Skip to content

[@vercel/blob] Allow get() to fetch from a VERCEL_BLOB_API_URL origin - #1110

Merged
falcoagustin merged 2 commits into
mainfrom
falcoagustin/blob-get-local-origin
Oct 6, 2026
Merged

falcoagustin merged 2 commits into
mainfrom
falcoagustin/blob-get-local-origin

Conversation

@falcoagustin

@falcoagustin falcoagustin commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

Problem

get() rejects any URL whose hostname isn't *.blob.vercel-storage.com. That check was added as an SSRF guard, but it also blocks local emulation: both emulate (blob support) and vercel/blob-local serve blob content from their own host, so get(blob.url) throws before any request is made. Every other command (put, head, list, del) already works against an emulator because they route through VERCEL_BLOB_API_URL.

Raised by @scotttrinh in #help-cdn while adding Blob coverage to emulate (#278) for the upcoming Python and Go SDKs.

Solution

get() now also accepts URLs on the same origin as a VERCEL_BLOB_API_URL / NEXT_PUBLIC_VERCEL_BLOB_API_URL override. With no override set, nothing changes — arbitrary hosts, subdomain spoofing and plain localhost are all still rejected, so production behavior and the SSRF guard are untouched.

Two things stay as they are, both because the SDK can't know an emulator's URL layout:

  • Pathname input still builds a production store URL. Emulator users pass the URL returned by put/head, which is what emulate already resolves on its side.
  • For an emulator URL, blob.pathname keeps the emulator's route prefix (vercel/blob/store_123/foo.txt, not foo.txt), since it's derived from the URL path.

Why: You couldn't read a blob back when pointing the SDK at a local emulator — writes worked, reads threw "the URL does not point to a Vercel Blob store". Now, if you've explicitly told the SDK where its API lives, reads from that same host are allowed too, which is what unblocks emulate and keeps the Python SDK from having to hardcode the hostname check.

No feature flag: this is an npm SDK, and the change is self-gating — it only takes effect when VERCEL_BLOB_API_URL is set, which is already an opt-in for non-production use. Rollback is a version revert.

🤖 Generated with Claude Code

get() only accepted URLs on *.blob.vercel-storage.com, which blocked local
emulators that serve blob content from their own host.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@changeset-bot

changeset-bot Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: d1a1576

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 2 packages
Name Type
@vercel/blob Patch
vercel-storage-integration-test-suite Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercel Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
vercel-storage-next-integration-test-suite Ready Ready Preview Oct 5, 2026 8:26pm UTC

Request Review

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@falcoagustin
falcoagustin enabled auto-merge (squash) October 5, 2026 20:32
@falcoagustin
falcoagustin merged commit 59be092 into main Oct 6, 2026
12 of 21 checks passed
@falcoagustin
falcoagustin deleted the falcoagustin/blob-get-local-origin branch October 6, 2026 07:41

This branch was successfully deployed

1 active deployment
Preview — d1a1576c Deployed Oct 5, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants