Note the new request headers in the 3.5.5 release notes - #539
Open
MichaelGHSeg wants to merge 2 commits into
Open
MichaelGHSeg wants to merge 2 commits into
MichaelGHSeg wants to merge 2 commits into
Conversation
3.5.5 started sending Authorization and X-Retry-Count. Customers whose proxies allowlist request headers had uploads rejected by the equivalent analytics-next change, so the shipped entry should say so.
didiergarcia
approved these changes
Sep 28, 2026
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
3.5.5 started sending two request headers that 3.5.4 did not:
Authorization(HTTP Basic, carrying the write key) andX-Retry-Counton retries.Customers whose proxies allowlist request headers had uploads rejected by the equivalent change in the already-released
analytics-next. The same trap applies here, and the shipped 3.5.5 notes do not mention it — so anyone debugging a sudden upload failure after upgrading has nothing to find.Being server-side, java's exposure is lower than a browser SDK's: there is no CORS preflight, and a server deployment is less likely to sit behind a header-filtering proxy. But "lower" is not "none", and the note costs nothing.
What
Adds an upgrade note to the existing 3.5.5 entry in
CHANGELOG.md. Documentation only — no code change.The equivalent note is going into the release notes for python, go, ruby, php and C# as part of the same initiative, scoped per SDK to whichever header is actually new on the wire there. For java both are.