Patch Changes
-
#70
b974208Thanks @JounQin! - fix: align the oneshot client with the DeepL iOS request profileThe anonymous oneshot request now mirrors the official DeepL iOS app, matching
the reverse engineering in OwO-Network/DLX:- The iOS
User-Agent(DeepL/26.42 CFNetwork/3826.600.41 Darwin/25.0.0) and
the threeClientInfos.appHeaderskeys (x-app-os-version,
x-app-instance-id,x-app-session-id) replace the Chrome-extension profile
(Origin: chrome-extension://…, theSec-Fetch-*set and the Chrome UA). app_informationreports the iOS app (os: "iOS",os_version: "26.0",
app_version: "26.42",app_build: "5443737") andusage_typeis the
lower-case"translate", exactly as the iOS client serializes it.- New exports
IOS_APP_VERSION,IOS_APP_BUILD,IOS_OS_VERSION,
IOS_CFNETWORK_VERSION,IOS_DARWIN_VERSIONandHTTP_STATUS_FORBIDDEN; the
Chrome-extension constants are deprecated but still exported so the public
surface does not break. - An HTTP 403 from DeepL is surfaced with the upstream
title/messagedetail
instead of a bare status text.
The iOS TLS ClientHello (utls
HelloIOS_Autoupstream) cannot be reproduced on
fetch, so the runtime's own TLS stack is used and only the HTTP profile is
aligned. - The iOS
-
#68
830ff11Thanks @JounQin! - fix: readSet-CookiethroughgetSetCookie()when availableHeaders.getSetCookie()is the accessor the current Fetch spec requires, and a
runtime that hidesSet-Cookiefromheaders.get()must provide it. Reading the
warm-up cookies through it parses eachSet-Cookieseparately instead of
depending on comma-joined concatenation, so we no longer rely on the non-standard
get('set-cookie')behaviour of some runtimes.Measured on workerd 1.20260625.1:
get('set-cookie')returns a joined string
(notnull) at every compatibility date tried,getSetCookie()is enabled by the
http_headers_getsetcookiecompatibility flag and on by default from
compatibility date2023-03-01(undefined at2023-02-01, present at
2023-03-01), and Workers' owngetAll('set-cookie')also exists -- Cloudflare's
docs are stale here. workerd behaviour is therefore unchanged by this patch: it is
a portability and robustness fix, not a fix for the reported "silent echo",
which is DeepL answering200with the input text whenever it declines to
translate.