</code></a>: JSON decoding is now using a streaming parser (Erlang/OTP <a href="https://www.erlang.org/doc/apps/stdlib/json.html#decode_start/3" rel="nofollow"><code>:json.decode_start/3</code></a>, <a href="https://www.erlang.org/doc/apps/stdlib/json.html#decode_continue/2" rel="nofollow"><code>:json.decode_continue/2</code></a>).</p>
</li>
</ul>
<h3><a name="p-392890-breaking-changes-2" class="anchor" href="#p-392890-breaking-changes-2" aria-label="Heading link" rel="nofollow"></a>Breaking Changes</h3>
<ul>
<li>Remove jason dependency. <code>Req.post(url, json: term)</code> will now use <code>JSON.encode!/2</code>, not <code>Jason.encode!/2</code>, that is, <code>term</code> must implement <a href="https://hexdocs.pm/elixir/JSON.Encoder.html" rel="noopener nofollow ugc"><code>JSON.Encoder</code></a> protocol.</li>
<li>Remove deprecated <code>:finch_request</code> option</li>
<li>Remove deprecated <code>into: :legacy_self</code></li>
<li>Remove deprecated <code>cache</code> step</li>
<li>Replace <code>compressed</code> and <code>decompress_body</code> with <a href="https://hexdocs.pm/req/0.8.0-rc.0/Req.Decompress.html" rel="noopener nofollow ugc"><code>Req.Decompress</code></a>.</li>
<li>Replace <code>handle_http_errors</code> with <a href="https://hexdocs.pm/req/0.8.0-rc.0/Req.Expect.html" rel="noopener nofollow ugc"><code>Req.Expect</code></a>.</li>
<li>Replace <code>auth</code> and <code>http_digest</code> steps with <a href="https://hexdocs.pm/req/0.8.0-rc.0/Req.Auth.html" rel="noopener nofollow ugc"><code>Req.Auth</code></a>.</li>
<li>Replace <code>redirect</code> with <a href="https://hexdocs.pm/req/0.8.0-rc.0/Req.Redirect.html" rel="noopener nofollow ugc"><code>Req.Redirect</code></a></li>
<li>Replace <code>retry</code> with <a href="https://hexdocs.pm/req/0.8.0-rc.0/Req.Retry.html" rel="noopener nofollow ugc"><code>Req.Retry</code></a></li>
<li>Replace <code>checksum</code> with <a href="https://hexdocs.pm/req/0.8.0-rc.0/Req.Checksum.html" rel="noopener nofollow ugc"><code>Req.Checksum</code></a></li>
<li>Replace <code>decode_body</code> with <a href="https://hexdocs.pm/req/0.8.0-rc.0/Req.Decode.html" rel="noopener nofollow ugc"><code>Req.Decode</code></a></li>
</ul> 
	            </div>

	            <div class="base-line">
	                <div class="thread-counters">
	                    <span class="thread-count count-likes js-likers-trigger" title="Likes" data-post-id="392890" data-batch-url="/posts/batch_likers">
                        10
                      </span>
                      <!-- <span class="thread-count js-solved-indicator" title="Marked as solution"></span> -->
	                </div>
	                <div class="go-to-post">
	                  <a title="Go to post" alt="Go to post" href="https://forum.elixirforum.com/t/req-a-batteries-included-http-client-for-elixir/48494/65">Post #64</a>
	                </div>
	            </div>
              <div id="likers-container-392890" 
                   class="likers-container"
                   data-first-post="false"
                   data-batch-url="/posts/batch_likers">
                   <div class="likers-placeholder" 
                     data-likers-post-id="392890"
                     data-batch-url="/posts/batch_likers">
                  <div class="post-likers"></div>
                </div>
              </div>
	        </div>
			

    </div>

    <div class="triangle-top-right type-last-post cat-last-post" title="Last post!"></div>
  </section>
</div>
</template></turbo-stream><turbo-stream action="replace" target="load-more-container"><template><div id="load-more-container" class="load-more-container">
    <span class="all-loaded">— All posts loaded —</span>
</div></template></turbo-stream>