Skip to content
CAI
Software that uses CAICheck a score

gofiber/fiber

72.9

Strong · 24 September 2026

40.3k

lines of production code

Go

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the Fiber v3 web framework, a high-performance HTTP server built on fasthttp that provides a comprehensive suite of middleware for routing, security, and data handling. It features a unified request binding system, an advanced HTTP client, and robust internal utilities for logging, storage, and context management. The codebase emphasizes security through hardened middleware implementations, strict RFC compliance, and protections against common web vulnerabilities like SSRF and open redirects.

How it got here

2019–2020 — Fiber v3 middleware overhaul

21 changes.

This period focused on the comprehensive rewrite of nearly all middleware for the Fiber v3 release, introducing stricter security hardening, RFC compliance, and modern configuration patterns. The work also included updating core dependencies to Go 1.26 and adding new features such as a net/http adaptor, timeout handling, and internal storage implementations.

2021–2024 — Fiber v3 feature expansion and stabilization

16 changes.

This period focused on expanding the Fiber v3 ecosystem with a comprehensive suite of new middlewares, including security, routing, and utility handlers, alongside a unified request binding system. It also introduced advanced features such as a high-level HTTP client, configurable contextual logging, and robust retry mechanisms to enhance application resilience and developer experience.

2025–2026 — security hardening and performance optimization

24 changes.

This period focused on strengthening the framework's security posture by introducing robust middleware for host authorization, Server-Sent Events, and pagination, while simultaneously hardening internal components against injection and redirect attacks. Significant effort was dedicated to performance optimization, particularly in hot-path operations like context local storage, configuration reading, and origin validation, to reduce memory allocations and latency. The work also involved consolidating disparate internal utilities for header parsing, logging, and error handling into shared, standardized packages to ensure consistency and correctness.

Features

Add ETag middleware for HTTP caching

The new ETag middleware automatically generates strong or weak ETags for successful (200 OK) responses, enabling client-side caching via standard If-None-Match headers. It supports a configurable Weak mode, skips ETag generation for non-200 status codes, empty bodies, or existing ETags, and specifically excludes Server-Sent Events (SSE) streams to prevent buffering. The middleware also handles RFC 9110 compliant If-None-Match evaluation and prevents overflow issues on 32-bit platforms.

middleware/etag · high confidence

Add Early Data middleware with TrustProxy support

Introduces a new middleware for handling HTTP Early Data (RFC 8470) in the \middleware/earlydata\ package. The middleware checks for the \Early-Data\ header and allows requests only if the proxy is trusted (via \c.IsProxyTrusted()\) and the HTTP method is safe by default. It exposes an \IsEarly\ helper to let downstream handlers detect accepted early-data requests and stores this state using context locals. The implementation includes a configurable \Config\ struct with defaults for header names, validation logic, and error responses (defaulting to \fiber.ErrTooEarly\).

middleware/earlydata · high confidence

Add EnvVar middleware to expose specific environment variables

Introduces a new EnvVar middleware that allows applications to explicitly whitelist and expose specific environment variables as a JSON response. Users can configure the \ExportVars\ map to define which variables to include; the middleware retrieves the current value of each variable (or uses a provided default if the environment variable is not set) and returns them under a \vars\ key. It strictly supports GET and HEAD requests, returning a 405 Method Not Allowed with the appropriate Allow header for other methods, and ensures no variables are exposed if the configuration is empty to prevent accidental information disclosure.

middleware/envvar · high confidence

Add Retry addon with exponential backoff and jitter

The new Retry addon provides an exponential backoff mechanism with jitter for retrying unsuccessful network operations in Fiber applications. Users can configure parameters such as initial interval, maximum backoff time, multiplier, and maximum retry count via the \Config\ struct. The implementation ensures that no sleep occurs after the final failed attempt, optimizing latency for operations that ultimately fail. This addon is designed to be shared across concurrent callers, maintaining its own backoff state per retry invocation.

addon · high confidence

Add Server-Sent Events (SSE) middleware

Introduces a new SSE middleware for Fiber that allows applications to push real-time events to clients. The middleware handles the SSE transport layer, including setting correct response headers (Content-Type: text/event-stream), managing stream lifecycle, and detecting client disconnects via flush errors. It supports configurable heartbeats to keep idle connections alive, automatic retry intervals, and a \Handler\ function for writing events. The \Stream\ API provides methods to send data (with automatic JSON encoding for non-string types), custom event names, IDs, and comments, while ensuring thread-safety and preventing field injection by sanitizing input.

middleware/sse · high confidence

Add Skip middleware for conditional handler execution

A new Skip middleware is introduced that allows developers to conditionally bypass a specific handler in the middleware chain. By providing a predicate function, requests matching the condition will skip the wrapped handler and proceed to the next one, while non-matching requests will execute the handler. This enables more flexible request routing logic without requiring complex conditional checks inside individual handlers.

middleware/skip · high confidence

Add expvar middleware for Go runtime metrics

Introduces a new expvar middleware that exposes Go runtime statistics (such as cmdline and memstat) via the /debug/vars endpoint. The middleware handles path matching to ensure sibling routes like /debug/varsdump are not intercepted, and supports a Next function to conditionally skip the middleware.

middleware/expvar · high confidence

Add internal context value retrieval utility

A new internal package \internal/contextvalue\ has been added, providing a generic \Value\ function that retrieves values from various supported context types (including \\*fasthttp.RequestCtx\, \context.Context\, and Fiber-specific contexts). This utility standardizes how context values are accessed across the application, prioritizing standard \Value\-style lookups over Fiber-specific \Locals\ or \UserValue\ methods when multiple accessors are available.

internal/contextvalue · high confidence

Add pagination middleware with offset and cursor support

The new \middleware/paginate\ package provides a Fiber middleware that handles both offset-based and cursor-based pagination. It parses query parameters for page, limit, offset, and sort fields, enforcing configurable maximum limits and allowing users to restrict allowed sort fields via an \AllowedSorts\ whitelist. The middleware stores a \PageInfo\ object in the request context, which includes helper methods for generating next/previous page URLs and managing cursor data, while also protecting against integer overflows in start-index calculations.

middleware/paginate · high confidence

Add response time middleware

A new middleware has been added to the Fiber framework that measures and reports the duration of request processing. By default, it sets the 'X-Response-Time' header on the response with the elapsed time. The middleware supports configuration to skip execution via a custom 'Next' function and allows specifying a custom header key, ensuring that response timing information is available to clients while preserving error propagation behavior.

middleware/responsetime · high confidence

Add utility to detect typed-nil errors

A new internal utility function, IsNil, has been added to the nilerror package. This function allows callers to correctly identify when an error interface holds a nil value of a concrete type (a 'typed-nil'), which standard Go equality checks (err == nil) fail to catch. This improves error handling robustness for code that needs to distinguish between a truly nil error and one that is nil but has a non-nil type.

internal/nilerror · high confidence

Added IDNA hostname folding utility for proxy matching

A new \idnafold\ package has been introduced to convert Unicode hostnames into their Punycode representation, ensuring that literal hostnames in configuration match the actual requests sent by browsers. The \ToASCII\ function handles non-ASCII labels by converting them to ASCII (e.g., \münchen.example.com\ to \xn--mnchen-3ya.example.com\), while leaving pure ASCII, already-Punycode, or host:port strings unchanged. Invalid inputs that fail strict IDNA validation are returned as-is to prevent false matches, and the implementation includes comprehensive unit tests and benchmarks.

internal/idnafold · high confidence

Added internal helpers for log template testing and sensitive data redaction

This change introduces two new internal packages to support logging infrastructure. The \internal/loggertest\ package provides a \CaptureContextLog\ helper that consolidates boilerplate for redirecting Fiber's default logger output and configuring context templates during integration tests, ensuring consistent setup and cleanup. The \internal/redact\ package adds a \Prefix\ function to mask sensitive values in log output by keeping a configurable leading prefix (default 4 bytes) for inputs of sufficient length (default 8 bytes) and replacing the rest with a mask, with tests verifying the redaction logic for various input lengths.

internal/loggertest, internal/redact · high confidence

Fiber v3 Helmet middleware adds comprehensive security headers and HSTS validation

The \middleware/helmet\ package has been introduced for Fiber v3, providing a security middleware that sets standard HTTP headers including XSS Protection, Content-Type Options, Frame Options, Referrer Policy, and several Cross-Origin policies (Embedder, Opener, Resource). It also supports Content-Security-Policy (with report-only mode) and Permissions-Policy. A key behavioral addition is strict validation for HSTS configuration: the middleware now panics if \HSTSMaxAge\ is negative or if \HSTSPreloadEnabled\ is set while \HSTSExcludeSubdomains\ is true, ensuring safe HSTS header generation.

middleware/helmet · high confidence

Internal memory storage implementation with context support and configurable GC

The internal storage package now includes a dedicated memory implementation (internal/storage/memory) that provides an in-memory store for testing and internal use. This implementation supports context-aware operations (GetWithContext, SetWithContext, etc.) allowing cancellation checks, and introduces a configurable garbage collection interval (defaulting to 10 seconds) to manage expired entries. It also ensures thread safety by copying keys and values during storage to prevent data races from pooled buffers, and rounds expiration durations up to whole seconds.

internal/storage · high confidence

Introduce Adaptor middleware to bridge net/http and Fiber handlers

The new \middleware/adaptor\ package enables running standard \net/http\ handlers within the Fiber framework. It implements a high-performance bridge that converts Fiber's \fasthttp\ request context to \net/http\ types and back, utilizing pooled buffers and optimized header copying to minimize allocations. The implementation includes specific optimizations for TLS connections, remote address handling, and body streaming, along with comprehensive test coverage for flushing, context propagation, and edge cases.

middleware/adaptor · high confidence

Introduce Fiber v3 Binder as a unified request binding system

Fiber v3 introduces the Binder, a new request/response binding feature that replaces the legacy parsers (BodyParser, ParamsParser, QueryParser, etc.) with a unified, extensible system. This change brings a consistent API for binding data into structs and maps, adds support for CBOR and MsgPack formats, and enables custom binder registration. The new implementation improves performance through pooled data maps and decoder caches, while also fixing several parsing edge cases such as unmatched brackets and case-insensitive content-type handling.

binder · high confidence

Introduce Idempotency Middleware

Adds a new idempotency middleware that caches HTTP responses keyed by the X-Idempotency-Key header, ensuring that repeated requests with the same key return the original response without re-executing the handler. The middleware includes a configurable lifetime (default 30 minutes), an in-memory locking mechanism to prevent race conditions, and support for custom storage and lock implementations. It also provides helper functions to determine if a response was served from the cache or stored during the current request.

middleware/idempotency · high confidence

Introduce configurable contextual logging with middleware-aware tags

The log package now supports contextual log fields that can be customized via format strings and custom tag renderers. Users can configure the default logger's context prefix using SetContextTemplate, which accepts a format string (e.g., "\[${request-id}\] ${username}") and a map of custom tag functions. Built-in tags for request ID, username, API key, CSRF token, and session ID are pre-registered to align with Fiber's standard middlewares, and the reserved ${value:KEY} tag allows reading arbitrary values from the context object. The system also includes safety features such as sanitizing control characters in log output to prevent log injection, handling typed-nil contexts gracefully, and ensuring that template rendering errors are visible in the log line rather than silently dropped. This change provides a structured way to enrich logs with request-scoped data without hardcoding field names.

log · high confidence

Introduce configurable timeout middleware with context propagation and leak prevention

Adds a new timeout middleware that enforces a configurable duration on incoming requests. The middleware wraps handlers in a goroutine and uses a timeout context, allowing handlers to detect cancellation via c.Context().Done() and return early. When a timeout occurs, it immediately returns a 408 Request Timeout (or a custom response via the new OnTimeout config option) and prevents context leaks by scheduling the race-free reclamation of the fiber.Ctx from the pool once the handler goroutine finishes. It also supports treating specific custom errors as timeouts and ensures that buffered response bodies from timed-out handlers are not leaked to the client.

middleware/timeout · high confidence

Introduce high-performance in-memory storage with defensive copying and safe TTL handling

A new internal in-memory storage implementation is added to provide a high-performance, type-safe cache for internal middleware use. The storage ensures thread safety and prevents data corruption by defensively copying string keys and byte-slice values on both set and get operations. It also introduces robust TTL handling that rounds durations up to the nearest second and saturates absolute expiries to prevent integer overflow issues, alongside a background garbage collection loop to automatically remove expired entries.

internal/memory · high confidence

Introduce new Fiber HTTP client with advanced features

The client package now provides a new, high-level HTTP client built on fasthttp, offering a chainable API for GET, POST, PUT, DELETE, and other methods. This client supports automatic JSON and XML marshaling/unmarshaling, CBOR encoding, and streaming response bodies. It includes a configurable cookie jar that adheres to RFC 6265, path parameter substitution with safe escaping, and a hook system for request and response interception. The client can be instantiated directly or wrapped around existing fasthttp.Client, HostClient, or LBClient instances, allowing for shared connection pools and TLS settings across Fiber and lower-level integrations.

client · high confidence

Introduce new static file serving middleware

A new static middleware has been added to serve files from a file system (fs.FS). It supports configuration for index files, caching (MaxAge, CacheDuration), compression, byte range requests, directory browsing, and direct downloads. The implementation includes robust path sanitization to prevent traversal attacks and handles various edge cases in path normalization.

middleware/static · high confidence

Introduce ordered redirect rules and fix open-redirect vulnerabilities

The redirect middleware now supports an ordered \RuleList\ configuration, allowing developers to define redirects as a slice of \Rule\ structs where the first matching rule wins, replacing the previous unordered \Rules\ map which relied on a heuristic to determine priority. This change ensures predictable redirect behavior and prevents shadowed rules from being silently ignored. Additionally, the middleware now strictly anchors patterns to the start of the path and validates target URLs to prevent open-redirect attacks, ensuring that captures cannot inject malicious authorities into the redirect location.

middleware/redirect · high confidence

New extractors package for shared value extraction

The new \extractors\ package provides shared utilities for Fiber middleware to extract string values from HTTP headers, cookies, query parameters, form data, and URL path parameters. It introduces a source-aware \Resolve\ function that returns not only the extracted value but also provenance metadata (the specific key and source type), enabling middleware to enforce security policies such as CSRF protection and authentication source validation. The package includes a \Chain\ function for fallback extraction logic, cycle detection to prevent recursive loops, and comprehensive benchmarking and fuzz testing to ensure performance and correctness.

extractors · high confidence

New header lookup API for case-insensitive and multi-value header handling

The \internal/headerlookup\ package introduces \Value\ and \Combined\ functions to safely read HTTP request headers, addressing limitations in the underlying byte-exact API. \Value\ retrieves single-value headers (like Authorization) with case-insensitive matching; it refuses to return a value if the header appears multiple times, treating such messages as malformed to prevent security issues where a later line might hide an earlier one. \Combined\ handles multi-value headers (like Accept) by joining repeated lines with a comma, while correctly preserving the semicolon separator for Cookie headers. The implementation supports both normalized and non-normalized header stores (relevant for HTTP/2 and HTTP/3) and ensures memory safety by returning copies when the \Immutable\ config option is enabled.

internal/headerlookup · high confidence

New host authorization middleware for Fiber v3

Added a new \hostauthorization\ middleware that restricts incoming requests to a configured list of allowed hosts. The middleware supports exact host matching and wildcard subdomains (e.g., \\*.example.com\), normalizes host headers by stripping ports and trailing dots, and converts Internationalized Domain Names (IDN) to Punycode. It enforces RFC 1035 length limits and rejects malformed host authorities, returning a 403 Forbidden status for unauthorized requests. Configuration allows for static allowed hosts, a dynamic validation function, and a custom error handler.

middleware/hostauthorization · high confidence

New internal TLS test helper for mutual authentication

The internal/tlstest package now provides a GetTLSConfigs function that generates paired server and client TLS configurations for testing. It creates an in-memory certificate authority and a server certificate signed by that CA, returning ready-to-use \*tls.Config objects that enforce TLS 1.2 or higher and trust each other, simplifying the setup of secure test environments.

internal/tlstest · high confidence

Security

Cache middleware rewritten with security hardening and RFC 9111 compliance

The cache middleware has been completely rewritten to address security vulnerabilities and improve standards compliance. It now includes protection against Denial of Service attacks by bounding query parameter counts (128 max) and buffer sizes (4KB max), hashing long path segments, and limiting Vary header partitions (32 max) to prevent cache explosion. Key generation has been hardened to escape delimiters and normalize method names, preventing delimiter injection. The middleware now strictly adheres to RFC 9111 for Cache-Control header parsing, including proper handling of quoted strings and directives. Additionally, it introduces a new cache key versioning system (v2) to ensure cache entries from previous versions are not misinterpreted, and adds support for the HTTP QUERY method with body-based key partitioning.

middleware/cache · high confidence

Proxy middleware hardened against SSRF, redirect downgrades, and hop-by-hop smuggling

The proxy middleware now enforces a strict security policy by default: it blocks upstream targets that resolve to private, loopback, or link-local IP addresses (preventing SSRF and DNS rebinding attacks), restricts allowed schemes to HTTP and HTTPS, blocks HTTPS-to-HTTP redirect downgrades, and strips RFC 7230 hop-by-hop headers to prevent request smuggling. These protections are applied via a configurable \SecurityPolicy\ struct and are installed at both construction time (for \Balancer\) and dial time (for \Do\, \Forward\, and other runtime helpers) to ensure DNS-rebinding cannot bypass initial validation. The middleware also introduces \MaxResponseBodySize\ to limit memory usage from large upstream responses and adds \DialDualStack\ and \KeepConnectionHeader\ configuration options.

middleware/proxy · high confidence

Behavioural changes

BasicAuth middleware rewritten for v3 with hashed password support and hardened validation

The BasicAuth middleware has been completely rewritten for Fiber v3, introducing support for hashed passwords (SHA-256, SHA-512, and bcrypt) in the Users map, which are verified using constant-time comparisons to prevent timing attacks. The implementation now enforces stricter RFC 7617 compliance by validating header characters, rejecting invalid UTF-8, normalizing input to NFC, and limiting header size via a new HeaderLimit config option. It also registers a ${username} log context tag for audit logging and uses high-performance SWAR-based scanning for credential checks.

middleware/basicauth · high confidence

CORS middleware rewritten for v3 with stricter origin validation and new configuration options

The CORS middleware has been refactored for v3, introducing a new \Config\ struct that replaces positional arguments with named fields. Key behavioral changes include the addition of \AllowOriginsFunc\ for dynamic origin evaluation, \AllowPrivateNetwork\ to support the Access-Control-Allow-Private-Network header, and \DisableValueRedaction\ to control logging privacy. The middleware now strictly validates origins, rejecting those with userinfo, paths, or queries, and correctly handles the literal "null" origin string as per the CORS specification. It also preserves the original case of the Origin header in responses and includes the HTTP QUERY method in the default allowed methods list.

middleware/cors · high confidence

CSRF middleware restructured with enhanced security validation and extractor support

The CSRF middleware has been restructured to improve security and configuration flexibility. It now includes built-in validation that panics if a custom extractor is configured to read from the same cookie used for token storage, preventing accidental CSRF protection bypass. The middleware supports the new extractor pattern, allowing tokens to be retrieved from headers, forms, queries, or parameters via the \Extractor\ config option. Additionally, it introduces \TrustedOrigins\ for flexible subdomain matching, \SingleUseToken\ for rotating tokens on each request, and \DisableValueRedaction\ to control whether tokens are masked in logs. The default key generator has been updated to use \utils.SecureToken\.

middleware/csrf · high confidence

Centralized path parameter delimiter grammar

A new internal package, internal/paramdelim, has been introduced to define the set of characters that terminate a ':name' placeholder in URL paths. This change ensures that both the route parser and the HTTP client use the same grammar for delimiters (specifically '/', '-', '.', ':', '\\', and '?'), preventing them from drifting out of sync. The implementation includes a test to verify that the returned delimiter set is immutable and does not include client-only terminators like '\#'.

internal/paramdelim · high confidence

Compress middleware rewritten for Fiber v3 with zstd support and RFC-compliant encoding negotiation

The compress middleware has been completely rewritten for Fiber v3, introducing support for the zstd compression algorithm alongside existing gzip, deflate, and brotli options. The implementation now adheres to RFC 9110 standards for Accept-Encoding negotiation, correctly handling quality weights, wildcards, and header lists. It also includes improved handling of streaming responses to avoid materialization, proper ETag management for encoded bodies, and configurable compression levels (Default, BestSpeed, BestCompression, Disabled).

middleware/compress · high confidence

Consolidate CORS and CSRF origin validation into a shared internal package

The duplicate origin-matching logic previously scattered across the CORS and CSRF middleware has been extracted into a new \internal/origin\ package. This change ensures consistent validation behavior for both security mechanisms, specifically enforcing that CSRF only accepts \http\ and \https\ schemes while CORS remains scheme-agnostic, and standardizing how wildcard subdomains and raw origin headers are normalized and matched.

internal/origin · high confidence

EncryptCookie middleware reinitialized for Fiber v3 with stricter key validation and error handling

The EncryptCookie middleware has been reinitialized for Fiber v3, introducing stricter configuration validation and improved error resilience. The middleware now enforces that the encryption key is a valid base64 string with a decoded length of exactly 16, 24, or 32 bytes, panicking at startup if these constraints are not met. During operation, it handles decryption failures by deleting invalid request cookies rather than passing them through, and ensures that response encryption errors are joined with downstream errors to prevent masking failures. The implementation also updates internal utilities to use \slices.Contains\ for exception checks and relies on \cipher.NewGCMWithRandomNonce\ for AES-GCM encryption.

middleware/encryptcookie · high confidence

Favicon middleware rewritten for Fiber v3 with new configuration options

The favicon middleware has been completely rewritten for Fiber v3, introducing a new \Config\ struct that allows users to specify a custom \FileSystem\ (supporting embedded or network filesystems via \io/fs\), set a custom \Cache-Control\ header value, provide raw favicon \Data\ directly, and enforce a \MaxBytes\ limit on the cached asset size. The middleware now defaults to serving from \/favicon.ico\, supports GET, HEAD, and OPTIONS methods, and returns 204 No Content when no favicon source is configured.

middleware/favicon · high confidence

Healthcheck middleware v3 with startup probe and multi-format responses

The healthcheck middleware has been migrated to v3, introducing a new StartupEndpoint (/startupz) alongside the existing liveness (/livez) and readiness (/readyz) paths to support Kubernetes startup probes. The middleware now supports configurable response formats including JSON, XML, MsgPack, and CBOR (defaulting to plain text), and ensures HEAD requests mirror the status code of GET requests as per RFC 9110.

middleware/healthcheck · high confidence

Introduce lightweight hot-path config reader to avoid struct copying

Added a new internal appconfig package that provides a zero-copy mechanism for reading specific configuration bits (Immutable, DisableHeaderNormalizing, UnescapePath) from the fiber application during request handling. This replaces the previous approach of copying the entire App.Config struct (over 600 bytes) on every call, reducing the overhead of accessing these hot-path settings from 25ns to 2ns. The implementation uses a thread-safe, once-only reader installation pattern to ensure the configuration snapshot is stable and consistent across concurrent requests.

internal/appconfig · high confidence

KeyAuth middleware refactored to use shared extractors and RFC 6750 compliance

The KeyAuth middleware has been restructured to use the shared extractor system, allowing keys to be extracted from various sources (headers, cookies, query params, etc.) via a configurable Extractor function. It now fully complies with RFC 6750 by supporting standardized error parameters (invalid\_request, invalid\_token, insufficient\_scope) and descriptions in WWW-Authenticate challenges. The middleware also integrates with the logger to automatically redact API keys in logs via a registered context tag.

middleware/keyauth · high confidence

Limiter middleware rewritten for v3 with dynamic configuration and sliding window support

The limiter middleware has been completely rewritten for v3, introducing a pluggable strategy interface that supports both Fixed Window and Sliding Window rate limiting via the new \LimiterMiddleware\ config option. Users can now dynamically control rate limits per request using the new \MaxFunc\ and \ExpirationFunc\ callbacks, and can opt out of counting specific outcomes with \SkipFailedRequests\ and \SkipSuccessfulRequests\. The middleware now supports disabling rate limit response headers via \DisableHeaders\, redacting keys in logs via \DisableValueRedaction\, and uses a shard-based locking mechanism to improve concurrency. Storage is handled via a new \fiber.Storage\ interface with \msgp\ encoding, and keys are automatically bounded to prevent storage abuse.

middleware/limiter · high confidence

Logger middleware rewritten for v3 with color support and template engine

The logger middleware has been completely refactored for v3, introducing a new template-based rendering engine (logtemplate) that replaces the previous string formatting logic. This change adds support for colored output (status codes and HTTP methods) with a new \ForceColors\ config option to override terminal detection, and introduces several predefined log formats including Common, Combined, JSON, and ECS. The middleware now supports custom context tags via \RegisterContextTag\, pre-registers known middleware tags to prevent build errors, and includes a \SanitizeValue\ helper to scrub control characters from log output, preventing log injection. The internal architecture has shifted to use compiled tag chains and a data pool for performance, while maintaining backward compatibility with the existing \Config\ structure for format, stream, and skip settings.

middleware/logger · high confidence

Optimized request-local storage for Fiber middleware

The \internal/ctxlocal\ package introduces a \Set\ function that stores request-local values more efficiently than the standard Fiber \Locals\ method. By directly invoking the underlying \Locals\ implementation on \\*fiber.DefaultCtx\ when possible, it avoids the heap allocation of the variadic slice that occurs when calling through the generic \fiber.Ctx\ interface. This change reduces allocation overhead (from 16 bytes to 0) and latency (from \~50ns to \~11ns) for middleware and extractors that store locals, while still correctly falling back to the interface method for custom context types to ensure overridden behavior is preserved.

internal/ctxlocal · high confidence

Performance optimization for same-origin checks in CSRF and redirect logic

The internal schemehost package, which validates same-origin status for CSRF (Origin/Referer) and open-redirect prevention, has been refactored to significantly improve hot-path performance. The new implementation uses allocation-free string comparisons and custom parsing for common host formats, avoiding the overhead of \url.Parse\ in the majority of cases. This change maintains strict behavioral compatibility with the previous logic, ensuring that scheme normalization (case-insensitivity) and default port handling (http:80, https:443) remain identical, while reducing memory allocations and CPU usage for these critical security checks.

internal/schemehost · high confidence

Recover middleware now supports configurable panic handling and optional stack traces

The recover middleware has been updated to allow customization of how panics are converted into errors and whether stack traces are printed. Users can now provide a custom PanicHandler to control the error message returned to the global error handler, and can enable stack trace logging via the EnableStackTrace config option, which defaults to false to avoid cluttering logs with stack dumps unless explicitly requested.

middleware/recover · high confidence

Request ID middleware now validates headers and uses SecureToken by default

The RequestID middleware has been updated to validate incoming HTTP headers, rejecting invalid characters (such as control characters) and falling back to a secure generator if the provided ID is malformed. The default generator has changed from UUIDv4 to \utils.SecureToken\ for improved privacy and security, and the middleware now automatically registers context tags for the logger middleware to include the request ID in logs.

middleware/requestid · high confidence

Rewrite middleware now supports ordered rules and anchored path matching

The rewrite middleware introduces a new \RuleList\ configuration option that accepts an ordered slice of rules, ensuring they are evaluated in the exact order specified (first match wins), replacing the previous unordered \Rules\ map which relied on a heuristic for specificity. Additionally, rewrite patterns are now anchored to the start of the request path, preventing rules from accidentally matching paths that merely contain the pattern as a suffix. The deprecated \Rules\ map is retained for backward compatibility but is discouraged in favor of the new ordered list.

middleware/rewrite · high confidence

Secure, high-performance log template engine with control-byte sanitization

The internal log template system has been replaced with a new, reusable rendering engine that parses format strings containing ${tag} and ${tag:param} placeholders into precompiled chains for efficient execution. To prevent log injection and terminal corruption, all user-controlled data written through the template is automatically sanitized, stripping ASCII control characters (such as newlines and carriage returns) while preserving tabs. The engine also provides structured error reporting via UnknownTagError, including helpful hints when a user references a bare tag that exists only in parametric form.

internal/logtemplate · high confidence

Session middleware rewritten for v3 with extractor-based ID resolution and msgp serialization

The session middleware has been completely rewritten for v3, introducing a new configuration structure and a pluggable Extractor pattern that allows session IDs to be resolved from cookies, headers, or query parameters via the extractors package. Session data is now stored in a pooled, thread-safe data structure and serialized using msgp for improved performance, while the default session key generator has been updated to use utils.SecureToken. The middleware also adds support for configurable idle and absolute timeouts, stricter cookie SameSite validation, and a new Destroy method to cleanly remove sessions.

middleware/session · high confidence

pprof middleware now supports URL prefixes and strict path matching

The pprof middleware has been refactored to support an optional URL prefix (e.g., /federated-fiber/debug/pprof) via a new Config.Prefix field, allowing it to be mounted at custom paths. Additionally, the middleware now strictly matches paths at segment boundaries to prevent accidental interception of sibling routes (such as /debug/pprofiler) and correctly handles trailing-slash redirects within the configured prefix.

middleware/pprof · high confidence

Fixes

Added quoted-string escaping for HTTP auth challenges

A new internal \quotedstring\ package has been added to correctly encode values for HTTP quoted strings, specifically targeting authentication challenges. The \Escape\ function implements RFC 9110 compliant escaping by handling backslashes, quotes, control characters, and non-ASCII bytes, ensuring that auth-related headers are formatted correctly without syntax errors.

internal/quotedstring · high confidence

Consolidated header list parsing into a shared internal package

The codebase now uses a single, shared \internal/headerlist\ package to handle comma-separated HTTP header values, replacing seven disparate implementations that previously existed in core helpers and middleware. This change ensures consistent parsing behavior across the application, specifically handling whitespace trimming, empty element skipping, and case-sensitivity rules (such as case-insensitive matching for the \Vary\ header) in one place, while also providing optimized, allocation-free utilities for common paths like \Accept-Encoding\.

internal/headerlist · high confidence

Corrected HTTP ETag parsing and comparison logic

The internal ETag handling has been consolidated into a new \internal/etag\ package that strictly follows RFC 9110. This change fixes a previous bug where the ETag middleware incorrectly split header values on every comma, which caused failures when parsing opaque tags containing commas (e.g., \"v1,v2"\). The new implementation correctly distinguishes between weak and strong comparisons, properly handles the wildcard \\*\ matcher, and ensures that commas inside quoted tags are preserved rather than treated as delimiters.

internal/etag · high confidence

Fix Content-Type normalization to preserve case-sensitive multipart boundaries

The mediatype package now correctly normalizes the case-insensitive parts of the Content-Type header while leaving parameter values (such as the multipart boundary) untouched. This prevents fasthttp's case-sensitive boundary matching from failing or selecting incorrect boundaries when headers contain mixed-case values or quoted strings with special characters.

internal/mediatype · high confidence

Prevent open redirects via URL normalization

Added an internal URL normalization package to enforce WHATWG URL parser rules before routing decisions. This change strips hidden control characters (tabs, newlines) and ensures composed route paths always start with exactly one forward slash, preventing attackers from using double slashes or backslashes to escape the intended origin and redirect users to external domains.

internal/urlnorm · high confidence

Robust HTTP header lookup and deletion with case-insensitive support

The internal/fieldname package now provides reliable, case-insensitive reading and removal of HTTP headers, addressing issues where fasthttp's byte-exact lookups failed when header normalization was disabled. The new First function correctly skips empty header lines to find the next valid value, preventing empty lines from hiding subsequent data. The Del function ensures all case variations of a header are removed, even in stores that preserve original casing, and avoids infinite loops when deleting synthesized headers like Content-Type. Additionally, a new crosshost package defines a list of sensitive headers (such as Authorization and Cookie) that must be stripped when a request is redirected to a different host, ensuring credentials are not leaked to unintended origins.

internal/fieldname · high confidence

Router keeps optional-slash routes reachable from the tree bucket

The routing engine now correctly preserves routes that end with an optional slash (e.g., \/path/\) within the tree bucket structure, ensuring they remain accessible and matchable. Previously, these routes could become unreachable or fail to match correctly during tree operations, leading to 404 errors for valid paths that relied on optional trailing slashes.

(repo-wide) · high confidence

The internal cookie package now centralizes SameSite mode parsing and formatting, ensuring consistent behavior across the framework. It supports Disabled, Lax, Strict, and None modes with case-insensitive input, and automatically enforces the Secure flag requirement for the None mode. Invalid inputs safely fall back to Lax mode, and the new logic correctly maps between Go's standard library and fasthttp cookie representations.

internal/cookie · high confidence

Test coverage

Added clocktest helper to synchronize tests with cached second-granularity clock

A new \internal/clocktest\ package provides the \SleepPast\ function, allowing tests to reliably wait for the expiration of time-to-live (TTL) values in fiber's memory storages and rate-limiters. Because these components compare expiry against a cached, second-granularity timestamp updated by a background goroutine, wall-clock sleeps alone are insufficient and can cause flaky CI failures. This helper sleeps past the TTL and then blocks until the cached timestamp has advanced, failing loudly if the clock gets stuck, ensuring deterministic test behavior.

internal/clocktest · high confidence

Dependencies

Update Go 1.26 and core dependencies in Fiber v3

The project now requires Go 1.26 and updates its core dependencies, including upgrading the HTTP engine to fasthttp v1.74.0, the schema parser to gofiber/schema v1.8.7, and the utility library to gofiber/utils/v2 v2.6.0. Additional updates include golang.org/x/crypto v0.57.0, golang.org/x/net v0.59.0, golang.org/x/text v0.42.0, and golang.org/x/sys v0.48.0, alongside updates to compression (klauspost/compress v1.20.0), CBOR (fxamacker/cbor/v2 v2.9.4), and testing libraries (stretchr/testify v1.12.1).

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 68 → 73 (+5.1)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 61 → 77 (+15.9)
  • Architecture 100 → 95 (-4.6)
  • Maturity 71 → 71 (-0.1)
  • Readiness 74 → 83 (+9.0)
  • Security 72 → 69 (-2.5)

Resolved (50)

  • Coverage not included — suite not readable by the collector
  • DefaultCtx.Charset (cognitive 31) (req.go)
  • DefaultCtx.Charset (cyclomatic 23) (req.go)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 2) (client/cookiejar.go)
  • Duplicated block (10 lines × 2) (domain.go)
  • Duplicated block (10 lines × 2) (router_skip.go)
  • Duplicated block (12 lines × 2) (middleware/redirect/redirect.go)
  • Duplicated block (13 lines × 2) (listen.go)
  • Duplicated block (13 lines × 2) (middleware/cache/utils.go)
  • Duplicated block (13 lines × 2) (middleware/cors/utils.go)
  • Duplicated block (14 lines × 2) (shared_state.go)
  • Duplicated block (15 lines × 2) (app.go)
  • Duplicated block (18 lines × 2) (middleware/cors/utils.go)
  • Duplicated block (21 lines × 2) (middleware/limiter/limiter_fixed.go)
  • Duplicated block (21 lines × 2) (router.go)
  • Duplicated block (24 lines × 2) (middleware/limiter/limiter_fixed.go)
  • Duplicated block (24 lines × 2) (router.go)
  • Duplicated block (5 lines × 2) (client/transport.go)
  • Duplicated block (5 lines × 2) (middleware/proxy/proxy.go)
  • …and 30 more

New (193)

  • App.ErrorHandler (cognitive 19) (app.go)
  • App.ensureAutoHeadRoutesLocked (cyclomatic 18) (router.go)
  • App.serverErrorHandler (cognitive 16) (app.go)
  • ClassTooLong: App (app.go)
  • ClassTooLong: Client (client/client.go)
  • ClassTooLong: DefaultCtx (ctx.go)
  • ClassTooLong: DefaultRes (res.go)
  • DefaultCtx.Endpoint (cognitive 18) (ctx.go)
  • DefaultCtx.Endpoint (cyclomatic 18) (ctx.go)
  • DefaultReq.Charset (cognitive 31) (req.go)
  • DefaultReq.Charset (cyclomatic 23) (req.go)
  • DefaultRes.Render (cyclomatic 23) (res.go)
  • Dependency advisory scan runs only on code events
  • Duplicated block (10 lines × 2) (binder/header.go)
  • Duplicated block (10 lines × 2) (constraint.go)
  • Duplicated block (10 lines × 2) (internal/tlstest/tls.go)
  • Duplicated block (10 lines × 2) (middleware/cache/manager.go)
  • Duplicated block (10 lines × 2) (middleware/limiter/limiter_fixed.go)
  • Duplicated block (10–15 lines × 2) (domain.go)
  • Duplicated block (11 lines × 2) (binder/mapping.go)
  • …and 173 more

Changes since last survey

  • 300 commits — 205 feature/other, 95 fixes

By area

  • (root) — 109 commits
  • (repo) — 78 commits
  • middleware/session — 15 commits
  • .github/dependabot.yml — 11 commits
  • docs/guide — 9 commits
  • .github/workflows — 7 commits
  • extractors/extractors.go — 7 commits
  • middleware/limiter — 7 commits
  • client/client_test.go — 5 commits
  • docs/api — 5 commits
  • middleware/cors — 5 commits
  • middleware/static — 5 commits
  • docs/middleware — 4 commits
  • middleware/logger — 3 commits
  • binder/mapping.go — 2 commits
  • client/hooks.go — 2 commits
  • extractors/PERFORMANCE_PLAN.md — 2 commits
  • extractors/extractors_test.go — 2 commits
  • middleware/cache — 2 commits
  • middleware/redirect — 2 commits

Notable commits

  • fix: Merge branch 'main' into claude/codebase-bug-audit-g0uzel
  • fix: Merge branch 'main' into claude/codebase-bug-audit-g0uzel
  • fix: Merge branch 'main' into claude/codebase-bug-audit-g0uzel
  • fix: Merge branch 'main' into fix-ipv6-port-normalization-issue
  • fix: Merge branch 'main' into fix/3297-render-to-writer
  • fix: Merge branch 'main' into fix/share-param-delimiters
  • fix: Merge branch 'main' into fix/vary-case-insensitive-field-names
  • fix: Merge pull request #4594 from RubenPari/fix/3297-render-to-writer
  • fix: Merge pull request #4599 from RubenPari/fix/3431-shutdown-context-docs
  • fix: Merge pull request #4601 from RubenPari/fix/2195-matched-route
  • fix: Merge pull request #4636 from AshSgDe29071999/fix/share-param-delimiters
  • fix: Merge pull request #4642 from official-burak/fix/vary-case-insensitive-field-names
  • fix: Merge pull request #4652 from gofiber/claude/codebase-bug-audit-g0uzel
  • fix: Merge pull request #4656 from gofiber/fix-unbounded-cache-in-sendfile
  • fix: Merge pull request #4659 from gofiber/propose-fix-for-request-ownership-vulnerability
  • fix: Merge pull request #4662 from gofiber/fix-panic-for-typed-nil-view-engines
  • fix: Merge pull request #4663 from gofiber/fix-route-naming-issue-in-fiber
  • fix: Merge pull request #4673 from BitWeaverDev/fix/domainforward-idn-fold
  • fix: Merge pull request #4674 from gofiber/fix-path-aliasing-vulnerability-in-fiber
  • fix: Merge pull request #4677 from BitWeaverDev/fix/limiter-bound-storage-key
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

gofiber/fiber was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit b03603103d23fe0ed177af7cc0f58e397905bedb — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-5f8d0eb43fd7.