Skip to content

featherbit 0.8.1

Choose a tag to compare

@francescodedomenico francescodedomenico released this 14 Sep 22:22
· 142 commits to main since this release

Bugfix release. No new node types, no config-surface changes, no migration steps.

Why now

upstream built its outbound URL from the request path alone, so every proxied request lost its query string. Anything query-dependent was silently broken — pagination, filters, and OIDC/OAuth hops, where the authorization request reached the IdP with no client_id at all and the IdP answered invalid_request.

Fixes

upstream drops the query string The request-target is now path plus the rebuilt query, for both the buffered HTTP path and the WebSocket relay (which stashed a bare path in __ws_upstream_path, so wss://host/ws?token=… lost its token the same way). Values are stored exactly as received — ingress splits the raw query on &/= without percent-decoding — so rebuilding is lossless. Parameter order is normalized: query_params is a map, so the original order was already lost at ingress; sorting makes the outbound target deterministic rather than arbitrary.
rustls → 0.23.45 GHSA-2mjx-qc3c-rqvc, functionally the same bug as Go's GO-2026-4340 (CVE-2025-61730). Lockfile-only; rustls-webpki 0.103.13 → 0.103.15 alongside.

Docs and examples

  • Self-contained docker compose example stacks under examples/compose/ — minimal, TLS, etcd-single, etcd-cluster — runnable from published images.
  • TLS guide: the container-uid gotcha when mounting certificates.
  • Every Admin API endpoint documented, with the UI panels the gateway has grown, plus a test guarding the endpoint table against drift.

Behavior change worth reading

Three external-auth scenarios previously observed a bare path at the upstream for requests carrying ?ticket=… / ?code=…. That was the dropped-query bug, not a plugin feature — nothing documents these plugins consuming their credential parameter (cas-auth strips the ticket only in interactive mode, and does it by redirecting to the ticket-free service URL). A spent single-use ticket or code now reaches the backend. If that is undesirable for your deployment, it is a deliberate change to those plugins rather than a property of the proxy hop — please open an issue.

Housekeeping

This branch also merges main into the release, recovering the hotfix/docs-admin-endpoints work (#39) that was merged to main but never back into develop. Merging this release into develop repairs that drift.

Verification

cargo test 1239 passed / 0 failed · cargo fmt --check clean · cargo clippy --all-targets clean · gitleaks clean against the CI image and config.