Skip to content

Version 1.24.0

Latest

Choose a tag to compare

@umputun umputun released this 19 Aug 02:33
153b694

Breaking change for one configuration. CORS now panics at construction when credentials are enabled and * is among the allowed origins, which is the default origin list. That combination reflects whatever origin the request carries and sends Access-Control-Allow-Credentials: true with it, so any site a signed-in user visits can read authenticated responses. Enumerate the origins, or opt in explicitly with the new CorsUnsafeAnyOriginWithCredentials if the service is meant to be embedded on arbitrary third-party origins.

Gzip now decides on the response content type rather than the request one. The request Content-Type is empty on a GET, so compression previously almost never happened. Responses that were never compressed will start being compressed. Accept-Encoding is parsed rather than substring-matched, a named gzip entry outranks *, and q=0 is honoured as a refusal. Responses with no body, already-encoded bodies and partial content are left alone, and Flush and Hijack are advertised only when the writer underneath has them.

Other fixes:

  • CacheControl parsed If-None-Match with a substring match, so an etag could match a longer one. It is now parsed as a tag list, answered only for GET and HEAD, and yields to If-Match and If-Unmodified-Since.
  • Recoverer re-panics http.ErrAbortHandler, which net/http needs to abort the response.
  • EncodeJSON encodes into a buffer before writing the status, so an encoding failure leaves the response uncommitted.
  • BlackWords refuses a request whose body cannot be read instead of passing a partly consumed one through.
  • The file server closes handles opened while probing directories.
  • Benchmark timings are measured on the injectable clock, which removes a flaky test.