Skip to content

docs: update for Echo v5.4.0 / v4.16.0 security release #449

Description

@vishr

Echo v5.4.0 and v4.16.0 are security releases that add API and change behavior. The docs site needs to reflect them. Full details are in the release notes and the linked advisories.

Pages are under site/src/content/docs/. The Spanish (es/) and Japanese (ja/) translations of each page need the same changes.

Request scheme and proxies (GHSA-2ffq-g2xg-c22p)

  • New section on the request scheme (in guide/ip-address.md or a new page next to it):
    • Context.Scheme() now uses X-Forwarded-Proto (and X-Forwarded-Protocol, X-Forwarded-Ssl, X-Url-Scheme) only when the request comes directly from a loopback, link-local or private network address or a unix socket.
    • New Echo#SchemeExtractor (v5 also Config.SchemeExtractor) with ExtractSchemeFromHeaders(...TrustOption) (default), ExtractSchemeDirect() and LegacySchemeExtractor().
    • When X-Forwarded-Proto is present only its last value is used, and the scheme is lowercase.
    • The trusted proxy must set (overwrite) X-Forwarded-Proto, not pass the client's value through.
  • Proxies on public addresses: document that they must be trusted explicitly, or HTTPSRedirect loops and HSTS is not sent. Include a TrustIPRange example and name common cases:
    • Cloudflare, CloudFront and Azure Front Door connecting to a public origin
    • GCP external HTTP(S) load balancer / GKE Ingress (35.191.0.0/16, 130.211.0.0/22)
    • 100.64.0.0/10 networks
  • middleware/redirect.md: HTTPS redirects depend on Context.Scheme(); link to the new section.
  • middleware/secure.md: HSTS is sent when Context.Scheme() is https (previously: TLS or a raw X-Forwarded-Proto: https header).

Client IP address (GHSA-99jh-6h7p-pp36, GHSA-246p-cpwv-v3jq)

  • guide/ip-address.md: v5 uses the direct peer address by default since v5.1.0 (LegacyIPExtractor for the old behavior). v4 still trusts X-Forwarded-For / X-Real-IP without Echo#IPExtractor, so v4 users should always set an extractor. Check the "default behavior" section, which describes the legacy default.

Proxy middleware

  • middleware/proxy.md and cookbook/reverse-proxy.md:
    • X-Forwarded-Proto is always set from Context.Scheme().
    • X-Forwarded-Ssl, X-Forwarded-Protocol and X-Url-Scheme are removed before forwarding.
    • In v5, X-Real-IP is always set from Context.RealIP(). For chains such as nginx → Echo Proxy → upstream, configure Echo#IPExtractor.

JSONP (GHSA-h9g5-28mm-hx3g)

  • cookbook/jsonp.md and guide/response.md:
    • The callback must be empty, a JavaScript identifier or a dot-separated path of identifiers. Otherwise a 400 error wrapping ErrInvalidJSONPCallback is returned.
    • Responses carry X-Content-Type-Options: nosniff.
    • Add a warning that any website can read JSONP responses with the user's cookies, so JSONP must not serve data that needs authentication (use JSON with CORS).

MethodOverride (GHSA-r7w9-592q-9vg4)

  • middleware/method-override.md:
    • Register with Echo#Pre.
    • A POST can no longer be overridden to GET, HEAD, OPTIONS, TRACE or CONNECT.

Static files (GHSA-375p-5qhx-8wq4, GHSA-3pmx-cf9f-34xr)

  • middleware/static.md and the Echo.Static / Echo.StaticFS docs:
    • With the defaults, files are resolved from the same form of the path that the router matched. File names sent with non-default escaping (for example %2C, %40, lowercase hex) need EnablePathUnescaping.
    • Paths with ., .. or empty segments (for example /assets//app.js) return 404; HTML5 mode still serves the index.
    • Document the EnablePathUnescaping / EnablePathUnescapingStaticFiles caveats: encoded slashes are decoded, so don't combine them with route-based access control.
    • Add a security note: e.Use(middleware.Static(...)) runs before route and group middleware, so route guards do not protect the files it serves. Keep protected files outside the root, or serve them with Echo.Static behind the guard.

Trailing slash (GHSA-v753-g4cw-jm48)

  • middleware/trailing-slash.md: redirects percent-encode control characters in the path (a short note is enough).

Testing

  • guide/testing.md: httptest.NewRequest uses RemoteAddr 192.0.2.1:1234, which is not a trusted proxy address. Tests that set X-Forwarded-Proto should set req.RemoteAddr = "10.0.0.1:1234" or use e.SchemeExtractor = echo.LegacySchemeExtractor().

Other

  • Update llms.txt / llms-full.txt if they describe any of the above (the echo repo copies have not been updated for v5.4.0).
  • Check that the version shown on the site is v5.4.0.

References: v5.4.0 changelog, v4.16.0 changelog.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions