Breaking change for one configuration. CORS now panics at construction when credentials are enabled and * is among the allowed origins, which is the default origin list. That combination reflects whatever origin the request carries and sends Access-Control-Allow-Credentials: true with it, so any site a signed-in user visits can read authenticated responses. Enumerate the origins, or opt in explicitly with the new CorsUnsafeAnyOriginWithCredentials if the service is meant to be embedded on arbitrary third-party origins.
Gzip now decides on the response content type rather than the request one. The request Content-Type is empty on a GET, so compression previously almost never happened. Responses that were never compressed will start being compressed. Accept-Encoding is parsed rather than substring-matched, a named gzip entry outranks *, and q=0 is honoured as a refusal. Responses with no body, already-encoded bodies and partial content are left alone, and Flush and Hijack are advertised only when the writer underneath has them.
Other fixes:
CacheControlparsedIf-None-Matchwith a substring match, so an etag could match a longer one. It is now parsed as a tag list, answered only for GET and HEAD, and yields toIf-MatchandIf-Unmodified-Since.Recovererre-panicshttp.ErrAbortHandler, which net/http needs to abort the response.EncodeJSONencodes into a buffer before writing the status, so an encoding failure leaves the response uncommitted.BlackWordsrefuses a request whose body cannot be read instead of passing a partly consumed one through.- The file server closes handles opened while probing directories.
- Benchmark timings are measured on the injectable clock, which removes a flaky test.