v3.0.0-beta.1 #723
Pinned
joseluisq
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
We are excited to announce our first
v3.0.0-beta.1release for the upcoming majorv3.0.0which is a significant milestone in the evolution of SWS, bringing new features, performance improvements, security hardening, among other enhancements.The release upgrades the HTTP stack to the latest Hyper v1, introduces new features like weak ETag validation, structured JSON logging and file logging, stabilizes the in-memory cache, provides FIPS-capable TLS binary support, and delivers significant performance and security hardening across all modules. Also, SWS defaults are now more secure out of the box.
Feel free to test this beta release. More betas will follow toward the major
v3.0.0. Please report any issues or suggestions on the GitHub Issues.Your feedback and contributions are appreciated.
Visit our updated website at static-web-server.net for more information, documentation, and examples. Also the v2 to v3 migration guide.
Breaking Changes
httpv1 andhttp-body-utilcrates. Response body handling and server connection wiring have been updated accordingly. (#647)--http2,--http2-tls-certand--http2-tls-keywith--tls,--tls-cert,--tls-keyand a standalone--http2flag. SWS now supports HTTP/1, HTTP/1+TLS and HTTP/2+TLS server modes. (#650)80to8787(unprivileged).--compression-staticand--security-headersare now enabled by default.Cache-Controldefaults tono-cachefor HTML/JSON and applies 1-yearmax-ageonly to immutable static assets. NewReferrer-Policy: strict-origin-when-cross-originsecurity header. (#660)--disable-symlinksand--ignore-hidden-files. are replaced with--follow-symlinksand--include-hiddenrespectively, both defaulting tofalse(disabled). (#671)8787. (#720)New Features
X-Cacheheader on cache hits. Byte-range requests are excluded from caching. (#665)--etagoption. Enables browser and CDN revalidation withIf-None-Match/If-Match/If-Rangesupport per RFC 7232. Returns304 Not Modifiedfor unchanged resources. Integrates with cache-control headers and the in-memory cache. (#679)--log-formatoption. Logs are now emitted as single-line JSON by default (--log-format json). A--log-format prettymode is available for human-readable development output. (#680)--log-fileoption. Streams log records to a file on disk in addition to stderr. Uses a non-blocking background writer thread so the request path is never blocked by disk I/O. (#682)--compression-staticfeature no longer depends on the dynamic compression feature flag and can be used standalone. (#662)200bytes bypass dynamic compression, avoiding CPU overhead on tiny payloads. (#661)--unix-socket,--unix-socket-modeand--unix-socket-forcerespectively (Unix domain sockets support #681)v3. (#658)--use-relative-rootoption. To instruct SWS to skip the canonicalization of the webroot (--root) at startup time and instead, to resolve the webroot at request time (e.g. symlink webroot). (#717)CONTRIBUTORS.mdfile has been updated to include a new section for AI-assisted coding contributions. (#708)Performance
HeaderValueconstants instead of per-response construction, cached CORS validation results, and optimizedAccept-Encodingquality-value parsing. (#652)Bug Fixes
QSA(Query String Append) fashion. Query strings on the client request are no longer silently discarded during redirect processing. (#709)/metricsendpoint when both features are enabled. (#718)Security & Hardening
Refactoring
server.rsinto sub-modules (http1,http1_tls,http2,redirect,listener,opts) for better maintainability. (#649)Testing
CODE_OF_CONDUCT.md,CODE_STYLE.md,COMMITS.md,PULL_REQUESTS.md) from the repository root into thedocs/directory. (#707)Documentation
This discussion was created from the release v3.0.0-beta.1.
All reactions