REST client — version history
A native HTTPS client, synchronous or asynchronous, that calls a REST API from PowerBuilder without a browser's CORS wall. Introduced in 3.0.
4.0 — October 2026 #
New #
ib_windows_auth: integrated Windows authentication (Negotiate / NTLM) answers an intranet server's challenge with the session's credentials, when you ask for it.is_client_certificate: a client certificate (mutual TLS), named by its thumbprint in the user's or the machine's personal store; a thumbprint that cannot be found makes the request return-5.
Fixed #
- A 301 or 302 redirect of a PUT, PATCH or DELETE keeps its method and body: the change used to be lost while the call returned 200. Only a POST becomes a GET; a 303 goes on as a GET without a body.
- A malformed header no longer sends the request without any header at all (authentication included): the request is refused with
-5andis_last_error= "invalid header: <name>". - Synchronous requests now keep their cookies: one session per object, shared by synchronous and asynchronous calls, so a synchronous login keeps you signed in. Changing
ib_keep_cookiesafter the first request applies at once. of_set_bearerandof_set_basicno longer add up: one authentication at a time, each replaces the other, an empty value removes it.- A response to
HEAD, or a204/304that announces a size, returns its status instead of-4"connection lost". - The
charsetannounced by the server is honoured (iso-8859-1, utf-16, legacy code pages); one invalid byte no longer makes the whole body be re-read as Windows-1252 — it alone becomes a replacement character. - A hundred asynchronous requests sent at once no longer start a hundred threads: six at most run together, the others wait their turn; a synchronous request of the same object no longer waits behind them.
- Asynchronous requests sent continuously (a telemetry timer) no longer delay response delivery indefinitely.
- Reading a response during
ue_progresscan no longer crash: it is empty andof_status(id)is0while the request runs. - A modal box opened in
ue_responseno longer causes nested events: responses arrive one after the other. - A reused connection that the server closes at the same moment no longer fails with "request failed: 12152": the request is resent once on a fresh connection.
- A relative
Location(?page=2) is resolved as a browser does; the#…fragment is no longer sent to the server. il_max_retriesno longer retries a failure that would happen again identically (too many redirects, HTTPS-to-HTTP redirect, TLS error, file that cannot be written); 429, 503 and network failures are still retried.of_status(id)returns0for any failed request, never the status of a response lost on the way.of_response_text()afterof_downloadis empty (the body is in the file) instead of the number of bytes written.
Behavior changes #
See the 3.0 → 4.0 migration guide, sections 11.6 and 11.9.
- Signature:
ue_failed (long al_id, long al_code, string as_error)replacesue_failed (long al_id, string as_error)— the code (-4failure,-5file or client certificate) spares you from parsing the text. of_json_valuetakes ann_pbt_jsonpath ("items/1/qty") and returns any value, numbers and booleans included; it is no longer a key searched at any depth, so a nested key is named with its parents ("json/customer").of_set_header,of_set_bearerandof_set_basicarelongfunctions:0, or-5on an invalid name or value (nothing changes then).- Windows authentication is no longer sent on its own: an intranet API that answered 200 answers 401 until
ib_windows_authis set. - On a redirect to another host or port, no header set by
of_set_headerfollows (an API key no longer reaches the third party); onlyContent-Typestays. - A body read as text is capped at 16 MB in a 32-bit application (64 MB in 64-bit): beyond it,
-4"body too large" — read it withof_download. of_get_async,of_request_async… on an invalid URL or header return-5at once, with no event.of_response_text(),of_response_headers(),of_response_headerandof_json_valueread the last response of the object, no longer of the process; per-id readers andof_cancelonly see the object's own requests.of_cancelof an unknown id returns-5, of a request already answered-4.of_openreturns-2when the client cannot be created;is_last_errorsays why.- A runtime error in your
ue_response,ue_failedorue_progressreaches the application'sSystemErrorevent instead of being swallowed, and later responses are still delivered. - A relative path given to
of_downloadis resolved at call time, in the application's current folder when the library was loaded.
3.0 — September 2026 #
New #
- The library's first HTTPS client, native (WinHTTP inside the DLL, no page): the system's TLS, certificates, proxy and decompression, and no CORS restriction on corporate APIs.
- Synchronous
of_get,of_post,of_put,of_patch,of_deleteandof_request(any method): each returns the HTTP status, or a negative code when the request did not complete (is_last_errorsays why). - Headers (
of_set_header,of_remove_header,of_clear_headers), Bearer and Basic authentication, base URL (is_base_url), timeout (il_timeout_ms). - Reading the response:
of_response_text,of_response_headers,of_response_header,of_json_value; request bodies built withn_pbt_json. of_download: a file downloaded byte for byte, whatever its size.- An asynchronous API that does not block the script:
of_get_asyncand its siblings,of_download_async,of_upload(multipart/form-data),of_cancel,of_status, withue_response,ue_failedandue_progressdelivered on their own — no timer or receiver to wire. - Cookies kept from one request to the next (
ib_keep_cookies,of_clear_cookies) and automatic retries on 429, 503 and network failures (il_max_retries,il_retry_backoff_ms,Retry-Afterhonoured).