Churust v0.3.1
All fourteen Churust crates release together on 0.3.1.
[dependencies]
churust = "0.3.1"Added
-
churust-clienttransparently decodesgzipanddeflateresponse bodies.
The client advertisesAccept-Encoding: gzip, deflateby default and inflates
those encodings before handing the body to the caller, so a peer that
compresses (CDNs, many affiliate APIs) is usable without application-side
flate2. Decompressed size is still capped bymax_response_bytes, which
closes the classic compression-bomb path of a tiny payload that expands past
memory. Opt out withClient::auto_decompress(false). -
Default
Permissions-PolicyandCross-Origin-Resource-Policyon every
response. New secure defaults onSecurityHeaders:Permissions-Policy: camera=(), microphone=(), geolocation=(), payment=(), usb=(), interest-cohort=()— browser features a JSON API never needs.Cross-Origin-Resource-Policy: same-origin— blocks no-cors cross-origin
reads; CORS clients are unaffected.
Override or disable withSecurityHeaders::permissions_policy/
cross_origin_resource_policy, or turn the whole set off with
without_security_headers().
Changed
-
Client::max_response_bytesis documented and enforced on the payload the
caller sees, including after decompression, not only on the compressed wire
form. -
Response::textvalidates UTF-8 without an intermediateto_vec, saving
one allocation on every successful text body.
Security
- Default response headers now include
Permissions-Policyand
Cross-Origin-Resource-Policyas above. Existing apps that relied on the
absence of those headers should set them explicitly or disable the defaults.
Crates
churust-core· docschurust-macros· docschurust-auth· docschurust-client· docschurust-compression· docschurust-cors· docschurust-json· docschurust-lab· docschurust-logging· docschurust-openapi· docschurust-ratelimit· docschurust-redis· docschurust-templates· docschurust· docs
What's Changed
- release: Churust 0.3.1 by @davthecodercom in #3
- fix: clippy Error::other for 0.3.1 by @davthecodercom in #4
Full Changelog: v0.3.0...v0.3.1