You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardexpand all lines: docs/root/version_history/current.rst
+1-14
Original file line number
Diff line number
Diff line change
@@ -1,28 +1,15 @@
1
-
1.19.1 (Aug 24, 2021)
1
+
1.19.2 (Pending)
2
2
=====================
3
3
4
4
Incompatible Behavior Changes
5
5
-----------------------------
6
6
7
7
Minor Behavior Changes
8
8
----------------------
9
-
*Changes that may cause incompatibilities for some users, but should not for most*
10
-
11
-
* http: reject requests with #fragment in the URI path. The fragment is not allowed to be part of request
12
-
URI according to RFC3986 (3.5), RFC7230 (5.1) and RFC 7540 (8.1.2.3). Rejection of requests can be changed
13
-
to stripping the #fragment instead by setting the runtime guard ``envoy.reloadable_features.http_reject_path_with_fragment``
14
-
to false. This behavior can further be changed to the deprecated behavior of keeping the fragment by setting the runtime guard
15
-
``envoy.reloadable_features.http_strip_fragment_from_path_unsafe_if_disabled``. This runtime guard must only be set
16
-
to false when existing non-compliant traffic relies on #fragment in URI. When this option is enabled, Envoy request
17
-
authorization extensions may be bypassed. This override and its associated behavior will be decommissioned after the standard deprecation period.
18
-
* http: stop processing pending H/2 frames if connection transitioned to the closed state. This behavior can be temporarily reverted by setting the ``envoy.reloadable_features.skip_dispatching_frames_for_closed_connection`` to false.
19
9
20
10
Bug Fixes
21
11
---------
22
12
23
-
* ext_authz: fix the ext_authz filter to correctly merge multiple same headers using the ',' as separator in the check request to the external authorization service.
24
-
* http: limit use of deferred resets in the http2 codec to server-side connections. Use of deferred reset for client connections can result in incorrect behavior and performance problems.
*Changes that may cause incompatibilities for some users, but should not for most*
10
+
11
+
* http: reject requests with #fragment in the URI path. The fragment is not allowed to be part of request
12
+
URI according to RFC3986 (3.5), RFC7230 (5.1) and RFC 7540 (8.1.2.3). Rejection of requests can be changed
13
+
to stripping the #fragment instead by setting the runtime guard ``envoy.reloadable_features.http_reject_path_with_fragment``
14
+
to false. This behavior can further be changed to the deprecated behavior of keeping the fragment by setting the runtime guard
15
+
``envoy.reloadable_features.http_strip_fragment_from_path_unsafe_if_disabled``. This runtime guard must only be set
16
+
to false when existing non-compliant traffic relies on #fragment in URI. When this option is enabled, Envoy request
17
+
authorization extensions may be bypassed. This override and its associated behavior will be decommissioned after the standard deprecation period.
18
+
* http: stop processing pending H/2 frames if connection transitioned to the closed state. This behavior can be temporarily reverted by setting the ``envoy.reloadable_features.skip_dispatching_frames_for_closed_connection`` to false.
19
+
20
+
Bug Fixes
21
+
---------
22
+
23
+
* ext_authz: fix the ext_authz filter to correctly merge multiple same headers using the ',' as separator in the check request to the external authorization service.
24
+
* http: limit use of deferred resets in the http2 codec to server-side connections. Use of deferred reset for client connections can result in incorrect behavior and performance problems.
0 commit comments