Skip to content

Remove url dependency, add feature flags for WebSocket and TLS support - #1659

Open
torkelrogstad wants to merge 4 commits into
paritytech:masterfrom
torkelrogstad:2026-09-30-remove-deps
Open

torkelrogstad wants to merge 4 commits into
paritytech:masterfrom
torkelrogstad:2026-09-30-remove-deps

Conversation

@torkelrogstad

Copy link
Copy Markdown

Motivation for removing url is in the commit message.

In total this allows for reducing the dependency graph of this library by quite a lot. For example a regular http-client goes from 103 to 76 members in the dependency graph. Going to http-client-no-tls reduces it further to 58. Removing WebSocket from the server by doing http-server instead of server, we go from 90 to 74.

The HTTP client only used `url` to validate and normalize the target, but it
pulls in `idna` and the ICU crates, about 27 crates in total. Parse the target
with `http::Uri` instead, which is already available through `hyper`.

Normalization is unchanged: scheme and host are lowercased, the default port
is omitted, an empty path becomes `/` and the fragment is dropped. Credentials
in the userinfo are still moved into a basic `Authorization` header.

Unlike `url`, non-ASCII hosts and paths are now rejected rather than
punycode/percent-encoded, and dot segments in the path are kept as is.

The WebSocket client and transport still depend on `url`, since `Url` is part
of their public API.
Add a `ws` feature to `jsonrpsee-server`, enabled by default, which gates the
WebSocket transport and with it `soketto` and its SHA-1 and `rand`
dependencies. Without it, upgrade requests are handled as plain HTTP requests
and `ServerConfigBuilder::ws_only` is unavailable. The ping and subscription
settings remain but have no effect.

Add an `http-server` feature to `jsonrpsee` for the server without WebSocket
support. `server` enables the same as before.

Users of `jsonrpsee-server` that already set `default-features = false` now
need to enable `ws` explicitly.
The `http-client` feature enables `jsonrpsee-http-client` with its default
features, so users of the `jsonrpsee` crate can't opt out of TLS and always
build `rustls` and `ring`, even if they only talk plain HTTP.

Add an `http-client-no-tls` feature for the HTTP client without TLS, like the
existing `client-ws-transport-no-tls`. `http-client` enables the same as
before.
Comment thread client/http-client/src/transport.rs Outdated
Comment on lines +571 to +574
let client = HttpTransportClientBuilder::new().build("http://user:p%40ss@localhost:9999/path").unwrap();
assert_eq!(&client.target, "http://localhost:9999/path");
// base64 of "user:p%40ss"
assert_eq!(client.headers[hyper::header::AUTHORIZATION], "Basic dXNlcjpwJTQwc3M=");

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It should be base64 of user:p@ss, not user:p%40ss. This an existing issue, see #1639.

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @0e4ef622 , fixed

Credentials in the URL userinfo were base64-encoded as written, so
`http://user:p%40ss@host` sent `user:p%40ss` instead of `user:p@ss` in
the `Authorization: Basic` header. Decode them first.

Fixes paritytech#1639 for the HTTP client.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants