Community
Mercure 1.0.3 moves the hub to Caddy 2.11.7, which brings the security fixes and hardening of Caddy 2.11.6: slowloris mitigation through idle read/write timeouts, a default cap on request header size, and fixes to the reverse proxy. Caddy now also supports the Incremental header field (RFC 10036), which the hub already sends on every event stream: a Caddy reverse proxy in front of a hub now forwards events immediately, without flush_interval -1. Read the upgrade notes below if your access tokens are large.
⚠️ Upgrade Notes
- Request headers are limited to 16 KiB by default. The hub accepts access tokens up to 64 KiB, but a token sent in the
Authorizationheader or themercureAuthorizationcookie and larger than 16 KiB is now refused with431 Request Header Fields Too Large. If your tokens carry long topic lists, raise the limit with themax_header_sizeserver option. - Stalled connections are closed after one minute. Pauses between events don't count, so subscribers are not affected. Tune with
read_body_idleandwrite_idlein thetimeoutsserver option. - Request header fields containing a
.are now dropped, like those containing a_. See the Caddy 2.11.6 breaking changes for the full list.
✨ New Features
- Upgrade to Caddy 2.11.7 and OpenTelemetry 1.47. by @dunglas in #1415
📖 Documentation
- Upgrade guide: new section on moving
publisher_jwt,subscriber_jwtand*_jwks_urlintoissuerblocks, theMERCURE_TRUSTED_ISSUERSvariable, and the stricter key validation. by @dunglas in #1412
Enterprise
Mercure Cloud and Mercure Enterprise pick up the same changes. The on-prem hub ships as image v1.0.3, and Cloud tenants are being rolled onto it.
These fixes ship under the Enterprise SLA, with prioritized patches and direct support. Contact contact@mercure.rocks for the managed Cloud offering, on-premise licenses, custom development, consulting, and training.
Full Changelog: v1.0.2...v1.0.3