github yusing/godoxy v0.32.0

latest release: v0.32.1
4 hours ago

Bug Fixes

  • Core/Routes: Partial file-provider reload failures preserve existing routes. (7adbf19, 4edd178, #273)
    • Valid additions and updates still apply; deletions wait for a clean reload.
    • Clean empty files still remove all file routes, and Docker/agent removals remain supported during partial failures.
  • Core/Configuration: Explicit empty lists remain distinct from omitted or null values when converting configuration values. (49e22e0)
    • Empty lists can disable inherited idlewatcher notification targets.
  • Deployment/Docker: The main image sets HOME=/app so the OVH SDK can check its optional configuration without permission errors when running as a non-root user. (ec19a07, #275)
  • WebUI/Certificates: Main and extra certificate forms offer backend-registered providers and provider-specific option fields. (3a41264, 5974829, #274, yusing/godoxy-webui@b79f285)
    • Structured options, including arrays and nested objects, are supported while option values remain redacted in JSON/YAML output.
    • Boolean provider options use labeled checkboxes in both forms, supporting existing boolean and string values while saving edits as booleans. (yusing/godoxy-webui@b79f285)
    • Switching providers refreshes option controls and clears old option values in the selected certificate form without changing the other form. (yusing/godoxy-webui@b79f285)
    • Inferred field labels use spaced words, such as Zone Token and Polling Interval. Generic duration guidance no longer replaces duration field names; other descriptions and raw configuration keys stay unchanged. (yusing/godoxy-webui@b79f285)
  • WebUI/Search: Apps without display names can be found by their aliases. (yusing/godoxy-webui@176f390, webui #21)
  • Core/Agents: Recovered agents retain their discovered names. (d579b86, #269)
    • Recovered names appear in provider logs, route metadata, and statistics.
  • Core/Agents: Agent v0.18.6 receives the correct upstream protocol, including h2c. (yusing/goutils@05a7cb0, cfae89e)
  • Core/Networking: Generated listener URLs preserve IPv6 brackets. (yusing/goutils@71fa4fe, cdeac60)
  • Core/GeoIP: Repeated MaxMind reloads no longer hit a cache-limit panic. (yusing/goutils@afabe72, yusing/goutils@9450745, 56fd47b)
    • Stopped MaxMind runtimes release cached data and callbacks.
  • Core/Events: Event streams continue after route or node removals. (yusing/goutils@32bb351, yusing/godoxy-webui@9c0b122)
    • Dashboard events show the names of removed routes and Proxmox nodes. (yusing/godoxy-webui@9c0b122)
    • Concurrent registry additions and removals no longer overwrite each other.
    • Listing a cleared registry no longer panics after removals.
  • Core/Rules: Repeated Basic Auth checks no longer panic on missing or invalid credentials. (yusing/goutils@1ab11c9)
  • Core/API: API error responses no longer fail when an error cause is absent. (yusing/goutils@78359dd)
  • Core/Listeners: HTTPS listeners support PROXY protocol without startup panics. (yusing/goutils@8803127)
  • Core/Events: Event IDs avoid deterministic collisions across processes. (yusing/goutils@c71a1e5)

New Features

  • Core/Idlewatcher: Optional sleep/pause and wake notifications use configured notification providers. (1025dc0, #264)
    • Enable them globally with defaults.idlewatcher.notify or per route with idlewatcher.notify; they are off by default.
    • Set to to provider names. An absent route block inherits global settings; an empty block inherits global targets, or uses all current providers at send time when neither block specifies targets.
    • Set notify: {to: []} to disable notifications and override global targets. A route with named targets can override a disabled global default.
    • Docker routes with proxy.idle_timeout can select targets with proxy.idle_notify_to: gotify,ntfy, or disable notifications with proxy.idle_notify_to: "".
    • Initial status, reloads, and dependency-only watchers stay silent; notifications report transitions rather than readiness or errors.
  • WebUI/Navigation: Header branding links to GitHub, and the version links to releases. (yusing/godoxy-webui@12f944b, webui #22)
  • Core/Logging: Startup logs show effective environment settings and their sources. (4824673, e60a798)
    • Sensitive setting values are redacted.
    • Unknown GODOXY_ variables produce name-only warnings.
    • Selected unprefixed app variables produce migration warnings but remain supported.

Breaking Changes

  • Core/Listeners: HTTPS startup requires a valid certificate. (yusing/goutils@8803127, e3d7700, 1c70409, cfae89e)
    • Set GODOXY_HTTPS_ADDR= for HTTP-only operation without a certificate.
    • An explicitly empty HTTPS address disables shared HTTP/3 and TCP SNI routing.
    • Dedicated route listeners are unaffected by disabling shared HTTPS.
    • The redirectHTTP middleware skips redirects when shared HTTPS is disabled.
    • Direct HTTP login requires GODOXY_API_JWT_SECURE=false.
    • Keep secure login cookies when clients connect through an external TLS-terminating proxy.
    • Failed startup closes partially started servers without disrupting existing TCP SNI routes.
  • Core/GeoIP: MaxMind downloads City databases by default. (4824673)
    • Set GODOXY_MAXMIND_COUNTRY_ONLY=true where City downloads are unavailable or Country-only data is required.
    • An existing Country database does not satisfy the new default, so a City database must be downloaded.
    • City databases provide the location data needed by timezone ACL rules.
    • City databases can exceed 100 MiB.
  • Deployment/Compose: The updated Compose example requires explicit deployment settings. (4824673)
    • When adopting the updated example, populate TAG, GODOXY_UID, GODOXY_GID, DOCKER_SOCKET, and LISTEN_ADDR in .env.
    • Set GODOXY_DOCKER_HOST in .env because Compose no longer injects a Docker endpoint.

Security

  • Core/ACL: Later country and timezone ACL rules match correctly. (3723f81, #270)
    • A nonmatching geographic rule no longer prevents a later deny or allow rule from matching.
  • Core/WebSocket: Local WebSocket endpoints reject cross-host origins. (yusing/goutils@7967281)
    • External reverse proxies must preserve the public Host header for same-host origin checks.
    • Closed WebSocket streams report closure instead of successful empty reads or writes.
  • Core/Redaction: Redacted output fully masks one- and two-character secrets. (yusing/goutils@c71a1e5)
    • Unicode redaction preserves valid character boundaries and JSON output.

CI

  • Contract Checks: Certificate-provider and environment contract checks run on pushes to main only when matching source, dependency, checked-output, workflow, or submodule-pointer paths change. Pull-request checks and all job steps remain unchanged. (881a4ca)

Full Changelog

  • c3b184d chore(webui): track reorganized main history
  • 881a4ca ci: limit contract checks to relevant push changes
  • b406ad2 fix(autocert): keep duration guidance out of field labels
  • b28305a fix(autocert): integrate provider form corrections
  • 5974829 fix(autocert): keep concrete provider options in sync
  • 3a41264 fix(autocert): guard schema-generated provider choices
  • ec19a07 fix(docker): set an accessible home for the main runtime
  • 1025dc0 Merge pull request #264 from taljaards/feat/idlewatcher-sleep-notifications
  • d4aed0d docs(config): clarify notification and environment examples
  • 518f42e Merge remote-tracking branch 'origin/main' into feat/idlewatcher-sleep-notifications
  • 49e22e0 fix(serialization): preserve explicit empty slices
  • 733a32f docs(idlewatcher): clarify default notification targets
  • 4c884cb refactor(idlewatcher): resolve notifier from task context
  • 4d4f916 refactor(idlewatcher): infer notification opt-in from targets
  • 2ef64af fix(serialization): preserve explicit empty slices
  • 8bdf61b refactor(idlewatcher): simplify sleep and wake notifications
  • 958498c Merge remote-tracking branch 'origin/main' into feat/idlewatcher-sleep-notifications
  • 8f28521 Merge pull request #273 from taljaards/codex/preserve-routes-on-partial-reload
  • fbb38ea chore: merge main into partial reload fix
  • 1de7944 chore(deps): update webui submodule
  • 4edd178 fix(provider): limit partial reload retention to file routes
  • 948dd3a chore: go mod tidy
  • fcab449 chore(deps): update webui submodule (#272)
  • 7adbf19 fix: preserve routes after partial reload failures
  • 46399bd feat(idlewatcher)!: drop the notify event filter
  • d7d6774 refactor(idlewatcher): tighten notify code and tests
  • 1773b1f fix(idlewatcher): inherit global notify events
  • 29e8571 chore(swagger): regenerate for idlewatcher notify config
  • 0197458 feat(docker): add proxy.idle_notify labels
  • 5aeffb7 feat(config): add defaults.idlewatcher.notify
  • 60572b9 feat(idlewatcher): notify on sleep and wake transitions
  • c1e07ca feat(idlewatcher): add sleep/wake notify config
  • fce8568 fix(wiki): quote generated frontmatter metadata
  • 378ac69 chore(idlewatcher): refresh minified loading script
  • 11b0a93 docs(wiki): refresh dependency migration documentation
  • 0b3fcfb chore(deps): update frontend tooling and webui gitlink
  • e454b5d chore(deps): update backend modules and migrate major APIs
  • e1557ba chore(deps): update webui submodule
  • 1c70409 fix(env): support explicitly disabling shared HTTPS
  • e3d7700 fix(entrypoint): preserve shared SNI listeners on startup failure
  • cdeac60 fix(env): bracket IPv6 hosts in generated URLs
  • 56fd47b fix(maxmind): release lookup caches on runtime cancellation
  • cfae89e test(goutils): adapt fixtures to strict HTTPS startup
  • 8e02291 chore(integration): align module requirements and package docs
  • e60a798 feat(logging): report safe effective environment settings
  • 4824673 feat(env): consume registry and generate deployment documentation
  • 3723f81 fix(acl): reuse resolved country data across geographic rules
  • d579b86 fix(provider): publish recovered agent names safely
  • 721f423 chore(deps): sync goutils release verification budget
  • d4a2571 chore(deps): advance goutils to CI-managed v0.8.0 release
  • d0ff796 refactor(goutils): integrate dependency-light utility modules

goutils

  • aba92f5 chore(release): prepare v0.9.3 modules
  • 4850351 chore(release): normalize Go version directives to 1.27
  • 6199c93 chore(release): prepare v0.9.2 modules
  • cdcf062 chore(deps): update modules and migrate backoff to v6
  • 75d2b8a chore(release): prepare v0.9.1 modules
  • 9450745 fix(cache): release janitor registrations for runtime-owned caches
  • a21196e chore(release): prepare v0.9.0 modules
  • 54a0142 docs(goutils): update package behavior references
  • afabe72 fix(cache): remove janitor state limit and handle concurrent registration
  • 7967281 fix(websocket): correct shutdown, reader, and origin handling
  • 885fea3 fix(task): allow finishing test tasks without root children
  • 32bb351 fix(pool): make registry mutations atomic per key
  • 78359dd fix(apitypes): skip nil errors in Error response builder
  • 71fa4fe fix(env): preserve IPv6 brackets in address URLs
  • 7c712ca fix(errs): handle nil unwrapped errors and empty field hints
  • fae0430 docs(eventqueue): clarify queue lifecycle and callback behavior
  • 04d7768 fix(fs): skip hidden entries at every directory level
  • 1ab11c9 fix(http): return nil for repeated BasicAuth cache misses
  • b2c17a6 fix(reverseproxy): simplify request docs and upstream scheme error log
  • e7a3234 docs(intern): clarify generic handle documentation
  • b573731 docs(num): clarify percentage precision and value count
  • 8803127 fix(server): validate startup and roll back partial server starts
  • c71a1e5 fix(strings): correct formatting, redaction, JSON encoding, and UUID generation
  • 62cfe86 fix(synk): stop intercepting interrupts in pprof reporter
  • 6042a0f fix(workerpool): serialize concurrent Wait calls and validate worker counts
  • 05a7cb0 fix(version): make older comparisons strict
  • bc3002d fix(testing): require lossless numeric equality conversions
  • 2815616 docs: add goutils agent skill and package guides
  • d5210f8 docs: expand package READMEs with usage and behavior guides
  • 82727b3 fix(ci): cover observed Go checksum propagation delays
  • 6d8914e fix(ci): allow Go publication services to observe release tags
  • aa4e3bd chore(release): prepare v0.8.0 modules
  • 3c23076 fix(release): reject permanently recorded Go module versions
  • b0ad3b1 chore(release): prepare v0.1.0 modules
  • 7260a77 ci: manage multi-module validation and releases with GitHub Actions
  • 743b861 refactor!: minimize root dependencies and decouple logging

webui

  • b79f285 fix(autocert): generate and refresh concrete provider forms
  • 62c54c3 docs(wiki): sync notification and deployment guidance
  • a88f7f9 feat(idlewatcher): add sleep/wake notification config (#20)
  • 8c80b73 docs(wiki): sync slice conversion semantics
  • ce8b6af docs(wiki): sync provider reload semantics
  • 12f944b Link header branding to GitHub and releases (#22)
  • 176f390 fix: search app aliases when display names are empty (#21)
  • de2392a chore(deps): update wiki submodule
  • bba79c8 docs(wiki): sync backend dependency migration examples
  • 4f366a2 chore(deps): refresh frontend dependencies and migrate openapi
  • 025e9cc docs(wiki): integrate HTTP-only deployment guidance
  • 9c0b122 fix(events): display names for removed pool entries
  • 913eee3 docs(wiki): sync integrated implementation guides
  • 1c6c013 docs(wiki): update environment contract
  • fbed24b docs(wiki): update goutils dependency documentation

Don't miss a new godoxy release

NewReleases is sending notifications on new releases.