github dunglas/mercure v1.1.2

3 hours ago

Community

Mercure 1.1.2 fixes the public identity of hubs running behind a reverse proxy. Requests coming from trusted_proxies now honor X-Forwarded-Proto and X-Forwarded-Host, so a hub behind a TLS terminator expects https:// audiences and advertises https:// metadata without pinning resource_identifier. The community Docker image is also published to GitHub Container Registry, a way around Docker Hub rate limits in CI.

🐛 Bug Fixes

  • Caddy: derive the hub's public origin from the X-Forwarded-Proto and X-Forwarded-Host headers of requests sent by trusted_proxies. This sets the OAuth 2.0 resource identifier the hub expects as the token aud, the RFC 9728 metadata URL it advertises, and the origin checked against public_urls. Headers from other peers are still ignored, and malformed values are discarded. Check your tokens before upgrading: a hub behind a TLS terminator with trusted_proxies set and no resource_identifier previously expected an http:// audience and now expects the https:// one. Trusted proxies must replace these headers on every request. See Configure trusted proxies and the public hub URL. by @dunglas in #1437

✨ New Features

  • Docker: the community image is published to ghcr.io/dunglas/mercure alongside Docker Hub, with the same tags (latest, vX.Y.Z, vX.Y, vX). Docker Hub stays the default. by @GromNaN in #1436

Enterprise

Mercure Enterprise picks up the same fix in image v1.1.2. Mercure Cloud hubs now derive their identity from the hostname each client uses: a project with a custom domain accepts tokens whose aud matches its custom domain or its mercure.rocks subdomain, and advertises matching metadata on each. Cloud hubs are upgraded automatically: use Mercure Cloud to get fixes like these without managing upgrades yourself.

Enterprise releases ship under the Enterprise SLA, with prioritized patches and direct support. Contact contact@mercure.rocks for the managed Cloud offering, on-premise licenses, custom development, consulting, and training.

💖 New Contributors

Full Changelog: v1.1.1...v1.1.2

Don't miss a new mercure release

NewReleases is sending notifications on new releases.