Skip to content

Upgrade Ruby and Faraday + bug fixes - #8

Merged
ehimen-io merged 4 commits into
mainfrom
owens/vertebrae-upgrade
Sep 29, 2026
Merged

ehimen-io merged 4 commits into
mainfrom
owens/vertebrae-upgrade

Conversation

@ehimen-io

@ehimen-io ehimen-io commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Fixes a bug where Vertebrae::Request#request applied the connection's prefix twice, so a default / prefix plus an already-absolute path (e.g. identity-api-client's /api/member/details) produced a leading //. Faraday treats that as a protocol-relative URL and mangles it into malformed URLs like https://host////api/path.
  • Note: this was originally suspected as the cause of 403s in Tokyo's Identity error reports, but 38 Degrees has since confirmed identical malformed requests succeeding on their end, and error reports for the same URL shape show varying statuses (403, 409) rather than one consistent rejection — which points to their infrastructure normalizing/tolerating the extra slashes rather than rejecting them. So this almost certainly isn't the cause of that specific incident. It's still a real, independently-reproducible URL construction bug (confirmed by 5 pre-existing failing specs in spec/request_spec.rb that this also fixes), and worth having fixed regardless of whether it explains that incident.
  • Modernizes the repo: Ruby bumped to 4.0.1 (CI matrix 3.3/3.4/4.0), Faraday pinned to ~> 2.0, dependencies consolidated into the gemspec, dead Rakefile/Gemfile cruft removed, CHANGELOG added.
  • Version bumped to 2.0.0 (breaking: Ruby floor raised, Faraday now pinned).

Test plan

  • bundle exec rspec — 51 examples, 0 failures
  • bundle exec rubocop — no offenses
  • bundle install resolves cleanly under Ruby 4.0.1

🤖 Generated with Claude Code

Request#request applied the connection's prefix twice: once baked
into the Faraday base URL via Configuration#endpoint, and again via
string concatenation. With the default '/' prefix and a caller path
that already starts with '/' (e.g. identity-api-client's
'/api/member/details'), this produced a leading '//', which Faraday
treats as a protocol-relative URL and mangles, yielding malformed
URLs like https://host////api/path. Some upstream APIs reject these
at the edge with a bare 403.

Join prefix and path so they always meet with exactly one slash,
regardless of whether either side already has one. This also fixes
5 pre-existing failures in the request spec.
- Bump .ruby-version to 4.0.1; CI now runs the matrix 3.3/3.4/4.0
  on actions/checkout@v4 and ruby/setup-ruby@v1
- Remove legacy .ruby-gemset (RVM artifact)
- Simplify Gemfile to source + gemspec; move all dependencies into
  vertebrae.gemspec with explicit version constraints, drop the
  unused juwelier dev dependency, set required_ruby_version and
  rubygems_mfa_required
- Simplify Rakefile to bundler/gem_tasks + rspec rake task
- Add CHANGELOG.md and a Requirements section to the README
- Bump version to 2.0.0 (breaking: Ruby floor raised, faraday now
  pinned ~> 2.0)
@ehimen-io ehimen-io changed the title Fix duplicate-slash request bug and modernize Ruby/Faraday support Upgrade Ruby and Faraday + bug fixes Sep 28, 2026
@ehimen-io
ehimen-io marked this pull request as ready for review September 28, 2026 16:50

@woodhull woodhull left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

Comment thread CHANGELOG.md Outdated
reject at the edge with a bare 403.

### Breaking Changes
- Dropped support for Ruby versions older than 3.3. Officially supported versions are Ruby 3.3, 3.4, and 4.0.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

we could also drop 3.3 i think.

Officially supported versions are now 3.4 and 4.0.
@ehimen-io
ehimen-io merged commit a7a06c0 into main Sep 29, 2026
3 checks passed
@ehimen-io
ehimen-io deleted the owens/vertebrae-upgrade branch September 29, 2026 17:39
ehimen-io added a commit to controlshift/action_kit_rest that referenced this pull request Sep 29, 2026
* Loosen vertebrae dependency to allow 2.x

vertebrae 2.0.0 fixes a bug where the request path was built with a
duplicated prefix, producing malformed URLs with multiple consecutive
slashes for any client passing an already-absolute path (see
controlshift/vertebrae#8). The previous ~> 1.0.5 pin blocked
upgrading. Verified action_kit_rest's own spec suite (44 examples)
passes unchanged against vertebrae 2.0.0.

* Bump version to 1.0.1
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants