Echo v5.4.0 and v4.16.0 are security releases that add API and change behavior. The docs site needs to reflect them. Full details are in the release notes and the linked advisories.
Pages are under site/src/content/docs/. The Spanish (es/) and Japanese (ja/) translations of each page need the same changes.
Proxy middleware
Testing
Other
References: v5.4.0 changelog, v4.16.0 changelog.
Echo v5.4.0 and v4.16.0 are security releases that add API and change behavior. The docs site needs to reflect them. Full details are in the release notes and the linked advisories.
Pages are under
site/src/content/docs/. The Spanish (es/) and Japanese (ja/) translations of each page need the same changes.Request scheme and proxies (GHSA-2ffq-g2xg-c22p)
guide/ip-address.mdor a new page next to it):Context.Scheme()now usesX-Forwarded-Proto(andX-Forwarded-Protocol,X-Forwarded-Ssl,X-Url-Scheme) only when the request comes directly from a loopback, link-local or private network address or a unix socket.Echo#SchemeExtractor(v5 alsoConfig.SchemeExtractor) withExtractSchemeFromHeaders(...TrustOption)(default),ExtractSchemeDirect()andLegacySchemeExtractor().X-Forwarded-Protois present only its last value is used, and the scheme is lowercase.X-Forwarded-Proto, not pass the client's value through.HTTPSRedirectloops and HSTS is not sent. Include aTrustIPRangeexample and name common cases:35.191.0.0/16,130.211.0.0/22)100.64.0.0/10networksmiddleware/redirect.md: HTTPS redirects depend onContext.Scheme(); link to the new section.middleware/secure.md: HSTS is sent whenContext.Scheme()ishttps(previously: TLS or a rawX-Forwarded-Proto: httpsheader).Client IP address (GHSA-99jh-6h7p-pp36, GHSA-246p-cpwv-v3jq)
guide/ip-address.md: v5 uses the direct peer address by default since v5.1.0 (LegacyIPExtractorfor the old behavior). v4 still trustsX-Forwarded-For/X-Real-IPwithoutEcho#IPExtractor, so v4 users should always set an extractor. Check the "default behavior" section, which describes the legacy default.Proxy middleware
middleware/proxy.mdandcookbook/reverse-proxy.md:X-Forwarded-Protois always set fromContext.Scheme().X-Forwarded-Ssl,X-Forwarded-ProtocolandX-Url-Schemeare removed before forwarding.X-Real-IPis always set fromContext.RealIP(). For chains such as nginx → Echo Proxy → upstream, configureEcho#IPExtractor.JSONP (GHSA-h9g5-28mm-hx3g)
cookbook/jsonp.mdandguide/response.md:ErrInvalidJSONPCallbackis returned.X-Content-Type-Options: nosniff.MethodOverride (GHSA-r7w9-592q-9vg4)
middleware/method-override.md:Echo#Pre.GET,HEAD,OPTIONS,TRACEorCONNECT.Static files (GHSA-375p-5qhx-8wq4, GHSA-3pmx-cf9f-34xr)
middleware/static.mdand theEcho.Static/Echo.StaticFSdocs:%2C,%40, lowercase hex) needEnablePathUnescaping..,..or empty segments (for example/assets//app.js) return 404; HTML5 mode still serves the index.EnablePathUnescaping/EnablePathUnescapingStaticFilescaveats: encoded slashes are decoded, so don't combine them with route-based access control.e.Use(middleware.Static(...))runs before route and group middleware, so route guards do not protect the files it serves. Keep protected files outside the root, or serve them withEcho.Staticbehind the guard.Trailing slash (GHSA-v753-g4cw-jm48)
middleware/trailing-slash.md: redirects percent-encode control characters in the path (a short note is enough).Testing
guide/testing.md:httptest.NewRequestusesRemoteAddr192.0.2.1:1234, which is not a trusted proxy address. Tests that setX-Forwarded-Protoshould setreq.RemoteAddr = "10.0.0.1:1234"or usee.SchemeExtractor = echo.LegacySchemeExtractor().Other
llms.txt/llms-full.txtif they describe any of the above (the echo repo copies have not been updated for v5.4.0).References: v5.4.0 changelog, v4.16.0 changelog.