Skip to content

Releases: gofiber/fiber

v2.52.14

Choose a tag to compare

@ReneWerner87 ReneWerner87 released this 06 Jul 06:30
a74500f

What's Changed

🐛 Bug Fixes

New Contributors

Full Changelog: v2.52.13...v2.52.14

v3.4.0

Choose a tag to compare

@github-actions github-actions released this 02 Jul 07:39

🚀 New

  • Complete HTTP QUERY method support (#4436, #4456)
    Adds the HTTP QUERY method (RFC 10008): fiber.MethodQuery, app.Query() routing, safe/idempotent handling in csrf, idempotency, earlydata and cache, plus client.Query() shorthands.
    app.Query("/search", func(c fiber.Ctx) error {
        return c.Send(c.Body()) // QUERY carries the query expression in the body
    })
    https://docs.gofiber.io/client/rest#query
  • Add WithContext variants for session storage I/O (#4393)
    SaveWithContext, DestroyWithContext, RegenerateWithContext and ResetWithContext propagate deadlines/cancellation to the session storage backend; the plain methods keep working unchanged.
    sess := session.FromContext(c)
    err := sess.SaveWithContext(ctx) // storage write bounded by ctx
    https://docs.gofiber.io/middleware/session#session-with-context-timeoutscancellation
  • Unify internal and custom constraints into a single interface (#4397)
    Built-in and custom route constraints now share one ConstraintHandler interface; the optional ConstraintAnalyzer precomputes constraint data at route registration, removing per-request parsing. Existing CustomConstraint implementations keep working unchanged.
    app.RegisterCustomConstraint(evenConstraint{}) // implements Name() + Execute()
    app.Get("/items/:id<even>", handler)
    https://docs.gofiber.io/guide/routing#constrainthandler-interface
  • Expose prefork RecoverInterval and ShutdownGracePeriod (#4491)
    New ListenConfig knobs: PreforkRecoverInterval delays respawning a crashed child (default 0) and PreforkShutdownGracePeriod sets how long the master waits after SIGTERM before SIGKILL (default 5s).
    app.Listen(":3000", fiber.ListenConfig{
        EnablePrefork:              true,
        PreforkRecoverInterval:     time.Second,
        PreforkShutdownGracePeriod: 10 * time.Second,
    })
    https://docs.gofiber.io/api/fiber#preforkrecoverinterval

🧹 Updates

  • Reduce avoidable work in the request hot path (#4490)
  • Avoid per-request heap allocation in DefaultErrorHandler (#4446)
  • Use sentinel errors on typed-getter and Range parse failures (#4448)
  • Replace appendLowerBytes with utilsbytes.UnsafeToLower (#4468)
  • Add MIMETextEventStream constant (#4415)
  • Cache binder decoder type metadata across requests (#4447)
  • Eliminate double reflection in binder mergeStruct (-10% allocs) (#4385)
  • Reduce binder data map allocations (#4379)
  • cache: Append canonical key segments into the pooled buffer (#4450)
  • cors: Optimize subdomain origin matching (#4482)
  • cors: Optimize exact-origin lookup to O(1) (#4368)
  • csrf/redirect: Share scheme/host matching and skip url.Parse on the hot path (#4449)
  • Narrow client user hook lock scope safely (#4375)
  • Raise middleware coverage above 90% for timeout, logger, idempotency, limiter, cache (#4466)
  • Cover remaining cors/csrf middleware branches (#4462)
  • Add unit tests for isOriginSerializedOrNull (#4461)
  • Cover session deadline/error paths and delegate Middleware lifecycle methods (#4435)
  • Inject clock to make time-dependent tests deterministic (#4430)
  • Rename benchmark cases (#4383)
  • Remove test-only dead code and add manual deadcode workflow (#4458)
  • Remove dead code flagged by static analysis (#4454)
  • Static analysis cleanups (#4444)
  • Fix modernize lint issues (#4315)

🐛 Fixes

  • Evaluate If-Modified-Since when If-None-Match is absent in Fresh (#4488)
  • Fix open redirect via Redirect().Back() by validating the Referer header origin (#4370)
  • Fix data race on lazy appListKeys generation in Render (#4440)
  • Avoid route fallback errors during server error middleware traversal (#4426)
  • Strip all trusted proxy IPs from X-Forwarded-For chain (#4394)
  • Guard typed-nil errors (#4407)
  • Guard typed-nil Fiber error paths without reflection (#4372)
  • Preserve legacy custom constraint arguments (#4432)
  • Remove unreachable SameSiteDefaultMode case (#4471)
  • Detach quoted filename strings from pooled buffers (#4374)
  • Prevent app.init mutex deadlock on panic (#4366)
  • Enforce CertClientFile for AutoCertManager TLS (#4312)
  • cache: Separate authorization key segment (#4467)
  • cache: Hash QUERY body keys (#4459)
  • cache: Evaluate freshness after locking (#4419)
  • cors: Validate wildcard origins before matching (#4438)
  • cors: Reject empty wildcard labels (#4437)
  • csrf: Validate nested extractor chains (#4439)
  • csrf: Port CORS subdomain match fixes (#4455)
  • etag: Skip Server-Sent Events responses (#4487)
  • Guard extractor introspection cycles (#4453)
  • helmet: Use Scheme() for HTTPS detection and validate HSTS configuration (#4389)
  • hostauthorization: Reject malformed hostnames in wildcard path (#4408)
  • idempotency: Make MemoryLock safe for zero-value use (#4371)
  • limiter: Correct fixed-window hit credit on skipped requests (#4422)
  • logger/cache/storage: Remove unbounded background goroutines (#4378)
  • pprof/proxy: Fix trailing-slash redirect and balancer empty-server panic (#4421)
  • proxy: Bound upstream connections by default (#4369)
  • rewrite/redirect: Anchor rules to the start of the path (#4483)
  • session: Prevent session fixation by preserving successful extractor in chains (#4469)
  • session: Prevent store error disclosure (#4424)
  • session: Restore isFresh field name (#4477)
  • sse: Preserve trailing newlines in event data (#4414)
  • timeout: Isolate default timeout responses (#4442)
  • timeout: Reclaim abandoned fiber.Ctx via ScheduleReclaim latch (#4359, #4400)
  • Fix client config locking races (#4470)
  • Fix client default access race in Replace/C path (#4377)
  • Handle panics in client execFunc without crashing callers (#4365)
  • Address bugs found in codebase audit (#4420)
  • Fix cleanup follow-ups and regression coverage (#4380)

🛠️ Maintenance

22 changes
  • bump github.com/klauspost/compress from 1.18.7 to 1.19.0 (#4489)
  • bump github.com/klauspost/compress from 1.18.6 to 1.18.7 (#4485)
  • bump github.com/andybalholm/brotli from 1.2.1 to 1.2.2 (#4484)
  • bump github.com/valyala/fasthttp from 1.71.0 to 1.72.0 in the fasthttp-modules group (#4481)
  • bump actions/cache/restore from 6.0.0 to 6.1.0 (#4480)
  • bump actions/cache/save from 6.0.0 to 6.1.0 (#4479)
  • bump release-drafter/release-drafter from 7.5.0 to 7.5.1 (#4463)
  • bump release-drafter/release-drafter from 7.4.0 to 7.5.0 (#4457)
  • bump actions/cache from 5.0.5 to 6.0.0 (#4452)
  • bump actions/setup-go from 6.4.0 to 6.5.0 (#4451)
  • bump actions/checkout from 6.0.3 to 7.0.0 (#4441)
  • bump release-drafter/release-drafter from 7.3.1 to 7.4.0 (#4434)
  • bump golang.org/x/net from 0.55.0 to 0.56.0 in the golang-modules group (#4425)
  • bump github.com/gofiber/schema from 1.7.2 to 1.8.0 (#4417)
  • bump the golang-modules group with 2 updates (#4416)
  • bump golang.org/x/sys from 0.45.0 to 0.46.0 in the golang-modules group (#4412)
  • bump codecov/codecov-action from 6.0.1 to 7.0.0 (#4413)
  • bump actions/checkout from 6.0.2 to 6.0.3 (#4398)
  • bump github.com/gofiber/schema from 1.7.1 to 1.7.2 (#4396)
  • bump github.com/mattn/go-colorable from 0.1.14 to 0.1.15 (#4384)
  • bump release-drafter/release-drafter from 7.3.0 to 7.3.1 (#4314)
  • bump the golang-modules group with 3 updates (#4310)

📚 Documentation

  • Restructure routing guide and split handler partials (#4311)
  • Fix Ctx.Scheme/Protocol documentation (#4473, #4474)
  • Clarify client hook concurrency contract (#4386)
  • keyauth: Fix extractor examples (#4409)
  • Add FAQ troubleshooting entry for the "id <= evictCount" (hpack/gRPC) panic (#4475)
  • Replace interface{} with any (Go 1.18+) (#4433)
  • Document thread-safety contracts for mutex-backed public types (#4367)
  • Enhance sponsorship section in README (#4402)

📒 Documentation: https://docs.gofiber.io/next/

💬 Discord: https://gofiber.io/discord

Full Changelog: v3.3.0...v3.4.0

Thank you @0xghost42, @Amirhf1, @DucMinhNe, @Fenny, @MD-Mushfiqur123, @ReneWerner87, @alexandear, @fereidani, @gaby, @james-yusuke, @ksw2000, @nekoworks-magic, @niksis02, @pageton, @sixcolors and @talktokim for making this release possible.

v3.3.0

Choose a tag to compare

@github-actions github-actions released this 22 May 07:15
a39a035

🚀 New

  • Add support for configuring the Regex engine on the router (#4254)
    Swap the compiler used for regex() route constraints. Assign a drop-in engine such as coregex.MustCompile for faster matching;Fiber reuses the compiled matcher across requests.
    app := fiber.New(fiber.Config{
        RegexHandler: coregex.MustCompile, // default: regexp.MustCompile
    })
    https://docs.gofiber.io/api/fiber#regexhandler
  • Host auth middleware (#4199)
    New hostauthorization middleware that validates the incoming Host header against an allowlist (exact host, .subdomain wildcard, CIDR range) to protect against DNS rebinding attacks.
    app.Use(hostauthorization.New(hostauthorization.Config{
        AllowedHosts: []string{"api.myapp.com", ".myapp.com", "10.0.0.0/8"},
    }))
    https://docs.gofiber.io/middleware/hostauthorization
  • Delegate implementation to fasthttp/prefork (#4210)
    Prefork now delegates to fasthttp's prefork package and adds PreforkRecoverThreshold (max child restarts before the master exits) and PreforkLogger to ListenConfig.
    https://docs.gofiber.io/api/fiber#preforkrecoverthreshold
  • Add support for contextual logs (#4241)
    Render request-scoped fields in log.WithContext(c) by configuring a template with log.SetContextTemplate, reusing the middleware/logger engine (including ${value:key} for arbitrary context values).
    log.MustSetContextTemplate(log.ContextConfig{Format: log.RequestIDFormat})
    
    app.Get("/", func(c fiber.Ctx) error {
        log.WithContext(c).Info("start") // renders the request id
        return c.SendString("ok")
    })
    https://docs.gofiber.io/api/log#bind-context
  • Add storage backed SharedState for prefork applications (#4243)
    A prefork-safe, storage-backed key/value store via app.SharedState() for data shared across workers/processes, with JSON/MsgPack/CBOR/XML helpers and automatic key namespacing. app.State() stays process-local.
    app := fiber.New(fiber.Config{
        SharedStorage: redis.New(), // any fiber.Storage shared across workers
    })
    app.SharedState().SetJSON("config", cfg, 0)
    https://docs.gofiber.io/api/state#sharedstate-prefork-safe
  • Add lightweight SSE middleware (#4239)
    A Fiber-native middleware/sse for Server-Sent Events: SSE headers, event/comment/retry frames, per-write flushing, heartbeats,
    Last-Event-ID access, and disconnect detection via stream.Context().
    app.Get("/events", sse.New(sse.Config{
        Handler: func(c fiber.Ctx, stream *sse.Stream) error {
            return stream.Event(sse.Event{Name: "message", Data: fiber.Map{"message": "hello"}})
        },
    }))
    https://docs.gofiber.io/middleware/sse

🧹 Updates

  • Add prefixes to unexported boolean fields (#4300)
  • Improve error messages in SaveFileToStorage (#4173)
  • Streamline request handler selection and context management for improved performance (#4233)

🐛 Fixes

  • Preserve mounted sub-app regex handler during mount prefixing (#4308)
  • Trim only one trailing dot in host normalization (#4307)
  • Reject oversized unknown-length adaptor request bodies (#4306)
  • Fix compress middleware's shouldSkip method to avoid memory growth (#4284)
  • Reject malformed host authorities in hostauthorization (#4293)
  • Synchronize view reloads with template rendering (#4288)
  • Avoid panic for non-struct listeners in TLS config discovery (#4305)
  • Clear plaintext cookie when encryption fails (#4303)
  • Fix regex route constraint parsing with literal > (#4292)
  • Reject empty normalized host before dynamic matching (#4291)
  • Preserve idempotency replay protection for oversized responses (#4287)
  • Enforce CookieJar domain acceptance and host-only cookie matching (#4282)
  • Avoid panic when reading released Fiber context values (#4271)
  • Enforce static root for fs-backed directory serving (#4277)
  • Prevent negative paginate start overflow (#4272)
  • Prevent SharedState namespace key collisions (#4274)
  • Copy FullURL string before returning pooled buffer (#4275)
  • Enforce paginate sort allowlist when AllowedSorts is unset (#4276)
  • Validate and safely apply workflow version updates (#4273)
  • Close BodyStream in adaptor FiberHandler streaming path (#4267)
  • Prevent panic when MsgPack is not configured (#4268)
  • Keep IsFromLocal loopback-only and add unix-socket helper (#4270)
  • Prevent panic when CBOR is not explicitly configured (#4269)
  • Guard session logger tag against released middleware (#4265)
  • Add X-Real-IP protection to Forward and DomainForward variants (#4261)
  • Ensure BalancerForward overwrites X-Real-IP header (#4260)
  • Add test coverage for multipart BodyLimit error handling (#4237)
  • Improve error propagation in Express-style handler (#4250)
  • Remove SSE Next and clarify SSE handler docs (#4247)
  • BasicAuth verifier for unknown users (#4245)

🛠️ Maintenance

13 changes
  • bump github.com/shamaton/msgpack/v3 from 3.1.1 to 3.1.2 (#4296)
  • bump codecov/codecov-action from 6.0.0 to 6.0.1 (#4294)
  • bump actions/add-to-project from 1.0.2 to 2.0.0 (#4256)
  • bump github.com/shamaton/msgpack/v3 from 3.1.0 to 3.1.1 (#4281)
  • bump the golang-modules group with 3 updates (#4278)
  • bump golang.org/x/sys from 0.43.0 to 0.44.0 in the golang-modules group (#4262)
  • bump DavidAnson/markdownlint-cli2-action from 23.1.0 to 23.2.0 (#4259)
  • bump benchmark-action/github-action-benchmark from 1.22.0 to 1.22.1 (#4258)
  • bump github.com/valyala/fasthttp from 1.70.0 to 1.71.0 in the fasthttp-modules group (#4255)
  • bump github.com/klauspost/compress from 1.18.5 to 1.18.6 (#4249)
  • bump DavidAnson/markdownlint-cli2-action from 23.0.0 to 23.1.0 (#4246)
  • bump github.com/mattn/go-isatty from 0.0.21 to 0.0.22 (#4242)

📚 Documentation

  • Fix invalid RouteChain method chaining example (#4304)
  • Harden reverse proxy X-Forwarded-For example (#4266)
  • Correct fasthttpctx Done semantics in context guide (#4264)
  • Clarify ${bytesSent} behavior in logger middleware (#4251)
  • Clarify prefork security model and OS-specific socket behavior (#4240)

📒 Documentation: https://docs.gofiber.io/next/

💬 Discord: https://gofiber.io/discord

Full Changelog: v3.2.0...v3.3.0

Thank you @ReneWerner87, @elton-peixoto-lu, @gaby, @gtoxlili, @lyyvalhalla, @mutantkeyboard, @pageton and @pratikramteke for making this release possible.

v3.2.0

Choose a tag to compare

@github-actions github-actions released this 25 Apr 10:53
bec9ba6

🚀 New

🧹 Updates

  • Optimize speed (#4231)
  • Remove duplicate benchmark handling and update benchmark action version (#4108)

🐛 Fixes

  • Fix race condition in TestTimeout_ContextPropagation (#4119)
  • Fix ARMv7 build overflow in etag middleware (#4190)
  • Fix HTML escaping in AutoFormat (#4228)
  • Structured default cache keys, and controls (#4224)
  • Enforce BodyLimit on request decompression and multipart form parsing (#4213)
  • Implement releaseData function for better resource management (#4209)
  • Strip path from referer before matching trusted origins (#4204)
  • Improve clarity for ProxyHeader and TrustProxy configuration (#4140)
  • Prefork children exit immediately in Docker containers (#4133)
  • Fix math.MaxUint32 overflow in etag middleware on 32-bit platforms (#4135)
  • Add nil checks to End() to prevent panic in streaming mode (#4128)
  • Custom binders bypass StructValidator in Body() and Custom() (#4124)

🛠️ Maintenance

43 changes
  • bump actions/setup-go from 6.2.0 to 6.3.0 (#4114)
  • bump golang.org/x/net from 0.50.0 to 0.51.0 in the golang-modules group (#4113)
  • bump github.com/gofiber/schema from 1.7.0 to 1.7.1 (#4220)
  • bump actions/setup-node from 6.3.0 to 6.4.0 (#4222)
  • bump dependabot/fetch-metadata from 3.0.0 to 3.1.0 (#4221)
  • bump github.com/tinylib/msgp from 1.6.3 to 1.6.4 (#4215)
  • bump github/codeql-action from 4.35.1 to 4.35.2 (#4216)
  • bump actions/cache from 5.0.4 to 5.0.5 (#4214)
  • bump actions/github-script from 8.0.0 to 9.0.0 (#4207)
  • bump release-drafter/release-drafter from 7.1.1 to 7.2.0 (#4206)
  • bump the golang-modules group with 2 updates (#4205)
  • bump github.com/mattn/go-isatty from 0.0.20 to 0.0.21 (#4203)
  • bump golang.org/x/text from 0.35.0 to 0.36.0 in the golang-modules group (#4202)
  • bump golang.org/x/sys from 0.42.0 to 0.43.0 in the golang-modules group (#4201)
  • bump github.com/valyala/fasthttp from 1.69.0 to 1.70.0 in the fasthttp-modules group across 1 directory (#4197)
  • bump lewagon/wait-on-check-action from 1.6.0 to 1.6.1 (#4198)
  • bump streetsidesoftware/cspell-action from 8.3.0 to 8.4.0 (#4188)
  • bump github.com/andybalholm/brotli from 1.2.0 to 1.2.1 (#4174)
  • bump benchmark-action/github-action-benchmark from 1.21.0 to 1.22.0 (#4172)
  • bump actions/setup-go from 6.3.0 to 6.4.0 (#4170)
  • bump lewagon/wait-on-check-action from 1.5.0 to 1.6.0 (#4171)
  • bump github/codeql-action from 4.35.0 to 4.35.1 (#4169)
  • bump dependabot/fetch-metadata from 2.5.0 to 3.0.0 (#4165)
  • bump codecov/codecov-action from 5.5.3 to 6.0.0 (#4166)
  • bump github/codeql-action from 4.34.1 to 4.35.0 (#4164)
  • bump DavidAnson/markdownlint-cli2-action from 22.0.0 to 23.0.0 (#4161)
  • bump github.com/klauspost/compress from 1.18.4 to 1.18.5 (#4158)
  • bump github/codeql-action from 4.34.0 to 4.34.1 (#4159)
  • bump github/codeql-action from 4.33.0 to 4.34.0 (#4156)
  • bump codecov/codecov-action from 5.5.2 to 5.5.3 (#4153)
  • bump release-drafter/release-drafter from 7.1.0 to 7.1.1 (#4152)
  • bump actions/cache from 5.0.3 to 5.0.4 (#4151)
  • bump release-drafter/release-drafter from 7.0.0 to 7.1.0 (#4147)
  • bump release-drafter/release-drafter from 6.4.0 to 7.0.0 (#4142)
  • bump github/codeql-action from 4.32.6 to 4.33.0 (#4141)
  • bump the golang-modules group with 3 updates (#4138)
  • bump golang.org/x/sys from 0.41.0 to 0.42.0 in the golang-modules group (#4136)
  • bump release-drafter/release-drafter from 6.3.0 to 6.4.0 (#4137)
  • bump github/codeql-action from 4.32.5 to 4.32.6 (#4131)
  • bump release-drafter/release-drafter from 6.2.0 to 6.3.0 (#4130)
  • bump actions/setup-node from 6.2.0 to 6.3.0 (#4129)
  • bump benchmark-action/github-action-benchmark from 1.20.7 to 1.21.0 (#4126)
  • bump github/codeql-action from 4.32.4 to 4.32.5 (#4123)

📚 Documentation

  • Key Value Expectation Notice (KeyAuth Middleware) (#4183)
  • Document array query parameter formats for Query binder (#4116)

📒 Documentation: https://docs.gofiber.io/next/

💬 Discord: https://gofiber.io/discord

Full Changelog: v3.1.0...v3.2.0

Thank you @JonasDoe, @ReneWerner87, @adrian-lin-1-0-0, @aviu16, @gaby, @ha-sante, @loderunner, @meruiden, @mutantkeyboard and @sixcolors for making this release possible.

v2.52.13

Choose a tag to compare

@ReneWerner87 ReneWerner87 released this 25 Apr 13:07
0c8cc20

What's Changed

🐛 Bug Fixes

  • Escape HTML output in Ctx.Format by @gaby in #4232

Full Changelog: v2.52.12...v2.52.13

v3.1.0

Choose a tag to compare

@github-actions github-actions released this 24 Feb 20:30
3c24ebe

🚀 New

  • expand middleware context helpers (#4079)
app := fiber.New(fiber.Config{
    PassLocalsToContext: true, // default: false
})

// Works for requestid, csrf, session, basicauth, keyauth middlewares
app.Use(requestid.New())

app.Get("/", func(ctx fiber.Ctx) error {
    // Value helpers from middlewares works now with 3 different context items
    id := requestid.FromContext(ctx)              // works always
    id := requestid.FromContext(ctx.RequestCtx()) // works always
    id := requestid.FromContext(ctx.Context())    // works only when `PassLocalsToContext` is true
    
    return c.SendString(id)
})

https://docs.gofiber.io/api/fiber/#passlocalstocontext

🧹 Updates

  • update utils and add go 1.26 for test workflow (#4087)
  • optimize helpers performance (#4049)
  • harden numeric constraint parsing and expand route tests (#4054)

🐛 Fixes

  • harden DefaultRes.Format against nil handler panics (#4105)
  • guard nil request in adaptor LocalContextFromHTTPRequest (#4097)
  • fix Unix-socket support in IsProxyTrusted (#4088)
  • harden proxy nil client handling in Do/Forward paths (#4083)
  • add nil-safety to response decode helpers (#4081)
  • sanitize attachment/download filenames (#4070)
  • harden flash cookie detection (#4078)
  • fix bind struct validation only for struct targets (#4082)
  • enforce Range header limit configuration (#4071)
  • apply limits to msgp serialization (#4065)
  • fix sanitizePath validation logic (#4064)
  • fix Test method returning empty response on timeout (#4063)
  • fix nil pointer dereference in context methods when accessed after release (#4062)
  • retry addon: remove unnecessary sleep after last failed attempt (#4060)
  • make TLS listener config discovery safer (#4055)
  • validate nil services early and during lifecycle (#4050)
  • skip non-string state keys during iteration (#4048)
  • harden Port() handling (#4051)
  • prevent panics on non-string log keys (#4046)

🛠️ Maintenance

  • bump streetsidesoftware/cspell-action from 8.2.0 to 8.3.0 (#4111)
  • bump the golang-modules group with 3 updates (#4080)
  • bump github.com/shamaton/msgpack/v3 from 3.0.0 to 3.1.0 (#4075)
  • bump github.com/klauspost/compress from 1.18.3 to 1.18.4 (#4076)
  • bump github.com/gofiber/schema from 1.6.0 to 1.7.0 (#4074)
  • bump golang.org/x/sys from 0.40.0 to 0.41.0 in the golang-modules group (#4073)
  • bump github/codeql-action from 4.32.3 to 4.32.4 (#4104)
  • bump github/codeql-action from 4.32.1 to 4.32.2 (#4058)
  • bump github/codeql-action from 4.32.0 to 4.32.1 (#4047)

📚 Documentation

  • update versioned storage imports in middleware docs (#4102)
  • update documentation for parser configuration and request handling (#4096)
  • fix invalid Go slice literal in middleware registration example (#4095)
  • document uri struct tag for ctx.Bind().URI() in migration guide (#4092)
  • document logger Stream rename (#4057)

📒 Documentation: https://docs.gofiber.io/next/

💬 Discord: https://gofiber.io/discord

Full Changelog: v3.0.0...v3.1.0

Thank you @ReneWerner87, @SadikSunbul, @gaby and @sixcolors for making this release possible.

v2.52.12

Choose a tag to compare

@ReneWerner87 ReneWerner87 released this 24 Feb 20:40
6cba195

🐛 Fixes

Full Changelog: v2.52.11...v2.52.12

v3.0.0

Choose a tag to compare

@ReneWerner87 ReneWerner87 released this 02 Feb 18:22
f8f34f6

For a detailed view of all changes and the migration guide, visit:
https://docs.gofiber.io/whats_new

Try our new migration tool to help you upgrade from v2 to v3:

go install github.com/gofiber/cli/fiber@latest
fiber migrate --to v3

What's Changed

🚀 New Features

  • 🚀 App (Docs)
    • Rename WithTlsConfig method to WithTLSConfig in (#2570)
    • Use any as default Message type of Error struct in (#1925)
    • Add support for custom constraints in (#2807)
    • Add support for trusted origins in (#2910)
    • Add DialDualStack option for upstream IPv6 support in (#2900)
    • TrustedOrigins using https://*.example.com style subdomains in (#2925)
    • Add configuration support to c.SendFile() in (#3017)
    • Add CHIPS support to Cookie in (#3047)
    • Add TestConfig to app.Test() for configurable testing in (#3161)
    • Add buffered streaming support in (#3131)
    • Add support for AutoTLS / ACME in (#3201)
    • Add support for configuring TLS Min Version in (#3248)
    • Fix square bracket notation in Multipart FormData in (#3235)
    • Add support for application state management in (#3360)
    • Add support for NewErrorf in (#3463)
    • Add UNIX socket support in (#3535)
    • Add support for Msgpack in (#3565)
    • Add default UTF-8 charset in (#3583)
    • Support for SendEarlyHints in (#3483)
    • Add conditional copy helpers in (#3703)
    • Add request inspection helpers in (#3727)
    • Add support for redacting values in (#3759)
    • Add support for handling unsupported HTTP methods as HTTP 501 in (#3854)
    • Add support for ReloadViews() in (#3876)
    • Expose startup message customization hooks in (#3824)
    • Migrate from UUIDv4 to SecureToken for key generation in (#3946)
    • Add ExpirationFunc for dynamic expiration in (#3984)
    • Auto-enforce Secure=true for Partitioned cookies in Cookie() in (#3976)
  • 📎 Binding (Docs)
    • Initial support for binding in (#1981)
    • Bind: add support for multipart file binding in (#3309)
    • Add All method to Bind in (#3373)
  • 🌎 Client (Docs)
    • Client refactor in (#1986)
    • Add support for creating Fiber client from existing FastHTTP client in (#3214)
    • Add support for iterator methods to Fiber client in (#3228)
    • Add support for HostClient and LBClient in (#3774)
    • Add support for streaming response bodies in client and response handling in (#4014)
  • 🧠 Context (Docs)
    • Convert fiber.Ctx type to interface in (#1928)
    • Add Drop method to DefaultCtx for silent connection termination in (#3257)
    • Add End() method to Ctx in (#3280)
    • Improve and Optimize ShutdownWithContext Func in (#3162)
    • Add support for context.Context in keyauth middleware in (#3287)
    • Fiber.Context implement context.Context in (#3382)
    • Add NewWithCustomCtx initialization helper in (#3476)
    • Add context methods to fiber.Storage interface in (#3566)
    • Add Fiber Context to BasicAuth Authorizer in (#3621)
    • Implement OverrideParam override behavior for DefaultCtx in (#3962)
    • Add context common request helpers in (#4007)
    • Adding GetReqHeaders and GetRespHeaders in (#2831)
    • Add Req and Res API in (#2894)
  • 🔬 Extractors (Docs)
    • Introduce Extractor pattern for session ID retrieval in (#3625)
    • Enhance extractor functionality with metadata and security validation in (#3630)
    • Add extractors package in (#3725)
  • 🧰 Generic (Docs)
    • Add QueryParser for get query using generic in (#2776)
    • Addition of Locals Function with Go Generics as an Alternative to c.Locals in (#2813)
    • Implement new generic functions: Params, Get and Convert in (#2850)
    • Support generic configurable logger in (#3705)
  • 🚀 Listen (Docs)
    • Merge Listen methods & ListenConfig in (#1930)
    • Add support for graceful shutdown timeout in ListenConfig in (#3220)
    • Add TLSConfig to ListenConfig in (#4024)
  • 🔌 Addons/retry (Docs)
    • Add retry mechanism in (#1972)
  • 🧬 Middleware – adaptor (Docs)
    • Add BodyStream() logic to adaptor.FiberHandler middleware in (#3799)
    • Add local context support to adaptor middleware in (#3975)
  • 🧬 Middleware – basicauth (Docs)
    • Add HeaderLimit option to BasicAuth middleware in (#3620)
    • Support hashed BasicAuth passwords in (#3631)
  • 🧬 Middleware – cache (Docs)
    • Add Cache Invalidation Option to Cache Middleware in (#3036)
    • Add Max Func to Limiter Middleware in (#3070)
    • Support for disabling response headers in Limiter Middleware in (#3618)
  • 🧬 Middleware – compression (Docs)
    • Add support for zstd compression in (#3041)
    • Add support for CBOR encoding in (#3173)
  • 🧬 Middleware – cors (Docs)
    • Add support for Access-Control-Allow-Private-Network in (#2908)
  • 🧬 Middleware – csrf (Docs)
    • Add support for Sec-Fetch-Site header in CSRF middleware in (#3913)
  • 🧬 Middleware – encryptcookie (Docs)
    • Add cookie name authentication for EncryptCookie middleware in (#3788)
  • 🧬 Middleware – favicon (Docs)
    • Add MaxBytes to favicon middleware in (#4016)
  • 🧬 Middleware – earlydata (Docs)
    • Add earlydata middleware in (#2270)
  • 🧬 Middleware – healthcheck (Docs)
    • Migrate HealthChecker to v3 in (#2884)
    • Add Startup Probe to Healthcheck Middleware in (#3069)
  • 🧬 Middleware – idempotency (Docs)
    • Add idempotency middleware in (#2253)
  • 🧬 Middleware – keyauth (Docs)
    • Add support for custom KeyLookup functions in the Keyauth middleware in (#3028)
  • 🧬 Middleware – logger (Docs)
    • Refactor logger middleware in (#1979)
    • Add AllLogger to Config in (#3153)
    • Add Skip function to logger middleware in (#3333)
    • Add predefined log formats in (#3359)
    • Add support for ForceColors in Logger middleware in (#3428)
  • 🧬 Middleware – proxy (Docs)
    • Add support for TrustProxy in (#3170)
    • Add KeepConnectionHeader option to Proxy middleware in (#3662)
  • 🧬 Middleware – requestid (Docs)
    • Add Context Support to RequestID Middleware in (#3200)
    • Validate HTTP headers in RequestID middleware in (#3919)
  • 🧬 Middleware – responsetime (Docs)
    • Add response time middleware in (#3891)
  • 🧬 Middleware – session (Docs)
    • Re-write session middleware with handler in (#3016)
    • Add support for Keys() in session middleware in (#3517)
  • 🧬 Middleware – static (Docs)
    • Add static middleware in (#3006)
  • 🧬 Middleware – timeout (Docs)
    • Add config for Timeout middleware in (#3604)
  • 🔄️ Redirect (Docs)
    • New redirection methods in (#2014)
  • 🗺️ Router (Docs)
    • Router interface changes in (#2176)
    • Native support for net/http and fasthttp handlers in (#3769)
    • New Route method in (#2065)
    • New mounting system in (#2022)
    • Add support for RebuildTree in (#3074)
    • Add support for Express.js style req/res handlers in (#3809)
    • Add support for DisableAutoRegister of HEAD routes in (#3817)
    • Enhance CheckConstraint method for improved error handling in (#3356)
    • Add Support for Removing Routes in (#3230)
    • Add support for embedded Koa-Style Req and Res structs in (#3533)
    • Support Express-style next callback handlers in (#4029)
  • 🧩 Services (Docs)
    • Add Support for service dependencies in (#3434)

🧹 Updates

  • ⚙️ Core & API
    • Replace string functions in (#3923)
    • Update conditional instructions for startup skip in (#3475)
    • Update AGENTS startup instructions in (#3474)
    • Add []byte support to utils.EqualFold in (#2029)
    • Change startup message in (#2041)
    • Update to use gofiber/utils/v2 in (#2184)
    • Router: return status 501 instead of 400 on unknown method in (#2220)
    • Cleanup in (#2255)
    • Fix ContextKey collisions in (#2781)
    • Update Ctx.Format to match Express's res.format in (#2766)
    • Update handler signature for v3 in (#2794)
    • Change interface{} to any in (#2796)
    • Added respects body immutability to ctx.Body() and ctx.BodyRaw() functions. in (#2812)
    • Print to stderr if log fails for default format in (#2830)
    • Clean up errcheck config in (#2841)
    • Update startup message formatting in (#2847)
    • Simplify content negotiation code in (#2865)
    • Rename "ClientNew" Function to "New" in (#2896)
    • Remove repetitive words in (#2917)
    • Improper query/body parsing with embedded structs in (#2906)
    • Improve and simplify logic of ctx.Next() in (#3063)
    • Use Named Fields Instead of Positional and...
Read more

v2.52.11

Choose a tag to compare

@ReneWerner87 ReneWerner87 released this 31 Jan 15:56
65b0f3d

What's Changed

🧹 Updates

🐛 Bug Fixes

Full Changelog: v2.52.10...v2.52.11

v3.0.0-rc.3

v3.0.0-rc.3 Pre-release
Pre-release

Choose a tag to compare

@ReneWerner87 ReneWerner87 released this 19 Nov 15:42
76576dc

🚀 New Features

  • Middleware/encryptCookie: Add cookie name authentication for EncryptCookie middleware by @gaby in #3788
  • Middleware/proxy: Add BodyStream() logic to adaptor.FiberHandler middleware by @grivera64 in #3799
  • Client: Add support for HostClient and LBClient by @gaby in #3774
  • Native support for net/http and fasthttp handlers by @gaby in #3769
  • Add support for Express.js style req/res handlers by @gaby in #3809
  • Add support for DisableAutoRegister of HEAD routes by @ReneWerner87 in #3817
  • Add support for handling unsupported HTTP methods as HTTP 501 by @gaby in #3854
  • Add support for ReloadViews() by @gaby in #3876
  • Expose startup message customization hooks by @efectn in #3824

🧹 Updates

🐛 Bug Fixes

  • Middleware/limiter: Fix default value for MaxFunc in Limiter middleware by @gaby in #3871
  • Middleware/recover: Fix recover middleware panic output formatting by @gaby in #3816
  • Middleware/session: correct fresh flag logic in getSession by @sixcolors in #3825
  • Fix spelling issues by @jsoref in #3813
  • Fix fatal error calls in adapter_test.go by @ReneWerner87 in #3810
  • Fix usage of runtime RO data for ppc64 and s390x platforms by @gaby in #3772
  • Respect DisablePathNormalizing during client requests by @gaby in #3773
  • Always close form file by @arturmelanchyk in #3786
  • Fix gocritic httpNoBody and hugeParam issues by @ReneWerner87 in #3855
  • Prevent memory corruption in internal memory storage from pooled buffers by @sixcolors in #3828
  • Avoid writing into released Response in core::execFunc() by @arturmelanchyk in #3830
  • Remove Flash Cookie from Response headers after parsing by @gaby in #3840
  • Fix binder splitting for pointer-backed slice fields by @gaby in #3844
  • Execute middleware routes when handling errors by @gaby in #3846
  • fix copying of key/values in internal/memory by @sixcolors in #3829
  • Fix maintain CustomCtx across middlewares by @ReneWerner87 in #3852
  • Enhance Body handling in setConfigToRequest for better type su… by @K0ng2 in #3820

🛠️ Maintenance

  • Replace release-drafter autolabel with fuxingloh/multi-labeler by @gaby in #3872
  • Golangci-lint issue for go1.25.0 by @laughing-nerd in #3775
  • Add automation for v3 label assignments by @ReneWerner87 in #3845
  • Update workflow path filters for Go module changes by @ReneWerner87 in #3856
  • Improvements to GitHub Workflows by @gaby in #3857
  • Update release-drafter workflow by @gaby in #3860
  • Add support for codespell in spell-check workflow by @gaby in #3850
  • Add spell check CI workflow by @gaby in #3814
  • Fix autolabeler for release-drafter by @gaby in #3865
  • Enable manual workflow dispatch for CI by @ReneWerner87 in #3881
  • build(deps): bump github.com/valyala/fasthttp from 1.65.0 to 1.67.0 by @dependabot[bot] in #3790
  • build(deps): bump golang.org/x/net from 0.44.0 to 0.45.0 by @dependabot[bot] in #3791
  • build(deps): bump github/codeql-action from 3 to 4 by @dependabot[bot] in #3792
  • build(deps): bump golang.org/x/text from 0.29.0 to 0.30.0 by @dependabot[bot] in #3797
  • build(deps): bump golang.org/x/crypto from 0.42.0 to 0.43.0 by @dependabot[bot] in #3796
  • build(deps): bump golang.org/x/net from 0.45.0 to 0.46.0 by @dependabot[bot] in #3795
  • build(deps): bump actions/setup-node from 5 to 6 by @dependabot[bot] in #3804
  • build(deps): bump github.com/shamaton/msgpack/v2 from 2.3.1 to 2.4.0 by @dependabot[bot] in #3808
  • build(deps): bump github.com/valyala/fasthttp from 1.67.0 to 1.68.0 by @dependabot[bot] in #3819
  • build(deps): bump github.com/tinylib/msgp from 1.4.0 to 1.5.0 by @dependabot[bot] in #3823
  • build(deps): bump github.com/gofiber/utils/v2 from 2.0.0-rc.1 to 2.0.0-rc.2 by @dependabot[bot] in #3853
  • build(deps): bump golang.org/x/crypto from 0.43.0 to 0.44.0 by @dependabot[bot] in #3863
  • build(deps): bump golang.org/x/net from 0.46.0 to 0.47.0 by @dependabot[bot] in #3861
  • build(deps): bump github/codeql-action from 4.31.2 to 4.31.3 by @dependabot[bot] in #3866
  • build(deps): bump DavidAnson/markdownlint-cli2-action from 20.0.0 to 21.0.0 by @dependabot[bot] in #3873
  • build(deps): bump actions/checkout from 5.0.0 to 5.0.1 - by @dependabot[bot] in #3877
  • build(deps): bump github/codeql-action from 4.31.3 to 4.31.4 by @dependabot[bot] in
    #3878

📚 Documentation

New Contributors

A fully-detailed view of all new features and the migration guide is available in our
https://docs.gofiber.io/next/whats_new

Full Changelog: v3.0.0-rc.2...v3.0.0-rc.3