v1.1
Full Changelog: v1.0.6...v1.1
Release v1.1.0
This release introduces BunnyCDN support for the Caddy CDN plugin, ports and refactors the caddy-error-gate error handling gateway, implements fine-grained security response header hardening, and adds global normalization mapping and data sanitization for country/region and Request ID headers.
🚀 Features
1. 🐰 Added Dynamic BunnyCDN Node IP Whitelisting
Added bunnycdn as a whitelist provider, supporting automatic retrieval and aggregation of IP whitelists from the following endpoints:
- BunnyCDN edge server list (IPv4 & IPv6):
https://api.bunny.net/system/edgeserverlist - Magic Containers node list:
https://api.bunny.net/mc/nodes/plain
2. 🛡️ Global Security Policy Response Header Hardening
Fine-tuned and hardened the global base security headers in applyBaseHeaders:
- Upgraded
Referrer-Policyto the strictersame-origin. - Added
Expect-CT: max-age=86400, enforceto enable Certificate Transparency enforcement. - Preserved and ensured high-security response headers such as
X-Frame-Options: DENY, which is stricter thanSAMEORIGIN.
3. 🐈 Ported and Integrated caddy-error-gate Error Gateway Logic
Multilingual server-side rendered error pages: Removed the previous multiple HTML file setup and replaced it with a unified templates/default.html and templates/default.json renderer. Combined with the server-side multilingual translation dictionary in i18n.go, error pages now adaptively support Chinese, English, French, Russian, Spanish, Arabic, and more.
CSP isolation for error pages: Intercepted error responses now forcibly include a sandbox-level CSP protection policy:
Content-Security-Policy: default-src 'none'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; base-uri 'none'; form-action 'none'; frame-ancestors 'none'Smart HTML content negotiation: Refactored file type detection. For requests whose Accept header does not include XML and does not explicitly request JSON, the plugin now defaults to returning a polished text/html error page, preventing browsers from displaying plain-text status codes in certain scenarios.
4. 🔀 Global Header Normalization and Sanitization
Country code normalization: Automatically converts incoming ali-ip-country or EO-Client-IPCountry request headers from Alibaba Cloud / Tencent Cloud EdgeOne into the standardized X-Catyuki-IP-Country header. The normalized header is propagated both upstream and back to the client, while the original non-standard headers are removed.
Request ID normalization: Automatically normalizes arbitrary candidate ID headers, such as x-request-id, x-req-id, requestid, and others, into X-Catyuki-Req-Id. Historical redundant candidate headers are sanitized from both upstream requests and downstream responses.
Trace ID injection: Injects and propagates X-Catyuki-Lb-Id across all request chains. If the request does not already include one, a 32-character hexadecimal Trace ID is dynamically generated and filled in.
🔧 Bug Fixes & Refactoring
CI/CD build fix: Fixed a syntax issue in .github/workflows/build.yaml where a missing line-continuation backslash \ in the xcaddy command caused packaging to fail with exit code 127.
Architecture refactor: Decoupled error page rendering logic from request header sanitization. The rendering flow is now centrally managed by renderError in templates.go.
Test coverage upgrade: Added main_error_test.go, covering and verifying wantsJSON, wantsHTML, error page rendering, country header normalization, and Request ID normalization conversion tests.
Full Changelog: v1.0.6...v1.1