Bug Fixes
-
Proxy: WebSocket and other HTTP/1 upgrades work on
h2c://upstream routes. (c351b2d)- Upgrade requests use the HTTP/1 transport; ordinary requests and h2c upgrades retain HTTP/2 behavior.
- Includes the fix in the pinned yusing/goutils submodule. (b0525ee)
-
TCP: TLS-terminated routes negotiate ALPN for HTTP/2 and HTTP/1.1. (e72c9b5)
- Restores compatibility with gRPC clients that require the server to select
h2.
- Restores compatibility with gRPC clients that require the server to select
-
Providers: Docker and agent providers retry startup and watcher failures automatically. (5c8f0c4)
- Known routes remain available during provider outages, and recovery no longer requires a Docker event or config reload.
- Providers with recoverable infrastructure errors report degraded status while retries continue.
-
Docker: Docker provider endpoints resolve environment settings consistently. (b57240c)
- Unresolved endpoint references produce an error with substitution syntax guidance.
- Prefixed DOCKER_HOST values are used consistently for provider configuration and local container address discovery.
-
Config: Environment references in YAML and JSON expand without corrupting values. (006a29e)
- Expanded values containing quotes, newlines, or YAML delimiters remain literal string data.
- Duplicate mapping keys created by expansion are rejected.
-
Auth: Session cookies persist on hosts whose parent domain is a public suffix. (f9ce753)
-
Middleware: Middleware options serialize in JSON without panicking. (89df347)
- Bypass-configured middleware reports the options of the middleware it guards.
-
OIDC: OIDC bypass rules can reach backend-owned
/auth/*endpoints. (7b2e20f)- OIDC still handles
/auth/callbackand/auth/logouteven when a bypass rule matches.
- OIDC still handles
Full Changelog
-
e72c9b5 fix(entrypoint): negotiate ALPN on TLS-terminated TCP routes
-
c351b2d fix(proxy): support WebSocket upgrades on h2c routes
-
75a22f9 docs(config): align environment examples with runtime defaults
-
5c8f0c4 fix(provider): retry startup failures with cancellable backoff
-
b57240c fix(docker): validate and consistently resolve provider endpoints
-
006a29e fix(serialization): expand environment references in decoded strings
-
f9ce753 fix(auth): omit public-suffix domains from session cookies
-
256a688 fix(config): report a missing WebUI build directly
-
4573153 test(auth): tamper the payload of a login transaction token
-
ca30a16 test(provider): configure global OIDC for middleware label tests
-
89df347 fix(middleware): serialize implementation options under json/v2
-
7b2e20f fix(oidc): reserve only callback and logout paths
- 1c4eff6 docs(wiki): update configuration and recovery guidance
- 6c35185 chore(deps): update wiki submodule
- 005d469 chore(deps): update wiki submodule
- b0525ee fix(reverseproxy): fall back to HTTP/1 for h2c upgrades