Skip to content

[codex] Improve Bun.file HTTP URL error - #30709

Closed
qkal wants to merge 3 commits into
oven-sh:mainfrom
qkal:codex/bun-file-http-url-error
Closed

qkal wants to merge 3 commits into
oven-sh:mainfrom
qkal:codex/bun-file-http-url-error

Conversation

@qkal

@qkal qkal commented May 14, 2026

Copy link
Copy Markdown

What does this PR do?

Fixes #9506.

Bun.file() now rejects http:// and https:// path strings immediately with a clearer error that tells users to use fetch() instead. The same guard is mirrored in the Rust and Zig Blob implementations, and the existing s3:// path remains routed through the S3 file handling branch.

How did you verify your code works?

  • Added a regression test covering both http:// and https:// URL strings.
  • Verified the new test fails against the installed Bun before the runtime change because Bun.file("https://...") returned a FileRef instead of throwing.
  • Ran git diff --check -- src/runtime/webcore/Blob.rs src/runtime/webcore/Blob.zig test/js/bun/util/bun-file.test.ts.
  • Ran BUN_CODEGEN_DIR=C:\bun\build\debug\codegen cargo check -p bun_runtime.

I also attempted bun run build:debug on Windows. The build was blocked before producing a patched Bun binary by a vendor extraction issue in zstd: tar.exe could not create Unix-style helper entries under vendor/zstd/tests/cli-tests/bin (Invalid argument).

@qkal
qkal marked this pull request as ready for review May 14, 2026 15:48

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude Code Review

This pull request is from a fork — automated review is disabled. A repository maintainer can comment @claude review to run a one-time review.

@coderabbitai

coderabbitai Bot commented May 14, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 59c3c421-320e-4a14-bf56-2e2a2af01058

📥 Commits

Reviewing files that changed from the base of the PR and between 63c4a63 and 5f49a23.

📒 Files selected for processing (1)
  • src/runtime/webcore/Blob.rs

Walkthrough

Bun.file() now rejects HTTP and HTTPS URL strings in both Rust and Zig code paths, returning an InvalidArguments error advising use of fetch(); a unit test verifies both protocols are rejected.

Changes

HTTP/HTTPS URL Rejection Feature

Layer / File(s) Summary
Rust implementation
src/runtime/webcore/Blob.rs
construct_bun_file caches the input path slice, retains S3 detection, and adds an early rejection for http:///https:// URLs via a new is_http_url_path helper (case-insensitive match).
Zig implementation
src/runtime/webcore/Blob.zig
constructBunFile computes path_slice once, reuses it for protocol checks, and routes HTTP/HTTPS rejection through a new isHTTPURLPath helper (case-insensitive match).
Test coverage
test/js/bun/util/bun-file.test.ts
New test asserts Bun.file() throws the explanatory error for both http:// and https:// inputs, advising use of fetch().
🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title '[codex] Improve Bun.file HTTP URL error' clearly and concisely summarizes the main change: improving error handling for HTTP URLs in Bun.file().
Description check ✅ Passed The PR description fully covers both template sections, providing clear details about what the PR does (rejecting HTTP/HTTPS URLs with improved error message) and comprehensive verification steps.
Linked Issues check ✅ Passed The PR successfully addresses issue #9506 by implementing explicit rejection of HTTP/HTTPS URLs in Bun.file() with a clear error message directing users to use fetch() instead, directly resolving the reported problem.
Out of Scope Changes check ✅ Passed All changes are directly scoped to the objective: rejecting HTTP/HTTPS URLs in both Rust and Zig Blob implementations, maintaining S3 handling, and adding corresponding regression tests.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

Tip

💬 Introducing Slack Agent: The best way for teams to turn conversations into code.

Slack Agent is built on CodeRabbit's deep understanding of your code, so your team can collaborate across the entire SDLC without losing context.

  • Generate code and open pull requests
  • Plan features and break down work
  • Investigate incidents and troubleshoot customer tickets together
  • Automate recurring tasks and respond to alerts with triggers
  • Summarize progress and report instantly

Built for teams:

  • Shared memory across your entire org—no repeating context
  • Per-thread sandboxes to safely plan and execute work
  • Governance built-in—scoped access, auditability, and budget controls

One agent for your entire SDLC. Right inside Slack.

👉 Get started


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@robobun

robobun commented Aug 13, 2026

Copy link
Copy Markdown
Collaborator

Thanks for the PR, and sorry it sat for so long.

Closing this one: #9506 was closed as fixed on main, which took a different route than this PR. On main, Bun.file("https://...") still treats the string as a path, but reading it now fails with ENOENT: no such file or directory, open 'https://...' instead of the misleading Request error from the issue, and Bun.file(new URL("https://...")) throws URL must be a non-empty "file:" path at construction. Both verified on a build of main (165dc9f).

Rejecting http(s) strings at construction time, as this PR does, would be a new behavior change rather than a fix for that issue, so it would need its own issue and discussion; feel free to open one if you still think it is worth doing. The branch also touches src/runtime/webcore/Blob.zig, which was removed in #32621, so it could not land as is either way.

@robobun robobun closed this Aug 13, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Improve error message when using non-file: URLs in Bun.file

2 participants