#Okay so I looked into this, and

1 messages ยท Page 1 of 1 (latest)

urban solstice
#

Do you mean it's not a problem with aiohttp?

rotund trail
#

Apparently not

#

Originally I thought it was on the sending part, but from what I understand google is sending us the header twice

urban solstice
#

Ok. Why is it erroring now?

rotund trail
#

Which kinda sucks, now I don't have time to dive into the full implementation of google drive integration

urban solstice
#

Did something change on the google side?

rotund trail
#

Nope, it's just that aiohttp fixed a security issue, and that's what causing this

#

So from what I understand, Google wouldn't be following the RFC

urban solstice
#

Ok, so it is aiohttp, but it's a valid fix.

rotund trail
#

๐Ÿ˜‚

#

Apparently it's not a problem with aiohttp*

urban solstice
#

Are we shipping the aiohttp bump tomorrow?

rotund trail
#

Yep

#

It fixes more security issues, so from what I understand it's quite important

#

And looking at the aiohttp PR there also doesn't seem a way to disable it for a client

urban solstice
#

Is tronikos aware?

rotund trail
#

I messaged him, no response thus far

urban solstice
#

Heh, Azure Blob Storage also seems to send duplicate headers. There's linked issue in the abvove issue.

#

This is annoying. Google Drive is our most popular backup location integration after Cloud and Synology. 2.4 % users.

#

We could revert the aiohttp bump but as it has many security fixes that's not a great solution.

#

And it would just be a delay. We'll need to bump eventually.

jade bay
#

Monkey patch aiohttp as a quick fix?

urban solstice
#

Could be an option.

#

@high warren do you have advice in this situation?

rotund trail
urban solstice
#

Ok, Nick is fixing it for us.

rotund trail
#

He's mentioning that he will discuss this with the others, but it might not make the release deadline

rotund trail
#

Okay, so if it doesn't make the initial release, what can we do? Like there's a chance we wake up tomorrow and there's no new aiohttp, how should we handle this

urban solstice
#

If we know it's on its way within a couple of days I think we can release with the "bug" and wait for Friday's patch release to fix it.

#

Otherwise we could look at a monkeypatch.

rotund trail
urban solstice
#

We have alerts. We would make one if we know it's a problem with the release.

rotund trail
#

Check

smoky widget
#

How does the aiohttp bump affect us?

#

as in, reverting that an option?

jade bay
#

Not sure if that is relevant to us though

smoky widget
#

ok, but that doesn't allow for us to asses impact and risk

rotund trail
#

Nick says that those fixes can't wait

#

That's all the info I have for those

#

He also says he came to an agreement with the other maintainers, he will now wrap things up

high warren
#

Working on the release now

high warren
#

Github is not cooperating today

jade bay
#

Wow, still running

high warren
#

ok got the approvals done. its going out

high warren
#

everything is working in my production testing. marked it ready

rotund trail
#

It's already approved ๐Ÿ™‚