Skip to content

v1.1

Choose a tag to compare

@binaryYuki binaryYuki released this 29 Jun 08:42
· 8 commits to main since this release
8af475b

Full Changelog: v1.0.6...v1.1

Release v1.1.0

This release introduces BunnyCDN support for the Caddy CDN plugin, ports and refactors the caddy-error-gate error handling gateway, implements fine-grained security response header hardening, and adds global normalization mapping and data sanitization for country/region and Request ID headers.

🚀 Features

1. 🐰 Added Dynamic BunnyCDN Node IP Whitelisting

Added bunnycdn as a whitelist provider, supporting automatic retrieval and aggregation of IP whitelists from the following endpoints:

  • BunnyCDN edge server list (IPv4 & IPv6): https://api.bunny.net/system/edgeserverlist
  • Magic Containers node list: https://api.bunny.net/mc/nodes/plain

2. 🛡️ Global Security Policy Response Header Hardening

Fine-tuned and hardened the global base security headers in applyBaseHeaders:

  • Upgraded Referrer-Policy to the stricter same-origin.
  • Added Expect-CT: max-age=86400, enforce to enable Certificate Transparency enforcement.
  • Preserved and ensured high-security response headers such as X-Frame-Options: DENY, which is stricter than SAMEORIGIN.

3. 🐈 Ported and Integrated caddy-error-gate Error Gateway Logic

Multilingual server-side rendered error pages: Removed the previous multiple HTML file setup and replaced it with a unified templates/default.html and templates/default.json renderer. Combined with the server-side multilingual translation dictionary in i18n.go, error pages now adaptively support Chinese, English, French, Russian, Spanish, Arabic, and more.

CSP isolation for error pages: Intercepted error responses now forcibly include a sandbox-level CSP protection policy:

Content-Security-Policy: default-src 'none'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; base-uri 'none'; form-action 'none'; frame-ancestors 'none'

Smart HTML content negotiation: Refactored file type detection. For requests whose Accept header does not include XML and does not explicitly request JSON, the plugin now defaults to returning a polished text/html error page, preventing browsers from displaying plain-text status codes in certain scenarios.

4. 🔀 Global Header Normalization and Sanitization

Country code normalization: Automatically converts incoming ali-ip-country or EO-Client-IPCountry request headers from Alibaba Cloud / Tencent Cloud EdgeOne into the standardized X-Catyuki-IP-Country header. The normalized header is propagated both upstream and back to the client, while the original non-standard headers are removed.

Request ID normalization: Automatically normalizes arbitrary candidate ID headers, such as x-request-id, x-req-id, requestid, and others, into X-Catyuki-Req-Id. Historical redundant candidate headers are sanitized from both upstream requests and downstream responses.

Trace ID injection: Injects and propagates X-Catyuki-Lb-Id across all request chains. If the request does not already include one, a 32-character hexadecimal Trace ID is dynamically generated and filled in.

🔧 Bug Fixes & Refactoring

CI/CD build fix: Fixed a syntax issue in .github/workflows/build.yaml where a missing line-continuation backslash \ in the xcaddy command caused packaging to fail with exit code 127.

Architecture refactor: Decoupled error page rendering logic from request header sanitization. The rendering flow is now centrally managed by renderError in templates.go.

Test coverage upgrade: Added main_error_test.go, covering and verifying wantsJSON, wantsHTML, error page rendering, country header normalization, and Request ID normalization conversion tests.

Full Changelog: v1.0.6...v1.1