Fetch.Redirect (Fetch v0.1.0)

View Source

Decides whether a response is a redirect and builds the next request.

Only these statuses are followed (RFC 9110 §15.4):

statusnext request
301 Moved Permanently, 302 FoundPOST becomes GET, other methods are kept
303 See Otheranything but HEAD becomes GET
307 Temporary Redirect, 308 Permanent Redirectsame method and body

301 and 302 were meant to keep the method, but browsers turned POST into GET and the RFC now allows it. 307 and 308 were added to say "really keep it". Other 3xx codes (300 Multiple Choices, 304 Not Modified) are responses, not instructions to follow.

When the method becomes GET, the body and the headers describing it are dropped. When the redirect leaves the origin (scheme, host or port), credentials are dropped, so a redirect cannot leak them to another server.

Summary

Functions

Returns the request to send after response, :none when the response is not a redirect to follow, or an error when the redirect is broken.

Types

request()

@type request() :: %{
  method: Fetch.Request.method(),
  url: Fetch.URL.t(),
  headers: Fetch.Request.headers(),
  body: iodata() | nil
}

Functions

next_request(request, response)

@spec next_request(request(), Fetch.Response.t()) ::
  {:ok, request()} | :none | {:error, {:redirect, term()}}

Returns the request to send after response, :none when the response is not a redirect to follow, or an error when the redirect is broken.