github dunglas/mercure v1.0.3

3 hours ago

Community

Mercure 1.0.3 moves the hub to Caddy 2.11.7, which brings the security fixes and hardening of Caddy 2.11.6: slowloris mitigation through idle read/write timeouts, a default cap on request header size, and fixes to the reverse proxy. Caddy now also supports the Incremental header field (RFC 10036), which the hub already sends on every event stream: a Caddy reverse proxy in front of a hub now forwards events immediately, without flush_interval -1. Read the upgrade notes below if your access tokens are large.

⚠️ Upgrade Notes

  • Request headers are limited to 16 KiB by default. The hub accepts access tokens up to 64 KiB, but a token sent in the Authorization header or the mercureAuthorization cookie and larger than 16 KiB is now refused with 431 Request Header Fields Too Large. If your tokens carry long topic lists, raise the limit with the max_header_size server option.
  • Stalled connections are closed after one minute. Pauses between events don't count, so subscribers are not affected. Tune with read_body_idle and write_idle in the timeouts server option.
  • Request header fields containing a . are now dropped, like those containing a _. See the Caddy 2.11.6 breaking changes for the full list.

✨ New Features

📖 Documentation

  • Upgrade guide: new section on moving publisher_jwt, subscriber_jwt and *_jwks_url into issuer blocks, the MERCURE_TRUSTED_ISSUERS variable, and the stricter key validation. by @dunglas in #1412

Enterprise

Mercure Cloud and Mercure Enterprise pick up the same changes. The on-prem hub ships as image v1.0.3, and Cloud tenants are being rolled onto it.

These fixes ship under the Enterprise SLA, with prioritized patches and direct support. Contact contact@mercure.rocks for the managed Cloud offering, on-premise licenses, custom development, consulting, and training.

Full Changelog: v1.0.2...v1.0.3

Don't miss a new mercure release

NewReleases is sending notifications on new releases.