v2.1.0
Tako 2.1.0 adds shared middleware backends, safer request defaults, bounded streaming, and more reliable server lifecycle handling across Tokio and Compio.
This release includes intentional breaking API and default changes. Read the 2.1 migration guide before upgrading from 2.0.x. All eight workspace crates are versioned together at 2.1.0 and require Rust 1.95 or newer.
Breaking changes and migration
- Enable
ws,sse,proxy-protocol, andudpexplicitly; they are no longer default features. Compio WebSockets usecompio-ws.per-thread-compioselects Compio throughout the framework, and--all-featuresselects the Compio API surface. - Only the final handler argument may consume the body; earlier arguments implement
FromRequestParts. Extractor traits return futures withoutasync_traitboxing. HandlerResult<T, E>values require both branches to implementResponder. - Buffered body extractors enforce a 2 MiB default limit, including chunked uploads. Configure
Router::body_limitor explicitly opt out withdisable_body_limit. Session and CSRF cookies default toSecure; static files deny dotfiles by default. - Route paths and
MatchedPathuseArc<str>, signal IDs and metadata keys useCow<'static, str>, and TLS metadata uses shared byte/string types. Middleware continues throughNext::run; continuation internals are private. - Shared middleware store methods are fallible. Idempotency uses atomic leases, SHA-256 request fingerprints, and a new cache-key encoding; clear old idempotency caches during migration. JWT provider keys are bound to their declared algorithms.
- Prefer
Server/CompioServerbuilders and router-local state. HTTP convenience entry points and global state helpers are deprecated; explicit rustls-config, raw-transport, and per-thread entry points remain available. The ineffectiveServerConfig::keep_alive_timeoutfield is removed. FileStream::try_range_responsetreats an inclusive end of zero as byte zero; useu64::MAXfor an open end. WebSocketkeep_aliveis deprecated and inert; handlers own ping/pong timing.- The
jemallocfeature exposes the allocator without installing it globally. Applications sharing integration types should align their dependencies with the updated Compio, Tungstenite, OpenTelemetry, Prometheus, Utoipa, validator, and garde versions.
Added
.store(...)integration for session, rate-limit, idempotency, CSRF, and JWT key backends, with memory reference implementations, TTL handling, atomic operations, and fail-closed backend errors.- Trusted-proxy client-IP policies and configurable IPv6 subnet grouping for rate limiting.
- Fallible
try_spawn_*startup,ServerHandle::result()andlocal_addr(), bounded graceful shutdown, and SIGINT/SIGTERM handling. AltSvcmiddleware for advertising an existing HTTP/3 endpoint.- Owned text and byte body extractors, request-aware error formatting, and additional route and feature exports.
Fixed and improved
- Nested routing preserves scoped state, plugins, body limits, and timeouts. HEAD fallback,
Allow, trailing-slash queries, responder content types, and problem-response headers follow the intended HTTP behavior. - Server tasks and routers are released on shutdown; connection limits, header deadlines, plugin failures, and per-thread startup errors are enforced. HTTP/3 streams request bodies and trailers while keeping connection tasks owned.
- Static files stream in bounded chunks with conditional requests, weak ETags, HEAD, byte ranges, and precompressed variants. WebSocket handshakes validate HTTP/1.1 upgrade requirements.
- Idempotency cancellation and replay behavior, CSRF token consumption, JWT key rotation, rate-limit bursts, and session lifecycle handling are hardened.
- Queue wakeups and deduplication avoid repeated scans. Large buffered compression runs on blocking workers, streaming responses remain streaming, and HTTP deflate uses the required zlib wrapper.
- Request signals reach the correct arbiters, listener-free dispatch avoids unnecessary work, and metrics record completed requests without a lossy broadcast path.
- Updated dependencies, expanded parser fuzzing, enabled standalone crate doctests, migrated all 40 examples, and refreshed the feature, runtime, deployment, and migration documentation.
Full diff: v2.0.2...v2.1.0