Fetch.Redirect (Fetch v0.1.0)
View SourceDecides whether a response is a redirect and builds the next request.
Only these statuses are followed (RFC 9110 §15.4):
| status | next request |
|---|---|
| 301 Moved Permanently, 302 Found | POST becomes GET, other methods are kept |
| 303 See Other | anything but HEAD becomes GET |
| 307 Temporary Redirect, 308 Permanent Redirect | same method and body |
301 and 302 were meant to keep the method, but browsers turned POST into GET and the RFC now allows it. 307 and 308 were added to say "really keep it". Other 3xx codes (300 Multiple Choices, 304 Not Modified) are responses, not instructions to follow.
When the method becomes GET, the body and the headers describing it are dropped. When the redirect leaves the origin (scheme, host or port), credentials are dropped, so a redirect cannot leak them to another server.
Summary
Functions
Returns the request to send after response, :none when the response is
not a redirect to follow, or an error when the redirect is broken.
Types
@type request() :: %{ method: Fetch.Request.method(), url: Fetch.URL.t(), headers: Fetch.Request.headers(), body: iodata() | nil }
Functions
@spec next_request(request(), Fetch.Response.t()) :: {:ok, request()} | :none | {:error, {:redirect, term()}}
Returns the request to send after response, :none when the response is
not a redirect to follow, or an error when the redirect is broken.