Skip to content

v2.1.0

Choose a tag to compare

@dancixx dancixx released this 27 Sep 14:17
· 10 commits to main since this release
23f8661

Tako 2.1.0 adds shared middleware backends, safer request defaults, bounded streaming, and more reliable server lifecycle handling across Tokio and Compio.

This release includes intentional breaking API and default changes. Read the 2.1 migration guide before upgrading from 2.0.x. All eight workspace crates are versioned together at 2.1.0 and require Rust 1.95 or newer.

Breaking changes and migration

  • Enable ws, sse, proxy-protocol, and udp explicitly; they are no longer default features. Compio WebSockets use compio-ws. per-thread-compio selects Compio throughout the framework, and --all-features selects the Compio API surface.
  • Only the final handler argument may consume the body; earlier arguments implement FromRequestParts. Extractor traits return futures without async_trait boxing. Handler Result<T, E> values require both branches to implement Responder.
  • Buffered body extractors enforce a 2 MiB default limit, including chunked uploads. Configure Router::body_limit or explicitly opt out with disable_body_limit. Session and CSRF cookies default to Secure; static files deny dotfiles by default.
  • Route paths and MatchedPath use Arc<str>, signal IDs and metadata keys use Cow<'static, str>, and TLS metadata uses shared byte/string types. Middleware continues through Next::run; continuation internals are private.
  • Shared middleware store methods are fallible. Idempotency uses atomic leases, SHA-256 request fingerprints, and a new cache-key encoding; clear old idempotency caches during migration. JWT provider keys are bound to their declared algorithms.
  • Prefer Server / CompioServer builders and router-local state. HTTP convenience entry points and global state helpers are deprecated; explicit rustls-config, raw-transport, and per-thread entry points remain available. The ineffective ServerConfig::keep_alive_timeout field is removed.
  • FileStream::try_range_response treats an inclusive end of zero as byte zero; use u64::MAX for an open end. WebSocket keep_alive is deprecated and inert; handlers own ping/pong timing.
  • The jemalloc feature exposes the allocator without installing it globally. Applications sharing integration types should align their dependencies with the updated Compio, Tungstenite, OpenTelemetry, Prometheus, Utoipa, validator, and garde versions.

Added

  • .store(...) integration for session, rate-limit, idempotency, CSRF, and JWT key backends, with memory reference implementations, TTL handling, atomic operations, and fail-closed backend errors.
  • Trusted-proxy client-IP policies and configurable IPv6 subnet grouping for rate limiting.
  • Fallible try_spawn_* startup, ServerHandle::result() and local_addr(), bounded graceful shutdown, and SIGINT/SIGTERM handling.
  • AltSvc middleware for advertising an existing HTTP/3 endpoint.
  • Owned text and byte body extractors, request-aware error formatting, and additional route and feature exports.

Fixed and improved

  • Nested routing preserves scoped state, plugins, body limits, and timeouts. HEAD fallback, Allow, trailing-slash queries, responder content types, and problem-response headers follow the intended HTTP behavior.
  • Server tasks and routers are released on shutdown; connection limits, header deadlines, plugin failures, and per-thread startup errors are enforced. HTTP/3 streams request bodies and trailers while keeping connection tasks owned.
  • Static files stream in bounded chunks with conditional requests, weak ETags, HEAD, byte ranges, and precompressed variants. WebSocket handshakes validate HTTP/1.1 upgrade requirements.
  • Idempotency cancellation and replay behavior, CSRF token consumption, JWT key rotation, rate-limit bursts, and session lifecycle handling are hardened.
  • Queue wakeups and deduplication avoid repeated scans. Large buffered compression runs on blocking workers, streaming responses remain streaming, and HTTP deflate uses the required zlib wrapper.
  • Request signals reach the correct arbiters, listener-free dispatch avoids unnecessary work, and metrics record completed requests without a lossy broadcast path.
  • Updated dependencies, expanded parser fuzzing, enabled standalone crate doctests, migrated all 40 examples, and refreshed the feature, runtime, deployment, and migration documentation.

Full diff: v2.0.2...v2.1.0