Overview
Version 2.3 improves stability and security with fixes for memory leaks, encoding issues, and request handling. Most deployments require no changes, but new access-control rules apply to query functions.
Key improvements
Security
- Query functions now require
USAGEprivilege on the foreign server, preventing unauthorised access through credential misuse.
New features
max_response_sizeserver option to cap response body size and fail gracefully when limits are exceeded.
Reliability
- Fixed numerous memory leaks during error conditions and encoding conversion failures.
- Improved error messages to diagnose misconfiguration and server issues.
- Request URLs now handle query strings and API keys correctly.
- Removed spurious query cancellations caused by routine PostgreSQL maintenance signals.
Correctness
- Entrance tags are now included in results where they were previously lost.
- Coordinate validation now catches invalid
NaNvalues. - Database encoding is now respected in both directions (parameter encoding and response decoding).
- Header injection and response parsing vulnerabilities have been closed.
Migration notes
The USAGE privilege check is the only change affecting existing deployments:
-- If users cannot run query functions, grant the privilege:
GRANT USAGE ON FOREIGN SERVER osm TO some_role;Invalid polygon_threshold values (negative, NaN, infinite) now raise an error instead of being silently forwarded to the server.
Full details
See CHANGELOG.md for a complete list of changes.