You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Added
Server-Sent Events and streaming on the Wing transport.c.SSE() and c.Stream()
now work on Wing (the default on Linux) via the new kruda.Stream route preset — app.Get("/events", h, kruda.Stream). Previously they returned an error unless the route
ran on net/http. Streaming dispatches via Takeover and does not affect the inline hot
path; a slow/stuck client is bounded by WriteTimeout, and a client disconnect cancels
the handler context (SSEStream.Done() fires). A TestClient.SSE(path) helper decodes the
emitted events for unit tests. The fasthttp transport (macOS dev default) does not support
streaming — c.SSE() there now returns an actionable error pointing to kruda.NetHTTP().
WithHeaderLimit(n) option. Configures the maximum total request-header size
(default 8 KB → HTTP 431). Clients sending large Authorization/Cookie headers (big
JWTs) previously hit a spurious 431 with no escape hatch.
Environment configuration for the Wing safety bundle.WithEnvPrefix now also reads <PREFIX>_HEADER_LIMIT, <PREFIX>_TRUST_PROXY, <PREFIX>_MAX_CONNS, <PREFIX>_MAX_CONNS_PER_IP, <PREFIX>_ACCEPT_RATE_PER_SEC, and <PREFIX>_ACCEPT_RATE_BURST, so Kubernetes/ConfigMap deployments can tune the v1.4.0
accept-side DoS limits and proxy trust without code changes.
Security
Raised the minimum Go to 1.25.11 (1.25 line) or 1.26.4 (1.26 line). go1.25.10
and go1.26.0–1.26.3 carry stdlib CVEs GO-2026-5037 (crypto/x509 quadratic verify) and
GO-2026-5039 (net/textproto error-message injection); the new floor clears both.
Breaking
Removed the no-op WithHTTP3 option and the Config.HTTP3 field. They advertised
HTTP/3 (QUIC) serving, but it was never implemented — nothing consumed the flag, so a
caller got the standard net/http fallback (HTTP/1.1 + HTTP/2), not QUIC. HTTP/3 is not on
the roadmap, so the dead API is removed rather than left as a misleading promise
(rationale: docs/decisions/0001-break-api-in-v1-minor.md). TLS is unaffected — use WithTLS(certFile, keyFile).