🚀 Enhancements
- resolveDotSegments: Add
mergeSlashesoption (9581407) - session: Default session cookie to
SameSite=Lax(acf8d77) - ⚠️ Escape interpolated values in html tagged template (#1459)
- readValidatedBody: Support readBody options (#1476)
- Add
onDisposehook (#1488) - defineValidatedHandler: Support async validation (#1491)
- sse: Allow returning EventStream directly from handlers (#1508)
🔥 Performance
- Single-scan fast-path guard for
resolveDotSegments(#1458) - cookie: Avoid quadratic chunked cookie parsing and header rebuilds (#1472)
- middleware: Precompose middleware chains (#1475)
- body-limit: Stream enforcement instead of pre-buffering (#1500)
🩹 Fixes
- resolveDotSegments: Preserve trailing slash on trailing dot segments (ca7de07)
- cookie: Dedup cookies with leading-dot / mixed-case domains (#1462)
- cors: Warn on credentials with null origin (#1464)
- Decode Basic-auth credentials as UTF-8 (#1463)
- proxy: forwardHeaders must not override framing headers (#1467)
- cookie: Cap chunk count in
setChunkedCookie(#1469) - cors: Set single-valued CORS headers instead of appending (#1466)
- auth: Harden basic-auth realm handling and credential timing (#1468)
- validate: Convert malformed JSON to 400 in validated-handler path (#1465)
- base: Collapse leading-slash run in all base-stripping sites (#1471)
- html: Make
raw()trust marker unforgeable and hoist escape map (#1473) - json-rpc: Use
-32600for valid-JSON non-object bodies (#1483) - Only discard prepared headers for error responses (#1486)
- event-stream: Correct stream teardown on close and client disconnect (#1484)
- deprecated: Correct v1 signatures in the compat shim (#1492)
- response: Do not render non-Error throws as successful responses (#1485)
- event: Keep
event.contextandreq.contextas one reference (#1499) - response: Absorb errors thrown in
onResponsehook (4a32c1b) - response: Route synchronous
prepareResponsethrows through the error pipeline (#1503) - response: Keep
content-lengthheader forUint8Arrayresponses (#1504) - response: Strip
HEADbody when merging prepared headers into a mutable Response (#1490) - response: Allow status and headers staged during the first stream chunk (#1512)
💅 Refactors
- request: ⚠️ Make
x-forwarded-prototrust opt-in (#1461) - event-stream: ⚠️ Drop autoclose option (#1495)
- sse: Promote EventStream to public API, deprecate
createEventStream(#1509)
📖 Documentation
- Security caveats for cors, proxy, redirect, host and static utils (#1470)
- Explain
event.url.pathnamedecoding (3f8b5bc)
🌊 Types
🏡 Chore
- Update srvx to 0.12 (5eb0a01) (release notes)
- Update undocs (ba42947)
❤️ Contributors
- Pooya Parsa (@pi0)
- N0liu (@n0liu)
- G1mn
- Sandro Circi (@sandros94)
- Max (@onmax)