Release/v1.61.0 - #4246
Release/v1.61.0#4246
Conversation
chore(metrics): pin gcp exporter to gofr.dev v1.60.1
…ption (#4099) * fix(middleware): require a path separator in the well-known auth exemption * test(middleware): cover the rate limiter well-known exemption * chore(middleware): satisfy goconst and noctx in the well-known check * docs(auth): describe the separator requirement in the well-known exemption --------- Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com> Co-authored-by: Umang Mundhra <mundhraumang.02@gmail.com>
Co-authored-by: aryanmehrotra <aryanmehrotra2000@gmail.com>
… global metrics accessor (#3856)
…urrent recovery test (#3755)
…pdate (#4153) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com>
Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com> Co-authored-by: Umang Mundhra <mundhraumang.02@gmail.com>
Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com>
…4196) Applied surgically per direct-dependency module (per-module go get + go mod tidy; no go work sync). All bumps are minor/patch/security — no majors, no go-redis mock regen needed (miniredis is a test double, not go-redis). Updates: - go.opentelemetry.io/otel/sdk 1.45.0 -> 1.46.0 (root, metrics/exporters/gcp, pubsub/nats, pubsub/sqs) - go.opentelemetry.io/otel/exporters/zipkin 1.44.0 -> 1.46.0 (root) - go.opentelemetry.io/contrib/detectors/gcp 1.44.0 -> 1.46.0 (metrics/exporters/gcp) - github.com/aws/aws-sdk-go-v2/config 1.32.37 -> 1.33.3 (file/s3, kv-store/dynamodb, pubsub/sqs, examples/using-s3-filestore) - github.com/aws/aws-sdk-go-v2/service/dynamodb 1.63.3 -> 1.67.0 (kv-store/dynamodb) - github.com/aws/aws-sdk-go-v2/service/sqs 1.46.6 -> 1.51.0 (pubsub/sqs) - github.com/nats-io/nats-server/v2 2.14.5 -> 2.14.6 (pubsub/nats) - golang.org/x/sync 0.22.0 -> 0.23.0 (root) - modernc.org/sqlite 1.56.0 -> 1.58.0 (root) - github.com/alicebob/miniredis/v2 2.38.0 -> 2.39.0 (root, test) - google.golang.org/grpc 1.83.1 -> 1.83.2 security (root + library modules + examples; pulls golang.org/x/net 0.57.0 -> 0.58.0). examples/using-gcp-metrics is excluded: it is baseline-untidy (excluded from the CI tidy gate) and tidying it to apply grpc would settle unrelated versions. Closes: #4172, #4173, #4174, #4175, #4176, #4177, #4178, #4179, #4180, #4181, #4182, #4183, #4184, #4185, #4186, #4187, #4188, #4189, #4190, #4191, #4192, #4194 Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com>
Co-authored-by: Umang Mundhra <mundhraumang.02@gmail.com> Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com>
…uisite (#3461) The broken Auth Middleware link this PR also carried has since landed via #3798, so what remains is: - "Custom Middleware" was plain text next to the linked Auth Middleware; it now points at docs/advanced-guide/middlewares. - The prerequisite said Go 1.24. Every go.mod in the repo declares go 1.26.0, and CI's 1.24/1.25 matrix entries only pass because a setup-go-toolchain step auto-upgrades them, so 1.26 is the real floor. Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com> Co-authored-by: Umang Mundhra <mundhraumang.02@gmail.com>
…3227) Co-authored-by: Umang Mundhra <mundhraumang.02@gmail.com> Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com>
…tech (#4199) Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com>
… public (#4208) quay.io/minio/minio:RELEASE.2025-09-07T16-13-09Z carries the identical manifest list — sha256:14cea493… , byte-for-byte the digest already pinned — so this changes the registry and nothing else. The image CI runs is provably the one it ran on 2026-09-11, and the digest pin protecting the integration guard for #3804 stays intact. Bumping to a newer release instead would have changed two things at once.
…sts entirely (#4201) Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com>
Since #4205 a scheme-bearing TRACER_URL is a real URL, so it can carry credentials in userinfo or its query string, and every tracer startup log wrote it verbatim. Endpoints are now logged through redactURL, the exporter name is logged as the matched constant, and the raw TRACER_INSECURE and unsupported TRACE_EXPORTER values are no longer echoed. This clears CodeQL go/clear-text-logging alerts 179-184 on pkg/gofr/otel.go, which failed the CodeQL check on the v1.61.0 release PR (#4246).
# Conflicts: # pkg/gofr/metrics/exporters/gcp/go.mod # pkg/gofr/metrics/exporters/gcp/go.sum # pkg/gofr/version/version.go
|
The 3 CodeQL The merge conflicts with |
Co-authored-by: Umang Mundhra <mundhraumang.02@gmail.com>
|
Updated with
Both are now in the release notes under Fixes, with entries under Upgrade Notes. Verified on the merged head: |
f515de0 to
8fc0ab1
Compare
Release v1.61.0
🚀 Features
🔹 HTTP
QUERYMethod (RFC 10008)QUERYis a safe, idempotent method that puts the query in the request body. It avoids GET's URL-length limit and query strings leaking into logs, without losing safety the way POST does. GoFr now supports it for incoming routes and on the service client:As RFC 10008 requires, a
QUERYrequest with noContent-Typegets400, and one GoFr cannot decode gets415, before your handler runs. The415is the new typedErrorUnsupportedMediaType. Unknown paths still return404. On the client,QUERYgets circuit-breaker and retry handling like GET. The circuit breaker now returns an error for an unrecognised method; before, it quietly returned anilresponse.🔹 Readiness Checks for
/.well-known/health/.well-known/healthalways answered200, so a Kubernetes readiness probe on it sent traffic to a pod whose dependencies weren't reachable yet.AddReadinessCheckmakes the endpoint answer503until your check passes:You can register several checks. They run in the order you added them, and the first failure decides.
FrameworkReadiness(ctx)returns GoFr's own result, so a replace-mode check can still use it. The error is logged, never written to the response, whose body is justDOWN. With no check registered, the endpoint behaves exactly as before.🔹 Configurable Metric Cardinality Limit
METRICS_CARDINALITY_LIMITsets how many attribute sets each OpenTelemetry instrument keeps. Once an instrument passes the limit, extra series are merged into oneotel.metric.overflowseries, so a label explosion can't overwhelm your backend.OTEL_GO_X_CARDINALITY_LIMIT) — unchanged> 0OTEL_GO_X_CARDINALITY_LIMIT0or negative🔹 Circuit Breaker Open Counter
app_circuit_open_count{service}goes up once each time a circuit actually goes from closed to open. It does not count every failing request that sees the trip, so a burst of concurrent failures still adds exactly one.🔹 Azure Event Hub Health Check
Health()for Event Hub was a stub that returned an empty status.Container.Healthdidn't count an empty status asDOWN, so an app that couldn't reach its Event Hub reportedUP. It now makes a real connectivity check, limited to 2s, and reportsUP/DOWNwithbackend,eventHubandpartitionCount. The 2s limit is enforced by GoFr itself, becauseazeventhubsignores the caller's deadline on this call.🔧 Enhancements
🔹 Concurrent Health Checks
Container.Healthused to check each dependency one after another, so the endpoint took as long as all the checks added together. The checks now run in parallel, and callers that arrive at the same time share one set of results:/healthprobe(MySQL, Redis and four HTTP dependencies, each taking 400 ms to answer.)
A panicking check reports its dependency as
DOWNinstead of crashing the process. Two new settings are both off by default:HEALTH_CACHE_TTL5s,1m) before checking again.HEALTH_CHECK_TIMEOUT2s). Dependencies that haven't answered are left out, the status isDEGRADED, and the partial result is never cached.🔹 MQTT Tracing Semantics
MQTT publish and subscribe spans now set
SpanKindand themessaging.*attributes, as Kafka, NATS, SQS and Google Pub/Sub already do. The consume span used to start oncontext.Background()and ended up in a separate trace. It now sits inside the trace of the request that consumed the message. MQTT 3.1.1 has nowhere to carrytraceparent, so there is still no link across the broker. With tracing off, publish allocates exactly what it did before.To match the other providers, MQTT's
app_pubsub_subscribe_total_countnow countsSubscribecalls, so it lines up with the success counter. It used to count messages arriving.⚡ Performance
Fewer allocations on every request. Output is byte-identical in each case.
(route, method, status)and reused. The cache is keyed on the route template and only admits templated routes, so unique unmatched paths can't fill it up.Content-Typevalue is built once.🛠️ Fixes
RBAC Wildcard Rules Ignored — Rules with
"methods": ["*"], or with nomethods, never matched, so the routes they protected let every request through. They are now enforced.Auth Exemption Matched Too Broadly — Paths that merely started with
/.well-known, such as/.well-knownprivate, skipped auth and rate limiting. The exemption now requires/.well-known/.Tracer Credentials in Logs — Credentials in
TRACER_URLwere printed in startup logs. They are now logged asREDACTED.TRACER_URLWith a Scheme Exported Nothing —http://andhttps://endpoints were not valid gRPC targets. They now work, andTRACER_INSECUREcontrolshost:portendpoints.Scanner Traffic Hid Real Routes in Metrics — Random unmatched URLs filled the metrics series limit. They now collapse into
__unmatched__, so real routes keep their series.SIGTERMDuring Startup Was Lost — A signal that arrived before the server started left it running untilSIGKILL. The server now stops.WebSocket Route Panic — A plain HTTP request to a WebSocket route panicked. It now returns an error.
Auto-CRUD Panics and Mangled Names —
uint,boolandtime.Timefields panicked, and digits were corrupted in table and column names. Both are fixed.SQL Log Duration Unit — SQL query logs now report microseconds, like every other datasource.
SFTP/S3 Observability — Failed SFTP opens were logged as
SUCCESS, and some operations used the wrong names. Status and labels are now correct.Kafka and Google Pub/Sub Panics — Closing a Kafka client, or subscribing to several Google Pub/Sub topics, could crash with concurrent map access. Both are now synchronized.
Dgraph Migrations — Migrations now run inside a transaction.
Full Changelog: v1.60.1...v1.61.0