Angaben zum Datum
Datum aus der Quelle.
Erstmals gesehen am .
Fiber Version 3.5.0: Proxy-Härtung mit SecurityPolicy und schnelleres Routing
Fiber v3.5.0 härtet die Proxy-Middleware mit der neuen proxy.SecurityPolicy (standardmäßig werden private/Loopback-Upstreams, Nicht-http(s)-Schemata und HTTPS-zu-HTTP-Redirect-Downgrades abgelehnt), ergänzt den Struct-Tag binding_source für eigene Bindungsreihenfolgen sowie die Option SkipUnmatchedRoutes für schnelle 404/405-Antworten und beschleunigt das Route-Matching.
🚀 New
- Harden proxy middleware (#4405)
New
proxy.SecurityPolicywith secure defaults: private/loopback upstreams, non-http(s) schemes and HTTPS-to-HTTP redirect downgrades are rejected and hop-by-hop headers stripped.
https://docs.gofiber.io/middleware/proxy#securityproxy.WithSecurityPolicy(proxy.SecurityPolicy{ AllowPrivateIPs: true, // internal upstreams are blocked by default }) - Add support for custom binding precedence (#4544)
New
binding_sourcestruct tag overrides theBind().All()source order per struct; the resolved order is cached perreflect.Type.
https://docs.gofiber.io/api/bind#custom-precedencetype SearchReq struct { Name string `binding_source:"query,header,cookie,body,uri" query:"name" header:"x-name" json:"name"` } - Add SkipUnmatchedRoutes with two-tier 404/405 fast path (#4486)
New
fiber.Configoption that answers unregistered paths with404/405before the middleware chain runs (CORS preflight exempt, off by default).
https://docs.gofiber.io/api/fiber#skipunmatchedroutesapp := fiber.New(fiber.Config{ SkipUnmatchedRoutes: true, // default: false })
🧹 Updates
- Speed up route matching with a flat tree index, leading-byte candidate rejection and a specialized /const/:param matcher (#4558)
- Quick-reject routes on precomputed slash-count bounds (#4517)
- Restore Route inlining lost in the RFC 9110 changes (#4501) …