Update module labstack/echo/v4 to v4.2.0 #785

Merged
konrad merged 1 commits from renovate/github.com-labstack-echo-v4-4.x into main 2021-02-13 22:46:04 +00:00
Member

This PR contains the following updates:

Package Type Update Change
github.com/labstack/echo/v4 require minor v4.1.17 -> v4.2.0

Release Notes

labstack/echo

v4.2.0

Compare Source

Important notes

The behaviour for binding data has been reworked for compatibility with echo before v4.1.11 by
enforcing explicit tagging for processing parameters. This may break your code if you
expect combined handling of query/path/form params.
Please see the updated documentation for request and binding

The handling for rewrite rules has been slightly adjusted to expand * to a non-greedy (.*?) capture group. This is only relevant if multiple asterisks are used in your rules.
Please see rewrite and proxy for details.

Security

  • Fix directory traversal vulnerability for Windows (#​1718, little-cui)
  • Fix open redirect vulnerability with trailing slash (#​1771,#​1775 aldas,GeoffreyFrogeye)

Enhancements

  • Add Echo#ListenerNetwork as configuration (#​1667, pafuent)
  • Add ability to change the status code using response beforeFuncs (#​1706, RashadAnsari)
  • Echo server startup to allow data race free access to listener address
  • Binder: Restore pre v4.1.11 behaviour for c.Bind() to use query params only for GET or DELETE methods (#​1727, aldas)
  • Binder: Add separate methods to bind only query params, path params or request body (#​1681, aldas)
  • Binder: New fluent binder for query/path/form parameter binding (#​1717, #​1736, aldas)
  • Router: Performance improvements for missed routes (#​1689, pafuent)
  • Router: Improve performance for Real-IP detection using IndexByte instead of Split (#​1640, imxyb)
  • Middleware: Support real regex rules for rewrite and proxy middleware (#​1767)
  • Middleware: New rate limiting middleware (#​1724, iambenkay)
  • Middleware: New timeout middleware implementation for go1.13+ (#​1743, )
  • Middleware: Allow regex pattern for CORS middleware (#​1623, KlotzAndrew)
  • Middleware: Add IgnoreBase parameter to static middleware (#​1701, lnenad, iambenkay)
  • Middleware: Add an optional custom function to CORS middleware to validate origin (#​1651, curvegrid)
  • Middleware: Support form fields in JWT middleware (#​1704, rkfg)
  • Middleware: Use sync.Pool for (de)compress middleware to improve performance (#​1699, #​1672, pafuent)
  • Middleware: Add decompress middleware to support gzip compressed requests (#​1687, arun0009)
  • Middleware: Add ErrJWTInvalid for JWT middleware (#​1627, juanbelieni)
  • Middleware: Add SameSite mode for CSRF cookies to support iframes (#​1524, pr0head)

Fixes

  • Fix handling of special trailing slash case for partial prefix (#​1741, stffabi)
  • Fix handling of static routes with trailing slash (#​1747)
  • Fix Static files route not working (#​1671, pwli0755, lammel)
  • Fix use of caret(^) in regex for rewrite middleware (#​1588, chotow)
  • Fix Echo#Reverse for Any type routes (#​1695, pafuent)
  • Fix Router#Find panic with infinite loop (#​1661, pafuent)
  • Fix Router#Find panic fails on Param paths (#​1659, pafuent)
  • Fix DefaultHTTPErrorHandler with Debug=true (#​1477, lammel)
  • Fix incorrect CORS headers (#​1669, ulasakdeniz)
  • Fix proxy middleware rewritePath to use url with updated tests (#​1630, arun0009)
  • Fix rewritePath for proxy middleware to use escaped path in (#​1628, arun0009)
  • Remove unless defer (#​1656, imxyb)

General

  • New maintainers for Echo: Roland Lammel (@​lammel) and Pablo Andres Fuente (@​pafuent)
  • Add GitHub action to compare benchmarks (#​1702, pafuent)
  • Binding query/path params and form fields to struct only works for explicit tags (#​1729,#​1734, aldas)
  • Add support for Go 1.15 in CI (#​1683, asahasrabuddhe)
  • Add test for request id to remain unchanged if provided (#​1719, iambenkay)
  • Refactor echo instance listener access and startup to speed up testing (#​1735, aldas)
  • Refactor and improve various tests for binding and routing
  • Run test workflow only for relevant changes (#​1637, #​1636, pofl)
  • Update .travis.yml (#​1662, santosh653)
  • Update README.md with an recents framework benchmark (#​1679, pafuent)

This release was made possible by over 100 commits from more than 20 contributors:
asahasrabuddhe, aldas, AndrewKlotz, arun0009, chotow, curvegrid, iambenkay, imxyb,
juanbelieni, lammel, little-cui, lnenad, pafuent, pofl, pr0head, pwli, RashadAnsari,
rkfg, santosh653, segfiner, stffabi, ulasakdeniz


Renovate configuration

📅 Schedule: At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻️ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [github.com/labstack/echo/v4](https://github.com/labstack/echo) | require | minor | `v4.1.17` -> `v4.2.0` | --- ### Release Notes <details> <summary>labstack/echo</summary> ### [`v4.2.0`](https://github.com/labstack/echo/blob/master/CHANGELOG.md#v420---2020-02-11) [Compare Source](https://github.com/labstack/echo/compare/v4.1.17...v4.2.0) **Important notes** The behaviour for binding data has been reworked for compatibility with echo before v4.1.11 by enforcing `explicit tagging` for processing parameters. This **may break** your code if you expect combined handling of query/path/form params. Please see the updated documentation for [request](https://echo.labstack.com/guide/request) and [binding](https://echo.labstack.com/guide/request) The handling for rewrite rules has been slightly adjusted to expand `*` to a non-greedy `(.*?)` capture group. This is only relevant if multiple asterisks are used in your rules. Please see [rewrite](https://echo.labstack.com/middleware/rewrite) and [proxy](https://echo.labstack.com/middleware/proxy) for details. **Security** - Fix directory traversal vulnerability for Windows ([#&#8203;1718](https://github.com/labstack/echo/issues/1718), little-cui) - Fix open redirect vulnerability with trailing slash ([#&#8203;1771](https://github.com/labstack/echo/issues/1771),[#&#8203;1775](https://github.com/labstack/echo/issues/1775) aldas,GeoffreyFrogeye) **Enhancements** - Add Echo#ListenerNetwork as configuration ([#&#8203;1667](https://github.com/labstack/echo/issues/1667), pafuent) - Add ability to change the status code using response beforeFuncs ([#&#8203;1706](https://github.com/labstack/echo/issues/1706), RashadAnsari) - Echo server startup to allow data race free access to listener address - Binder: Restore pre v4.1.11 behaviour for c.Bind() to use query params only for GET or DELETE methods ([#&#8203;1727](https://github.com/labstack/echo/issues/1727), aldas) - Binder: Add separate methods to bind only query params, path params or request body ([#&#8203;1681](https://github.com/labstack/echo/issues/1681), aldas) - Binder: New fluent binder for query/path/form parameter binding ([#&#8203;1717](https://github.com/labstack/echo/issues/1717), [#&#8203;1736](https://github.com/labstack/echo/issues/1736), aldas) - Router: Performance improvements for missed routes ([#&#8203;1689](https://github.com/labstack/echo/issues/1689), pafuent) - Router: Improve performance for Real-IP detection using IndexByte instead of Split ([#&#8203;1640](https://github.com/labstack/echo/issues/1640), imxyb) - Middleware: Support real regex rules for rewrite and proxy middleware ([#&#8203;1767](https://github.com/labstack/echo/issues/1767)) - Middleware: New rate limiting middleware ([#&#8203;1724](https://github.com/labstack/echo/issues/1724), iambenkay) - Middleware: New timeout middleware implementation for go1.13+ ([#&#8203;1743](https://github.com/labstack/echo/issues/1743), ) - Middleware: Allow regex pattern for CORS middleware ([#&#8203;1623](https://github.com/labstack/echo/issues/1623), KlotzAndrew) - Middleware: Add IgnoreBase parameter to static middleware ([#&#8203;1701](https://github.com/labstack/echo/issues/1701), lnenad, iambenkay) - Middleware: Add an optional custom function to CORS middleware to validate origin ([#&#8203;1651](https://github.com/labstack/echo/issues/1651), curvegrid) - Middleware: Support form fields in JWT middleware ([#&#8203;1704](https://github.com/labstack/echo/issues/1704), rkfg) - Middleware: Use sync.Pool for (de)compress middleware to improve performance ([#&#8203;1699](https://github.com/labstack/echo/issues/1699), [#&#8203;1672](https://github.com/labstack/echo/issues/1672), pafuent) - Middleware: Add decompress middleware to support gzip compressed requests ([#&#8203;1687](https://github.com/labstack/echo/issues/1687), arun0009) - Middleware: Add ErrJWTInvalid for JWT middleware ([#&#8203;1627](https://github.com/labstack/echo/issues/1627), juanbelieni) - Middleware: Add SameSite mode for CSRF cookies to support iframes ([#&#8203;1524](https://github.com/labstack/echo/issues/1524), pr0head) **Fixes** - Fix handling of special trailing slash case for partial prefix ([#&#8203;1741](https://github.com/labstack/echo/issues/1741), stffabi) - Fix handling of static routes with trailing slash ([#&#8203;1747](https://github.com/labstack/echo/issues/1747)) - Fix Static files route not working ([#&#8203;1671](https://github.com/labstack/echo/issues/1671), pwli0755, lammel) - Fix use of caret(^) in regex for rewrite middleware ([#&#8203;1588](https://github.com/labstack/echo/issues/1588), chotow) - Fix Echo#Reverse for Any type routes ([#&#8203;1695](https://github.com/labstack/echo/issues/1695), pafuent) - Fix Router#Find panic with infinite loop ([#&#8203;1661](https://github.com/labstack/echo/issues/1661), pafuent) - Fix Router#Find panic fails on Param paths ([#&#8203;1659](https://github.com/labstack/echo/issues/1659), pafuent) - Fix DefaultHTTPErrorHandler with Debug=true ([#&#8203;1477](https://github.com/labstack/echo/issues/1477), lammel) - Fix incorrect CORS headers ([#&#8203;1669](https://github.com/labstack/echo/issues/1669), ulasakdeniz) - Fix proxy middleware rewritePath to use url with updated tests ([#&#8203;1630](https://github.com/labstack/echo/issues/1630), arun0009) - Fix rewritePath for proxy middleware to use escaped path in ([#&#8203;1628](https://github.com/labstack/echo/issues/1628), arun0009) - Remove unless defer ([#&#8203;1656](https://github.com/labstack/echo/issues/1656), imxyb) **General** - New maintainers for Echo: Roland Lammel ([@&#8203;lammel](https://github.com/lammel)) and Pablo Andres Fuente ([@&#8203;pafuent](https://github.com/pafuent)) - Add GitHub action to compare benchmarks ([#&#8203;1702](https://github.com/labstack/echo/issues/1702), pafuent) - Binding query/path params and form fields to struct only works for explicit tags ([#&#8203;1729](https://github.com/labstack/echo/issues/1729),[#&#8203;1734](https://github.com/labstack/echo/issues/1734), aldas) - Add support for Go 1.15 in CI ([#&#8203;1683](https://github.com/labstack/echo/issues/1683), asahasrabuddhe) - Add test for request id to remain unchanged if provided ([#&#8203;1719](https://github.com/labstack/echo/issues/1719), iambenkay) - Refactor echo instance listener access and startup to speed up testing ([#&#8203;1735](https://github.com/labstack/echo/issues/1735), aldas) - Refactor and improve various tests for binding and routing - Run test workflow only for relevant changes ([#&#8203;1637](https://github.com/labstack/echo/issues/1637), [#&#8203;1636](https://github.com/labstack/echo/issues/1636), pofl) - Update .travis.yml ([#&#8203;1662](https://github.com/labstack/echo/issues/1662), santosh653) - Update README.md with an recents framework benchmark ([#&#8203;1679](https://github.com/labstack/echo/issues/1679), pafuent) This release was made possible by **over 100 commits** from more than **20 contributors**: asahasrabuddhe, aldas, AndrewKlotz, arun0009, chotow, curvegrid, iambenkay, imxyb, juanbelieni, lammel, little-cui, lnenad, pafuent, pofl, pr0head, pwli, RashadAnsari, rkfg, santosh653, segfiner, stffabi, ulasakdeniz </details> --- ### Renovate configuration 📅 **Schedule**: At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻️ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
renovate added the
dependencies
label 2021-02-11 19:00:32 +00:00
renovate added 1 commit 2021-02-11 19:00:33 +00:00
continuous-integration/drone/pr Build is passing Details
cb699c779d
Update module labstack/echo/v4 to v4.2.0
konrad merged commit 618b464ca3 into main 2021-02-13 22:46:04 +00:00
Sign in to join this conversation.
No reviewers
No Milestone
No Assignees
1 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: vikunja/vikunja#785
No description provided.