ktorio/ktor
63.2
Adequate · 25 September 2026
154.8k
lines of production code
Kotlin
primary language
3
measurements over time
What this system is
This system is a Kotlin Multiplatform HTTP client framework that provides a unified API for making network requests across JVM, Android, iOS, macOS, Linux, Windows, JavaScript, and WebAssembly targets. It supports a wide variety of underlying engine implementations, including native platform clients like Darwin and WinHTTP, popular libraries such as OkHttp and Jetty, and custom engines like CIO and Curl. The framework features a modular plugin architecture for handling authentication, content negotiation, caching, compression, and real-time protocols like WebSockets and Server-Sent Events.
How it got here
2014–2020 — Ktor 2.0 architecture and multiplatform migration
96 changes.
This period focused on the major architectural overhaul of Ktor, replacing legacy hosting and routing subsystems with a new plugin-based engine and client architecture. The project simultaneously migrated its I/O layer to kotlinx-io and expanded comprehensive support for Kotlin Multiplatform targets, including Native, JS, and WasmJS. Significant effort was also dedicated to stabilizing public APIs, introducing new HTTP client engines, and establishing rigorous testing and contributor guidelines.
2021–2022 — Ktor 2.0 plugin API migration and stabilization
119 changes.
This period focused on migrating the Ktor client and server to a new hook-based plugin API, replacing legacy models with standardized lifecycle hooks and configuration patterns. It involved stabilizing public APIs for core plugins like authentication, content negotiation, and caching, while introducing new features such as WebSocket support, tracing, and type-safe resource building. The work also expanded platform coverage with new engines for Darwin, Windows, and Curl, alongside comprehensive test coverage and deprecation of older serialization interfaces.
2023–2025 — Jakarta EE migration and WebRTC expansion
130 changes.
This period focused on migrating server and client engines to Jakarta EE 10 standards, introducing new implementations for Jetty, Tomcat, and Apache HTTP Client 5. It also significantly expanded platform support by adding WebRTC client capabilities across multiple targets, establishing WebAssembly (WasmJS) as a first-class citizen for both client and server components, and introducing a comprehensive dependency injection system for the server.
2026 — OpenAPI expansion and non-JVM support
28 changes.
This period focused on significantly expanding OpenAPI documentation capabilities through new reflection-based inference, flexible source APIs, and runtime route description features. Concurrently, the codebase advanced multiplatform support by introducing non-JVM implementations for WebSockets, network primitives, and client IO, while adding initial support for Jackson 3 and Zstd compression.
Features
Add Android client engine using HttpURLConnection
The Android client engine is now available as a standalone module, providing an \HttpClient\ implementation backed by \HttpURLConnection\. This engine is designed for applications targeting older Android versions (API 1 and above) and can be instantiated via \HttpClient(Android)\ with optional configuration through \AndroidEngineConfig\.
ktor-client-android · high confidence
Add Apache 5 HTTP client engine for JVM
Users can now use the Apache HTTP Client 5 library as a backend for the Ktor HTTP client on the JVM. This new engine is exposed as the \Apache5\ data object, allowing configuration via \Apache5EngineConfig\ when constructing an \HttpClient\ instance.
ktor-client-apache5 · high confidence
Add BOMRemover plugin to strip Byte Order Marks from HTTP responses
The BOMRemover plugin is now available for Ktor HttpClient, allowing users to automatically remove Byte Order Marks (BOM) from the beginning of response bodies. By installing this plugin, the client intercepts incoming responses, detects common BOM signatures (UTF-8, UTF-16, UTF-32), and strips them before passing the content downstream, ensuring cleaner text processing for applications that do not expect these markers.
ktor-client/ktor-client-plugins/ktor-client-bom-remover/common/src/io/ktor/client/plugins/bomremover · high confidence
Add CallId plugin for client request tracing
The Ktor client now includes a CallId plugin that enables end-to-end tracing of requests by automatically injecting unique identifiers into outgoing HTTP headers. By default, the plugin retrieves a call ID from the current coroutine context and adds it to the X-Request-Id header, but users can customize this behavior by configuring custom generators and interceptors via the CallIdConfig.
ktor-client/ktor-client-plugins/ktor-client-call-id/common/src/io/ktor/client/plugins/callid · high confidence
Add JS-specific test dispatcher implementation
A new \TestJs.kt\ file has been added to the \ktor-test-dispatcher\ module for the JS target, providing the \testSuspend\ function implementation. This change enables JS suspend tests to run using the standard coroutine test runner with configurable timeouts, completing the test dispatcher support for the JS platform.
ktor-test-dispatcher/js · high confidence
Add JTE template support for server-side views
Introduces the JTE plugin, enabling developers to render JTE templates as HTTP responses. This adds the \JteContent\ class and \respondTemplate\ extension functions, allowing applications to serve dynamic HTML views by specifying a template name and parameters directly in route handlers.
ktor-server/ktor-server-plugins/ktor-server-jte/jvm · high confidence
Add JVM-specific CIO server implementation and utilities
This change introduces the JVM backend for the Ktor CIO server engine. It adds platform-specific utility files (\SocketAddressUtilsJvm\ and \CoroutineUtilsJvm\) that provide the necessary bridge implementations for network address handling and coroutine dispatchers, enabling the CIO server to function on the JVM platform.
ktor-server/ktor-server-cio/jvm · high confidence
Add JVM-specific HTTP request extensions for java.net.URL
The JVM-specific request builder module now provides convenience overloads for HttpClient methods (request, get, post, put, patch, options, head, delete, prepareRequest, prepareGet, preparePost, preparePut, preparePatch) that accept a java.net.URL directly, automatically converting it to the internal URL representation. Additionally, HttpRequestBuilder now supports setting or constructing requests from java.net.URL instances, and a deprecated unixSocket helper is retained for binary compatibility.
ktor-client/ktor-client-core/jvm/src/io/ktor/client/request · high confidence
Add JVM-specific default transformers for InputStream handling
A new JVM-specific implementation for default HTTP request and response transformers has been added to the client core. This change enables automatic conversion of \InputStream\ bodies to \ByteReadChannel\ for outgoing requests and converts incoming \ByteReadChannel\ responses to \InputStream\ when the expected type is \InputStream\, simplifying the integration of Java I/O streams with Ktor's client.
ktor-client/ktor-client-core/jvm/src/io/ktor/client/plugins · high confidence
Add JVM-specific socket timeout exception implementations
The JVM module now includes a new file defining actual implementations for ConnectTimeoutException and SocketTimeoutException, mapping them to standard Java network exceptions. This change provides the concrete platform-specific behavior required for the Ktor client's cross-platform network layer on JVM, ensuring that connection and socket timeouts are correctly reported to users via standard Java exception types.
ktor-client/ktor-client-core/jvm/src/io/ktor/client/network · high confidence
Add Jakarta Servlet engine support
The \ktor-server-servlet-jakarta\ module now includes the core implementation files for the Jakarta Servlet engine, specifically \KtorServlet\ and \ServletApplicationRequestHeaders\. \KtorServlet\ acts as the base class for servlet engine implementations, handling request lifecycle, coroutine scoping, and dispatching to either async or blocking service methods. \ServletApplicationRequestHeaders\ provides the mapping between Jakarta Servlet request headers and Ktor's internal headers interface. This change introduces the foundational components required to run Ktor applications on Jakarta EE 9+ servlet containers.
ktor-server-servlet-jakarta · high confidence
Add Kotlinx XML serialization support for Ktor
Introduces the \ktor-serialization-kotlinx-xml\ module, enabling developers to serialize and deserialize XML data within Ktor applications using the kotlinx.serialization library. This change adds the \xml()\ extension function to the \ContentNegotiation\ configuration, allowing users to register the \application/xml\ content type with a default XML configuration that handles namespace repair and disables XML declarations and polymorphic serialization by default.
ktor-network/windows, ktor-shared/ktor-serialization/ktor-serialization-kotlinx/ktor-serialization-kotlinx-cbor/common, ktor-shared/ktor-serialization/ktor-serialization-kotlinx/ktor-serialization-kotlinx-xml/common · high confidence
Add Ktor Client Engine Defaults module stubs
This change introduces the \ktor-client-engine-defaults\ module, which provides a curated set of default configurations for Ktor client engines. The current diff adds the initial module structure, including API dumps and platform-specific stub files (for JVM, Android Native, Darwin, Linux, Web, and Windows) to support multiplatform publication, laying the groundwork for centralized engine configuration.
(repo-wide) · high confidence
Add POSIX test runner for native suspend tests
A new test runner implementation for POSIX platforms has been added to the Ktor test dispatcher. This change introduces the \testSuspend\ function for native suspend tests, which executes test blocks within a coroutine scope using \runBlocking\ and \withTimeout\ to enforce specified timeout limits. The implementation also includes a feedback link in the KDoc for reporting issues.
ktor-test-dispatcher/posix · high confidence
Add POSIX-native implementation for Ktor I/O utilities
This change introduces the POSIX-specific implementations for core Ktor I/O components, enabling native support for byte channel operations, input/output handling, and object pooling. It provides platform-specific code for reading and writing raw C pointers, managing POSIX error codes (such as connection refused or timeout) via typed exceptions, and implementing synchronization primitives using native mutexes and atomic operations. Users on POSIX-compliant platforms (Linux, macOS, etc.) now have access to these native I/O abstractions, which are required for the broader Native CIO server support.
ktor-io/posix · high confidence
Add Stetho-based network tracing for Android
The Stetho tracing plugin for Ktor Client on Android is now available, enabling developers to inspect HTTP and WebSocket network traffic via Chrome DevTools. This change introduces the \StethoTracer\ class and a \Context.Stetho\ extension function that wraps the HTTP client engine to report request, response, and WebSocket frame data to the Stetho inspector.
ktor-client/ktor-client-plugins/ktor-client-tracing/ktor-client-tracing-stetho/android/src/io/ktor/client/features/tracing · high confidence
Add Tomcat Jakarta engine factory and main entry point
The Tomcat Jakarta server module now includes the core factory object and a main entry point for running the embedded server. Users can start the application via the new EngineMain.main() function, which parses command-line arguments and launches the Tomcat-based engine, or programmatically access the Tomcat factory to create and configure the server instance within their own application logic.
ktor-server/ktor-server-tomcat-jakarta/jvm · high confidence
Add Unix domain socket support and request cancellation detection to CIO server
The CIO server engine now supports Unix domain sockets, allowing users to configure a \UnixSocketServerSettings\ with a specific socket path instead of a TCP host and port. Additionally, the server can now detect when a client cancels a request, improving handling of aborted connections.
ktor-server-cio · high confidence
Add Unix domain socket support for Android Native targets
The ktor-network module now supports Unix domain sockets on Android Native platforms. This change introduces the necessary C interop definitions (un.def) and platform-specific implementations for socket address packing and unpacking, enabling applications to bind and connect using Unix socket paths on this target.
ktor-network · high confidence
Add Unix domain socket support for iOS and tvOS
Users can now use Unix domain sockets on iOS and tvOS platforms. This change adds platform-specific implementations for packing and unpacking Unix socket addresses, enabling network communication via local file system paths on these native targets.
ktor-network/ios, ktor-network/tvos · high confidence
Add WASM browser fetch engine for Ktor Client
This change introduces a new HTTP client engine implementation for Kotlin/Wasm running in browser environments. The new \BrowserFetch.kt\ file provides the core logic to execute HTTP requests using the browser's native Fetch API and handle response bodies by converting JavaScript ReadableStreams into Ktor's ByteReadChannel, enabling WASM-based applications to perform network calls in the browser.
ktor-client/ktor-client-core/wasmJs/src/io/ktor/client/engine/js/browser · high confidence
Add WASM client compatibility utilities
The Ktor HTTP client now supports the WasmJS target by introducing a new compatibility layer in the JS engine module. This change adds a \Utils.kt\ file that provides common fetch logic, allowing the client to function in both browser and Node.js-like environments within the WasmJS runtime. Users can now utilize the Ktor client on WebAssembly platforms with the same API surface as the existing JS implementation.
ktor-client/ktor-client-core/wasmJs/src/io/ktor/client/engine/js/compatibility · high confidence
Add WasmJS HTTP client engine
Introduces a new HTTP client engine for the WasmJS target, enabling Ktor client functionality in WebAssembly environments. This includes the core engine implementation (JsClientEngine) which handles standard HTTP requests via the browser's Fetch API and WebSocket connections, along with utility functions for converting Ktor request data to native JS objects and handling response bodies.
ktor-client/ktor-client-core/wasmJs/src/io/ktor/client/engine/js · high confidence
Add WebSocket support for Kotlin/Wasm
Introduces the \JsWebSocketSession\ implementation for the Kotlin/Wasm target, enabling WebSocket client functionality in WebAssembly environments. This new file provides the underlying session logic, including handling text and binary frames, managing connection states (open, error, close), and configuring channel backpressure, effectively bringing parity with the existing JavaScript WebSocket implementation.
ktor-client/ktor-client-core/wasmJs/src/io/ktor/client/plugins/websocket, ktor-client/ktor-client-webrtc/wasmJs · high confidence
Add WinHTTP client engine for Windows
A new Kotlin/Native HTTP client engine based on the Windows WinHTTP API is now available for Windows-based operating systems. Users can create an HTTP client by passing \WinHttp\ to the \HttpClient\ constructor and configure it using \WinHttpClientEngineConfig\.
ktor-client-winhttp · high confidence
Add WinHTTP client engine for Windows
Introduces a new HTTP client engine for Windows applications that leverages the native WinHTTP API. This engine supports HTTP/1.1 and HTTP/2.0, configurable security protocols (TLS 1.0–1.3), proxy settings, and timeout customization. It also enables WebSocket communication and Server-Sent Events (SSE), providing a native networking alternative for Ktor clients running on Windows.
ktor-client/ktor-client-winhttp/windows · high confidence
Add client-side Server-Sent Events (SSE) support with reconnection and deserialization
The Ktor client now includes a new SSE plugin that allows applications to receive real-time event streams from servers. This feature introduces \serverSentEvents\ and \serverSentEventsSession\ extension functions to establish connections, along with an \SSEConfig\ that enables automatic reconnection with configurable retry attempts and delays. The implementation supports filtering comment and retry events, captures diagnostic buffers for debugging stream failures, and provides a typed session interface with built-in deserialization helpers to map incoming event data to Kotlin objects.
ktor-client/ktor-client-core/common/src/io/ktor/client/plugins/sse · high confidence
Add configurable body filtering to the logging plugin
The Ktor client logging plugin now supports filtering the request and response bodies that are written to logs. A new \LogBodyFilter\ interface allows users to define custom logic to include, exclude, or transform body content, while a built-in \BinaryLogBodyFilter\ is provided to automatically skip binary or encoded content. This change enables more precise control over log verbosity and prevents sensitive or large binary data from cluttering logs.
ktor-client-logging · high confidence
Add fetchOptions extension for customizing HTTP requests on JS and WasmJs
Users can now configure underlying fetch request options (such as headers, body, or method) directly from their Ktor client code on JavaScript and WasmJs platforms. This is achieved via the new \fetchOptions\ extension function on \HttpRequestBuilder\, which accepts a lambda with a \RequestInit\ receiver, allowing fine-grained control over the native fetch API behavior.
ktor-client/ktor-client-core/js/src/io/ktor/client, ktor-client/ktor-client-core/wasmJs/src/io/ktor/client · high confidence
Add non-JVM implementations for WebSocket Frame and RawWebSocket
New source files have been added to the \nonJvm\ source-set to provide platform-specific implementations for the \Frame\ class (including Binary, Text, Close, Ping, and Pong variants) and the \RawWebSocket\ factory function. This change moves core WebSocket data structures and session creation logic out of the JVM-specific code, enabling the Ktor WebSocket module to function on non-JVM targets such as Wasm/Wasi.
ktor-shared/ktor-websockets/nonJvm · high confidence
Add non-JVM implementations for network timeout exceptions and exception utilities
The Ktor client core now includes specific source files for non-JVM platforms, providing actual implementations for ConnectTimeoutException, SocketTimeoutException, and the unwrapCancellationException utility. This ensures that network timeout handling and exception unwrapping logic are available and functional on non-JVM targets, completing the multiplatform support for these core client utilities.
ktor-client/ktor-client-core/nonJvm/src/io/ktor/client/network, ktor-client/ktor-client-core/nonJvm/src/io/ktor/client/utils · high confidence
Add raw WebSocket session builders for CIO client
The CIO HTTP client now exposes \webSocketRawSession\, \webSocketRaw\, \wsRaw\, and \wssRaw\ extension functions. These allow users to establish WebSocket connections without automatic ping-pong or other service message handling, providing direct access to the raw session for scenarios where manual control over connection lifecycle and messages is required.
ktor-client/ktor-client-cio/jvm/src/io/ktor/client/plugins/websocket · high confidence
Add upload/download progress observation via ObservableContent
The Ktor HTTP client now supports tracking upload and download progress through a new \ProgressListener\ callback and \ObservableContent\ wrapper. This allows users to register listeners on \HttpRequestBuilder.onDownload\ and \HttpRequestBuilder.onUpload\ to receive real-time updates on bytes sent and total content length, enabling features like progress bars for file transfers.
ktor-client/ktor-client-core/common/src/io/ktor/client/content · high confidence
Added Linux-specific thread stack collection and signal handling
The Ktor Utils library now includes native Linux support for gathering thread stack traces and managing signal handlers. This change introduces the \ThreadInfoLinux\ implementation, which utilizes platform-specific POSIX and Linux APIs to collect stack information and set up signal handling, enabling better debugging and error reporting capabilities on Linux targets.
ktor-utils/linux · high confidence
Added Node.js-specific socket module loaders for JS and WASM targets
New implementation files were added to the Ktor Network module for both the JS and WASM-JS platforms to handle Node.js-specific networking primitives. These files provide the actual implementations for loading the \node:net\ and \node:dgram\ modules, enabling the framework to access Node.js APIs for TCP/UDP sockets on these platforms. The changes include logic to dynamically import these modules only when running in a Node.js environment, ensuring compatibility with bundlers and other JavaScript runtimes.
ktor-network/js, ktor-network/wasmJs · high confidence
Added non-JVM platform stubs and implementations for Ktor modules
This change introduces a set of new source files across Ktor client, server, HTTP, and shared modules, placing them in the \nonJvm\ source-set to support platforms outside the JVM (such as Wasm/Wasi, JS, and Native). These files provide the necessary \actual\ implementations for platform-specific declarations, including default content transforms, response observer contexts, ignored types for content negotiation, MDC logging contexts, and HTTP CIO builders. Several modules also include stub implementations that explicitly throw \NotImplementedError\ or \error\ to indicate that certain features (like OAuth1a or file caching) are not yet supported on non-JVM targets, while others provide basic functional equivalents (like the Zstd encoder).
(repo-wide) · high confidence
Android WebRTC client implementation added
The \ktor-client-webrtc\ module now includes a complete Android implementation, enabling WebRTC peer-to-peer communication on Android devices. This adds platform-specific support for creating peer connections, managing media tracks (audio and video via the Android Camera2 API and JavaAudioDeviceModule), and handling data channels. The implementation wraps the native \org.webrtc\ library, providing Kotlin coroutines-based APIs for sending/receiving data, handling ICE candidates, and managing connection states, along with extensions to access native objects when needed.
ktor-client-webrtc · high confidence
Android logging now outputs to Logcat with message length handling
The Ktor Client Logging plugin on JVM/Android now includes a dedicated Android logger that writes to Logcat when no external SLF4J provider is present, ensuring logs are visible in Android development environments. This logger automatically handles Android's 4068-character log limit by splitting long messages, and falls back to the standard SLF4J logger if a provider is detected or if Logcat integration fails.
ktor-client/ktor-client-plugins/ktor-client-logging/jvm/src/io/ktor/client/plugins/logging · high confidence
CIO client engine API and POSIX loader stabilization
The CIO client engine's public API is now formally defined and validated, exposing the \CIO\ engine factory, \CIOEngineConfig\ (with \dnsResolver\, \maxConnectionsCount\, and \requestTimeout\ settings), \EndpointConfig\ (with \socketTimeout\, \connectTimeout\, and \keepAliveTime\), and WebSocket builder functions (\webSocketRaw\, \wsRaw\, \wssRaw\). Additionally, a POSIX-specific loader (\Loader.posix.kt\) has been added to eagerly register the CIO engine at initialization, ensuring the engine is available for use on POSIX targets without manual wiring.
ktor-client/ktor-client-cio/api · high confidence
CIO client engine support for JS and Wasm-JS platforms
The CIO HTTP client engine is now available for JavaScript and WebAssembly (Wasm-JS) targets. New loader files have been added for both platforms to register the CIO engine during initialization, enabling developers to use the CIO engine for HTTP requests in Node.js environments running on these platforms.
ktor-client/ktor-client-cio/js, ktor-client/ktor-client-cio/wasmJs · high confidence
CIO engine adds Unix domain socket support and suspending lifecycle methods
The CIO server engine now supports binding to Unix domain sockets via a new \unixConnector\ configuration option, allowing applications to listen on file-system sockets instead of TCP ports. Additionally, the engine exposes \startSuspend\ and \stopSuspend\ methods, enabling non-blocking, coroutine-aware control over the server's lifecycle.
ktor-server · high confidence
CIO engine adds async DNS resolver and stabilizes client support
The CIO HTTP client engine now includes a new asynchronous DNS resolver (CioDnsResolver) that performs non-blocking hostname lookups via UDP, supporting both IPv4 and IPv6 with configurable timeouts and servers. This change also stabilizes the CIO engine for use across JVM, Android, and Kotlin/Native platforms, and introduces internal task management for handling dedicated connections and custom timeouts. Users can now configure the DNS resolver directly in their CIO engine settings for more control over network resolution behavior.
ktor-client-cio · high confidence
Client WebSocket plugin implementation and API
The client-side WebSocket plugin is now available, providing the \WebSockets\ plugin configuration and extension functions like \webSocketSession\, \webSocket\, and \ws\ to establish connections. The API supports configuring ping intervals using \kotlin.time.Duration\ and allows sending and receiving serialized data via \sendSerialized\ and \receiveDeserialized\ methods that leverage the client's content converters.
ktor-client/ktor-client-core/common/src/io/ktor/client/plugins/websocket · high confidence
Curl engine now supports WebSockets and response body backpressure
The Curl engine now supports WebSocket connections, allowing users to establish bidirectional communication channels. This change introduces new internal components to handle WebSocket frame processing, including support for chunked frames and configurable maximum frame sizes. Additionally, the engine now implements response body backpressure, ensuring that large responses are handled efficiently without overwhelming memory. These changes enhance the Curl engine's capability to handle modern, real-time communication protocols.
ktor-client/ktor-client-curl/desktop/src/io/ktor/client/engine/curl/internal · high confidence
Darwin client engine and certificate pinning implementation
The Darwin client engine for macOS, iOS, tvOS, and other Darwin-based platforms is now available, allowing users to create HTTP clients using the native \NSURLSession\ via \HttpClient(Darwin)\. This update also introduces certificate pinning support, enabling users to configure trusted certificate hashes (SHA-1 or SHA-256) for specific hostnames to prevent man-in-the-middle attacks and ensure secure connections.
ktor-client-darwin · high confidence
DefaultHeaders plugin adds Date and Server headers to responses
The DefaultHeaders plugin now automatically injects standard HTTP Date and Server headers into every server response. Users can configure additional custom headers via the plugin's DSL and override the default Server header value. The implementation includes a caching mechanism for the Date header to minimize overhead, with a configurable time source for testing purposes.
ktor-server/ktor-server-plugins/ktor-server-default-headers/common/src/io/ktor/server/plugins/defaultheaders · high confidence
Dependency injection plugin adds non-JVM platform support with limited capabilities
The dependency injection plugin now includes initial support for non-JVM platforms, enabling the plugin to be used in multiplatform projects. However, because reflection is not available on these platforms, several features are restricted: service locator functionality is disabled, covariant type resolution and nullable type handling via reflection are omitted, and classpath references cannot be installed. Additionally, synchronous dependency resolution (\getBlocking\) is implemented by checking if the async resolution is already completed; if the dependency is not yet ready, a \MissingDependencyException\ is thrown instead of blocking.
ktor-server/ktor-server-plugins/ktor-server-di/nonJvm/src/io/ktor/server/plugins/di · high confidence
Flexible certificate generation helpers for testing
The \ktor-network-tls-certificates\ module now provides more flexible builders for generating test certificates and keystores. The new \CertificateBuilder\ allows configuration of hash and signature algorithms, validity duration, key size, and specific domains or IP addresses for server certificates. It also supports creating non-self-signed certificates by specifying an issuer via the \signWith\ methods. The \KeyStoreBuilder\ simplifies assembling these certificates into a usable keystore, automatically handling certificate chains based on the issuer relationships defined in the builders.
ktor-network-tls-certificates, ktor-network/ktor-network-tls/ktor-network-tls-certificates/jvm · high confidence
GSON serialization support for HTTP and WebSocket content conversion
This change introduces the GSON-based content converters for Ktor, enabling JSON serialization and deserialization for both standard HTTP responses and WebSocket frames. The new GsonConverter handles HTTP content negotiation, including specific support for serializing kotlinx.coroutines.flow.Flow objects as JSON arrays, while GsonWebsocketContentConverter provides similar functionality for WebSocket text frames, ensuring proper context handling during deserialization.
ktor-shared/ktor-serialization/ktor-serialization-gson/jvm · high confidence
HTMX extension adds typed constants for attributes, events, and headers
The Ktor HTMX extension now provides a comprehensive set of type-safe constants for HTMX integration. This includes \HxAttributeKeys\ for all HTMX HTML attributes (such as \hx-get\, \hx-target\, and \hx-swap\), \HxEvents\ for HTMX lifecycle events (like \htmx:afterSwap\ and \htmx:beforeRequest\), \HxCss\ for CSS class names used during requests, \HxRequestHeaders\ and \HxResponseHeaders\ for standard HTMX HTTP headers, and \HxSwap\ for swap mode values. These constants allow developers to avoid magic strings when configuring HTMX behavior in Ktor applications.
ktor-shared/ktor-htmx/common · high confidence
HTMX plugin adds typed header access and scoped routing
The Ktor HTMX plugin now provides typed accessors for HTMX request and response headers (such as \hx.isBoosted\, \hx.prompt\, and response \location\ or \pushUrl\) via the \HXRequestHeaders\ and \HXResponseHeaders\ classes, and introduces an \hx\ routing scope that allows developers to define routes that only apply when the \HX-Request\ header is present, with additional helpers to filter by target or trigger headers.
ktor-server/ktor-server-plugins/ktor-server-htmx/common · high confidence
HTTP method builders added to Ktor Client Resources plugin
The \builders.kt\ file in the Ktor Client Resources plugin now provides extension functions for \HttpClient\ to execute HTTP requests (GET, POST, PUT, DELETE, PATCH, OPTIONS, HEAD, and generic request) using resource objects. This includes both immediate execution methods (e.g., \get\, \post\) and preparation methods (e.g., \prepareGet\, \preparePost\) that return \HttpStatement\. These builders automatically construct the URL from the provided resource and attach the resource to the request attributes, enabling type-safe resource-based HTTP calls.
ktor-client/ktor-client-plugins/ktor-client-resources/common/src/io/ktor/client/plugins/resources · high confidence
Initial ABI dump for Ktor Client WebSockets
The Ktor Client WebSockets module now includes an initial ABI dump file (ktor-client-websockets.klib.api) that defines the public API surface for a wide range of targets, including Android Native, iOS, macOS, Linux, Windows, and WebAssembly. This establishes the baseline API contract for the plugin across these platforms.
ktor-client/ktor-client-plugins/ktor-client-websockets/api · high confidence
Initial Jackson 3 serialization support for Ktor
This change introduces the \ktor-serialization-jackson3\ module, providing new \JacksonConverter\ and \JacksonWebsocketContentConverter\ classes that integrate the Jackson 3 library (package \tools.jackson\) with Ktor's ContentNegotiation and WebSocket plugins. Users can now register Jackson 3 as their JSON provider via the \jackson()\ extension function, which configures an \ObjectMapper\ with Kotlin module support and pretty-printing defaults. The implementation handles both standard HTTP body serialization/deserialization and WebSocket frame conversion, allowing applications to migrate from Jackson 2 to the newer Jackson 3 API.
ktor-shared/ktor-serialization/ktor-serialization-jackson3/jvm · high confidence
Initial WASM Fetch client implementation
Adds a new HTTP client implementation for Kotlin/WASM targets that bridges Ktor Client to the browser's native Fetch API. This change introduces the necessary JavaScript interop bindings (LibDom and LibEs5) for Web APIs such as Request, Response, Headers, FormData, and TypedArrays, enabling Ktor Client to function in WebAssembly environments.
ktor-client/ktor-client-core/wasmJs/src/io/ktor/client/fetch · high confidence
Initial implementation of the Ktor Curl client engine for desktop
This change introduces the core implementation of the Curl-based HTTP client engine for the desktop platform. The new \CurlClientEngine\ declares support for HTTP timeouts, WebSockets, and Server-Sent Events (SSE). It includes configuration options in \CurlClientEngineConfig\ for setting CA certificate paths (\caInfo\, \caPath\) and controlling SSL verification (\sslVerify\), along with utility functions for parsing HTTP responses.
ktor-client/ktor-client-curl/desktop/src/io/ktor/client/engine/curl · high confidence
Initial public API definition for Ktor Client Mock
This change introduces the official API dump files for the \ktor-client-mock\ module, establishing the public binary interface for the MockEngine. It exposes the \MockEngine\ class and its \Companion\ for creating mock HTTP clients, along with \MockEngineConfig\ for configuring request handlers and handler reuse behavior. The API also defines \MockRequestHandleScope\ and utility extension functions like \respond\, \respondOk\, \respondError\, and \respondRedirect\ to facilitate writing test responses, ensuring binary compatibility across all supported platforms including Android Native, iOS, JS, and JVM.
ktor-client/ktor-client-mock/api · high confidence
Initial public API definition for the Android HTTP client engine
This change introduces the binary compatibility API surface for the new Android-specific HTTP client engine. It exposes the \Android\ engine factory, the \AndroidClientEngine\ implementation, and the \AndroidEngineConfig\ configuration class, which allows users to set connection/socket timeouts, request configuration, and SSL manager settings. This establishes the public contract for integrating the Android engine with Ktor Client.
ktor-client/ktor-client-android/api · high confidence
Initial public API definitions for Ktor Test Dispatcher
This change introduces the initial public API surface for the \ktor-test-dispatcher\ module, exposing the \runTestWithRealTime\ and \testSuspend\ functions for use in testing coroutine-based code. The API is available across multiple platforms, including native targets (iOS, macOS, Linux, Windows, etc.) and JavaScript/Wasm, allowing developers to integrate this testing utility into their multiplatform projects.
ktor-client/api, ktor-test-dispatcher · high confidence
Initial release of the OpenAPI Schema inference module
This change introduces the new \ktor-openapi-schema\ module, providing the core infrastructure for automatically generating JSON Schema definitions from Kotlin types. It includes the \JsonSchemaInference\ API and \KotlinxSerializerJsonSchemaInference\ implementation, which traverse kotlinx-serialization descriptors to build schemas for classes, sealed types, and value classes. The module also defines the foundational \JsonType\ enum, \ExtensionProperties\ typealias, and platform-specific serialization adapters (such as the \YamlNodeSerialAdapter\ for JVM) required to integrate with the broader OpenAPI/Swagger documentation plugins.
ktor-shared/ktor-openapi-schema/common · high confidence
Initial support for Android Native targets
Ktor now supports Android Native platforms, enabling developers to build and run Ktor applications on Android devices using Kotlin/Native. This release adds platform-specific implementations for core networking and I/O operations, including charset handling (UTF-8 support) in ktor-io and native socket utilities (such as recvfrom, accept, and getsockopt) in ktor-network for both 32-bit and 64-bit Android Native architectures, as well as Darwin and Linux environments.
(repo-wide) · high confidence
Introduce Android HTTP client engine
Adds a new Android-specific HTTP client engine that uses Java's HttpURLConnection under the hood. This engine supports HTTP timeouts (connect, socket, and request), SSL configuration, and Server-Sent Events (SSE). It automatically disconnects connections when a request is cancelled and includes a service provider registration for automatic discovery.
ktor-client/ktor-client-android/jvm, ktor-client/ktor-client-java/api · high confidence
Introduce Apache 5 HTTP client engine
Users can now use the Apache 5 HTTP client engine for Ktor on the JVM. This new engine provides an asynchronous implementation backed by Apache HttpClient 5, supporting HTTP/2, custom DNS resolvers, and configurable connection management. It includes built-in support for Server-Sent Events (SSE) and allows fine-grained control over SSL/TLS settings, timeouts, and proxy configurations through the \Apache5EngineConfig\.
ktor-client/ktor-client-apache5/jvm · high confidence
Introduce Apache 5 client engine API
Users can now use the Apache 5 HTTP client engine with Ktor. This change adds the public API for the new engine, including the \Apache5\ factory, the \Apache5EngineConfig\ for configuring connection timeouts, DNS resolution, SSL settings, and request customization, and the \Apache5EngineContainer\ for engine registration.
ktor-client/ktor-client-apache5/api · high confidence
Introduce CIO HTTP engine implementation
This change adds the initial implementation of the CIO (Coroutines I/O) HTTP engine for Ktor. It introduces core classes for handling HTTP messages, including \CIOHeaders\ for header management, \ConnectionOptions\ for parsing the Connection header, and \Multipart\ support for parsing multipart content with non-blocking release capabilities. The implementation also includes internal utilities like \AsciiCharTree\ for efficient header parsing and \CharArrayBuilder\ for memory-efficient string building, establishing the foundation for the CIO transport layer.
ktor-http-cio · high confidence
Introduce ContentEncoding plugin for request compression and response decompression
The ktor-client-encoding module now provides a new ContentEncoding plugin that allows users to configure compression algorithms (such as gzip, deflate, and identity) for both outgoing requests and incoming responses. Users can enable request body compression via the new Mode configuration, set quality values for Accept-Encoding headers, and automatically decode compressed server responses. The plugin handles header management, including stripping Content-Encoding and Content-Length headers from decompressed responses, and supports custom encoders.
ktor-client-encoding · high confidence
Introduce DoubleReceive plugin for re-reading request bodies
The DoubleReceive plugin is now available, allowing request bodies to be read multiple times without throwing a RequestAlreadyConsumedException. It caches the raw request body in memory or on disk (configurable via cacheRawRequest, useFileForCache, and maxSize) and intercepts the receive pipeline to serve cached content on subsequent reads, enabling use cases like logging the body before route handlers consume it.
ktor-server/ktor-server-plugins/ktor-server-double-receive/common/src/io/ktor/server/plugins/doublereceive · high confidence
Introduce Jackson content converters for HTTP and WebSocket serialization
This change adds the \JacksonConverter\ and \JacksonWebsocketContentConverter\ classes to the \ktor-serialization-jackson\ module, enabling Jackson-based JSON serialization for standard HTTP requests/responses and WebSocket frames. The HTTP converter supports streaming via \OutputStreamContent\ to avoid loading entire bodies into memory, handles various charsets by delegating to Jackson's native encoding logic, and includes specific serialization logic for \kotlinx.coroutines.flow.Flow\<T\>\. The WebSocket converter provides similar functionality for WebSocket text and binary frames, ensuring that deserialization runs on \Dispatchers.IO\ to prevent blocking the event loop. These converters are registered with the \ContentNegotiation\ plugin via the new \jackson()\ extension function, which configures an \ObjectMapper\ with Kotlin module support and default pretty-printing.
ktor-shared/ktor-serialization/ktor-serialization-jackson/jvm · high confidence
Introduce Jakarta EE 10-compatible Jetty HTTP client engine
Adds a new \ktor-client-jetty-jakarta\ module providing an HTTP client engine built on Jetty 12 (Jakarta EE 10). This engine allows users to create HTTP clients using the \Jetty\ factory, which internally utilizes Jetty's HTTP/2 implementation. The implementation includes a dedicated response listener (\JettyResponseListener\) that manages HTTP/2 stream lifecycle, handles push promises by canceling them, processes headers and data chunks via coroutines, and ensures proper resource cleanup on timeouts or connection resets.
ktor-client-jetty-jakarta · high confidence
Introduce Jakarta-based Jetty HTTP/2 client engine
Adds a new \ktor-client-jetty-jakarta\ module providing an HTTP/2 client engine built on Jetty 12. This engine supports cleartext HTTP/2 (h2c) connections, allows custom Host headers, and includes a configurable client instance cache. The implementation registers itself via the standard service provider interface and includes a dedicated test suite to validate HTTP/2 protocol compliance and engine behavior.
ktor-client/ktor-client-jetty-jakarta/jvm · high confidence
Introduce Ktor Resources for type-safe URL generation
The Ktor Resources module is now available, providing a \@Resource\ annotation and an \href\ function to generate URLs from data classes. This feature maps class properties to path placeholders and query parameters, handling serialization and deserialization of resources via the new \Resources\ plugin and \ParametersEncoder\/\ParametersDecoder\ components.
ktor-shared/ktor-resources/common · high confidence
Introduce KtorServlet and servlet-specific request/response implementations
The \ktor-server-servlet\ module now includes the core \KtorServlet\ base class, which bridges the servlet container lifecycle with Ktor's coroutine-based engine pipeline, supporting both async and blocking request handling modes. Additionally, new \ServletApplicationRequestHeaders\ and \ServletApplicationResponse\ classes provide the concrete implementations for mapping HTTP servlet requests and responses to Ktor's internal application call structures, enabling the server to correctly handle headers, status codes, and response channels within a Java EE servlet environment.
ktor-server-servlet · high confidence
Introduce Mustache templating plugin for Ktor Server
Adds a new Mustache plugin that enables rendering HTML views using Mustache templates. Users can now respond with templates via the \respondTemplate\ extension function or by returning \MustacheContent\, supporting optional ETag caching and custom content types. The plugin allows configuration of the underlying \MustacheFactory\ through \MustacheConfig\.
ktor-server/ktor-server-plugins/ktor-server-mustache/jvm · high confidence
Introduce Partial Content plugin for HTTP range requests
The Ktor server now includes a new Partial Content plugin that enables handling HTTP range requests, allowing clients to resume downloads or stream specific portions of content. This change adds the core plugin logic, configuration for maximum range counts, and utilities for processing single and multiple byte ranges, including support for the If-Range header and proper 206 Partial Content responses.
ktor-server/ktor-server-plugins/ktor-server-partial-content/common/src/io/ktor/server/plugins/partialcontent · high confidence
Introduce Rust-based WebRTC engine for Ktor Client
This change adds a new native WebRTC engine implementation for the Ktor client, built on the WebRTC.rs library via UniFFI bindings. It introduces the \RustWebRtc\ engine factory and \RustWebRtcEngine\ to handle peer connections, along with a \RustWebRtcDataChannel\ that exposes data channel properties (such as \id\, \label\, and \state\) and supports asynchronous text and binary message sending. The update includes utility functions for mapping WebRTC states (ICE, signaling, connection) and exceptions between the Rust native layer and the Ktor API, providing an alternative to existing platform-specific implementations.
ktor-client/ktor-client-webrtc/ktor-client-webrtc-rs/common · high confidence
Introduce Server-Sent Events (SSE) model classes
The \ktor-sse\ module now includes the core data models for Server-Sent Events, specifically the \ServerSentEvent\ and \TypedServerSentEvent\ classes along with the \ServerSentEventMetadata\ interface. These classes define the structure for SSE data, event types, IDs, retry intervals, and comments, and provide the \eventToString\ logic to serialize these fields into the standard SSE wire format. This change establishes the foundational types used by the SSE plugin for both server and client implementations.
ktor-sse · high confidence
Introduce StatusPages plugin for centralized error and status code handling
Adds the StatusPages plugin, allowing developers to configure custom handlers for specific HTTP status codes and exception types. This enables centralized error page rendering and exception management by registering handlers for status codes (e.g., 404, 500) or specific exception classes, with support for unhandled call fallbacks.
ktor-server/ktor-server-plugins/ktor-server-status-pages/common/src/io/ktor/server/plugins/statuspages · high confidence
Introduce Tomcat as an embedded server engine for Ktor
Users can now run Ktor applications on the Apache Tomcat server using the new \ktor-server-tomcat\ module. This change adds the \TomcatApplicationEngine\, allowing developers to configure embedded Tomcat instances with support for SSL/TLS (including client certificate authentication), HTTP/2 via OpenSSL, and custom Tomcat initialization hooks. The engine integrates with Ktor's standard application lifecycle, handling startup, shutdown, and coroutine context propagation.
ktor-server-tomcat · high confidence
Introduce WebRTC client implementation for JavaScript and WasmJS targets
This change adds the WebRTC client engine implementation for the \web\ module, enabling WebRTC connectivity on JavaScript and WasmJS platforms. It includes the \JsWebRtc\ engine factory, \JsWebRtcDataChannel\ for handling data streams, and \Browser.kt\ for mapping Kotlin types to native browser WebRTC interfaces. The update also introduces \WebRtcIO\ and \DataChannelClosed\ exceptions to improve error handling and adds tests for audio/video track creation and mock media devices.
ktor-client/ktor-client-webrtc/web · high confidence
Introduce WinHTTP client engine for Windows
This change adds the WinHTTP engine module for the Ktor HTTP client, enabling users on Windows to utilize the native WinHTTP API for network requests. The module exposes a \WinHttp\ engine factory and a \WinHttpClientEngineConfig\ that allows configuration of security protocols (TLS 1.0 through 1.3), SSL verification, and HTTP protocol versions. It also includes a C-interop definition (\winhttp.def\) that binds to the Windows \winhttp\ library and explicitly defines WebSocket-related types and functions (such as \WinHttpWebSocketSend\ and \WinHttpWebSocketReceive\) to support WebSocket communication. The entry includes the public API dump for the mingwX64 target and initial test coverage for basic HTTP operations, proxy support, and error message formatting.
ktor-client/ktor-client-winhttp · high confidence
Introduce iOS WebRTC client implementation
Adds a new iOS-specific implementation for the Ktor WebRTC client, enabling real-time communication capabilities on iOS devices. This change introduces platform-specific components including the \IosWebRtcEngine\ for managing peer connections, \IosWebRtcConnection\ for handling signaling and state events, and \IosWebRtcDataChannel\ for data transmission. The implementation bridges Kotlin coroutines with the native iOS WebRTC framework, ensuring proper delegate retention to prevent message loss and providing utilities for converting between Ktor and native WebRTC types.
ktor-client/ktor-client-webrtc/ios/src/io/ktor/client/webrtc · high confidence
Introduce native WebRTC client engine backed by WebRTC.rs
A new native WebRTC client engine is now available for the Ktor WebRTC client, implemented in Rust using the \webrtc\ crate and exposed to Kotlin via UniFFI. This engine provides the \RustWebRtc\ implementation of \WebRtcClientEngineFactory\, enabling peer connections, media tracks (audio and video), and data channels on supported platforms (JVM, Native). The API exposes core WebRTC capabilities including session description management (offers/answers), ICE candidate handling, track management, and data channel communication, with state observers for connection, signaling, and ICE events.
ktor-client/ktor-client-webrtc/ktor-client-webrtc-rs · high confidence
Introduce new embedded Tomcat engine with Jakarta Servlet support
The Ktor server now includes a new \TomcatApplicationEngine\ implementation located in the \ktor-server-tomcat-jakarta\ module, enabling users to run applications on an embedded Tomcat server using the Jakarta Servlet API. This engine supports configurable HTTP and HTTPS connectors, including SSL/TLS settings (key stores, trust stores, protocols) and HTTP/2 upgrades via OpenSSL, while also providing shutdown configuration options for graceful termination.
ktor-server-tomcat-jakarta · high confidence
Introduce persistent cookie storage API with public matching and default-filling utilities
The Cookies plugin now exposes a new \CookiesStorage\ interface that allows applications to implement custom, persistent cookie storage backends instead of relying on the default in-memory behavior. To support this, the \Cookie.matches\ and \Cookie.fillDefaults\ functions are now public, enabling custom storage implementations to correctly filter cookies by URL and apply default domain/path values. A \ConstantCookiesStorage\ implementation is also provided for scenarios where a static list of cookies is required.
ktor-client/ktor-client-core/common/src/io/ktor/client/plugins/cookies · high confidence
Introduce shared serialization content converter interfaces and exception types
This change introduces the foundational interfaces and exception classes for content conversion in the \ktor-serialization\ module. It adds \ContentConverter\ for HTTP content negotiation (handling serialization to \OutgoingContent\ and deserialization from \ByteReadChannel\) and \WebsocketContentConverter\ for WebSocket frame conversion, along with specific exception classes like \ContentConvertException\, \JsonConvertException\, and \WebsocketContentConvertException\ to provide clearer error reporting during conversion failures.
ktor-shared/ktor-serialization/common · high confidence
Introduce web-specific platform implementations for Ktor utilities
This change adds a new \ktor-utils/web\ module providing actual implementations of common Ktor utility interfaces for JavaScript and WebAssembly targets. It includes platform-specific logic for attributes storage, collection handling, content encoding (gzip/deflate as identity), platform detection (Node vs. Browser), stack trace generation, and network address representation. Additionally, it implements the logging infrastructure to route messages to the browser console and defines the pipeline coroutine start behavior for the web environment, ensuring Ktor utilities function correctly in web contexts.
ktor-utils/web · high confidence
Introduces Ktor Dependency Injection plugin
Adds the \ktor-server-di\ plugin, providing a new dependency injection system for Ktor applications. This includes a \DependencyRegistry\ for registering and resolving dependencies, support for async resolution via \Deferred\ types, and advanced type matching through covariance rules (handling supertypes, nullable types, raw types, and type parameter variance). The plugin also features a \Named\ annotation for qualified dependencies, a \Property\ annotation for injecting configuration values, and lambda overloads for registering providers with up to six resolved parameters.
ktor-server/ktor-server-plugins/ktor-server-di/common/src/io/ktor/server/plugins/di · high confidence
Introduces Rust-based WebRTC client implementation
The WebRTC client module now includes a new implementation backed by the WebRTC.rs library (via UniFFI). This adds native support for managing peer connections, handling media tracks (audio and video), and managing RTP senders and parameters using Rust internals. Users can now leverage this Rust-based engine for WebRTC operations, which provides specific capabilities such as data channel creation, ICE candidate handling, and statistics gathering, while noting that certain features like DTMF and setting RTP parameters are currently unsupported by the underlying WebRTC.rs library.
ktor-client-webrtc-rs · high confidence
Introduces typesafe authentication DSL with typed schemes and role-based authorization
The authentication plugin now supports a new typesafe DSL that allows defining authentication schemes with specific principal types, enabling route handlers to access the authenticated user without casting. This change introduces \AuthenticationScheme\ and \SimpleAuthenticationScheme\ classes, along with typed provider builders for Basic, Bearer, Form, and Session authentication. Additionally, it adds role-based authorization support via \AuthenticationRole\ and \withRoles\, allowing routes to declare required roles and handle authorization failures separately from authentication failures. The legacy \Principal\ property is deprecated in favor of new accessor methods on \AuthenticationContext\.
ktor-server/ktor-server-plugins/ktor-server-auth/common · high confidence
Introduces web platform support for Ktor server engine
Adds the core server engine implementation for web targets (JS/Wasm), enabling Ktor applications to run in browser or Node.js environments. This includes the \EmbeddedServer\ class with \startSuspend\ support, platform-specific environment variable handling via \process.env\, and graceful shutdown hooks that listen for \SIGTERM\ and \SIGINT\ signals. It also provides necessary internal utilities such as console error logging, dispatcher bridging, and hostname escaping for Windows compatibility.
ktor-server/ktor-server-core/web · high confidence
Introduces web-specific HttpClient implementation and Blob support
This change adds the core web implementation for the Ktor HTTP client, establishing the \HttpClient\ constructor to automatically select the JavaScript engine (preferring non-JS engines if available). It introduces \appendBlob\ extensions for \FormBuilder\, enabling Kotlin/JS and Kotlin/WasmJS applications to upload browser \Blob\ and \File\ objects as multipart form data. Additionally, it provides utility functions for registering DOM event listeners with proper disposal handling and configures the client to skip unreliable Content-Length checks in the browser environment.
ktor-client/ktor-client-core/web · high confidence
Introduction of Content Negotiation plugin with OpenAPI schema inference
The Content Negotiation plugin is now available to handle media type negotiation via Accept and Content-Type headers and manage serialization for formats like JSON, XML, CBOR, and ProtoBuf. A key behavioral addition is automatic integration with OpenAPI documentation: the plugin now registers default content types for application metadata and, if a converter implements JsonSchemaInference, it automatically aligns the generated OpenAPI schema with the models used in serialization.
ktor-server-content-negotiation · high confidence
Introduction of HttpClient core API and engine discovery mechanism
This change introduces the foundational \HttpClient\ class and its configuration model (\HttpClientConfig\), providing the primary entry point for users to create and configure HTTP clients with plugins, timeouts, and redirection settings. It also adds \HttpClientEngineContainer\, which implements a priority-based discovery mechanism to automatically select the default HTTP engine when multiple implementations are present on the classpath, simplifying setup for end-users.
ktor-client/ktor-client-core/common/src/io/ktor/client · high confidence
Introduction of Pebble templating plugin for Ktor
The Ktor server now includes a new Pebble templating plugin, allowing developers to render HTML views using Pebble templates. This addition introduces a \Pebble\ application plugin and a \PebbleContent\ response type, along with a convenient \respondTemplate\ extension function for \ApplicationCall\. The plugin supports automatic locale selection based on the client's \Accept-Language\ header when available languages are configured, and allows for custom content types and ETag support in responses.
ktor-server/ktor-server-plugins/ktor-server-pebble/jvm · high confidence
Introduction of WebRTC Client API
A new multiplatform WebRTC client is now available, allowing users to establish peer-to-peer connections and manage media tracks via a high-level API. The \WebRtcClient\ class and its factory function are marked as \@ExperimentalKtorApi\, indicating they are subject to change. Users can configure the client using platform-specific engines and settings such as ICE servers and statistics refresh rates.
ktor-client/ktor-client-webrtc/common · high confidence
Introduction of new server core APIs and plugin creation utilities
This release introduces foundational components for the Ktor server core, including new functions to create \ApplicationPlugin\ and \RouteScopedPlugin\ instances via \createApplicationPlugin\ and \createRouteScopedPlugin\. It adds a new \MapConfigDecoder\ to support configuration deserialization from map-based sources, and establishes base classes for application engines (\BaseApplicationEngine\) and their request/response handling (\BaseApplicationRequest\, \BaseApplicationResponse\). The routing system is expanded with new selectors for matching hosts and ports (\HostRouteSelector\, \LocalPortRouteSelector\) and a new \host\/\port\ DSL builder. Additionally, a new \EmbeddedServer\ interface and factory mechanism are provided to manage server lifecycle, alongside a default uncaught exception handler for better error logging.
ktor-server-core · high confidence
Introduction of the CIO HTTP client engine
The CIO client engine is now available for use, providing a new implementation for HTTP requests. It supports HTTP pipelining, WebSocket connections, and Server-Sent Events (SSE). The engine includes configuration options for connection limits, timeouts, and a custom DNS resolver. It also supports Unix domain sockets and HTTP proxying (excluding SOCKS).
ktor-client/ktor-client-cio/common · high confidence
Introduction of the CIO server engine
Adds a new CIO-based server engine to Ktor, providing an alternative to existing engines like Netty. This implementation includes the core application engine, request/response handling, and a dedicated HTTP pipeline. It supports standard TCP connectors as well as Unix domain sockets, and includes a main entry point for running the server via command-line configuration.
ktor-server/ktor-server-cio/common · high confidence
Introduction of the Ktor Events subsystem
A new eventing system has been added to Ktor, providing a generic mechanism for publishing and subscribing to typed events. The \Events\ class allows components to register handlers via \subscribe\ and trigger them using \raise\, ensuring that all registered handlers are executed in order even if some throw exceptions. A convenience function \raiseCatching\ is also provided to handle exceptions internally and log them, which is useful for decoupled error handling. This subsystem enables loose coupling between different parts of an application by allowing them to communicate through defined event definitions.
ktor-events · high confidence
Introduction of the new Ktor Server Rate Limit plugin
The \ktor-server-rate-limit\ module now provides a new rate-limiting plugin for incoming requests. This update introduces a public \RateLimiter\ interface with a \tryConsume\ method and built-in implementations (including a default token-bucket style limiter and an unlimited variant). It adds a \RateLimit\ application plugin for configuring global or named rate-limit providers and a \Route.rateLimit\ DSL function to apply these rules to specific routes, supporting nesting with authentication to access request principals.
ktor-server-rate-limit · high confidence
JVM TLS implementation now supports client certificate authentication
The JVM TLS module in \ktor-network-tls\ now allows clients to present certificates to servers during the TLS handshake. This is enabled by new configuration options in \TLSConfigBuilder\, specifically the \certificates\ list and the \addCertificateChain\ and \addKeyStore\ methods, which let you provide certificate chains and private keys. The underlying handshake logic in \TLSClientHandshake\ has been updated to handle the \CertificateRequest\ and \CertificateVerify\ messages, and the \Render\ module now includes logic to write the client certificate chain. Note that ECDSA certificates are currently not supported for client authentication; only RSA and DSA are supported.
ktor-network/ktor-network-tls/jvm · high confidence
JVM-specific I/O interoperability and platform bindings
This release adds JVM-specific implementations and extension functions to the Ktor I/O layer, enabling seamless integration with Java platform APIs. Users can now convert between Ktor's \ByteReadChannel\/\ByteWriteChannel\ and Java's \InputStream\/\OutputStream\ via \toInputStream\, \toOutputStream\, and \asByteWriteChannel\. The update also introduces interoperability with Java NIO, allowing \ReadableByteChannel\ and \ByteBuffer\ to be read from or written to Ktor channels using functions like \toByteReadChannel\, \readAvailable\, and \copyTo\. Additionally, it provides JVM-native implementations for character encoding (using \java.nio.charset\), byte order reversal, and synchronization primitives (\ReentrantLock\, \synchronized\), ensuring that Ktor's cross-platform abstractions behave correctly on the JVM.
ktor-io/jvm · high confidence
JVM-specific dependency injection implementation and function reference support
The DI plugin now includes JVM-specific implementations for dependency resolution, enabling support for function references, nullable types, and type parameter covariance. This change adds \DependencyFunctionReferenceSupport\ to allow registering dependencies via \KFunction\ references, implements \DependencyReflectionJvm\ to handle constructor and function invocation with automatic parameter resolution (including \@Named\ and \@Property\ annotations), and provides \ClasspathReference\ support for loading and injecting dependencies from the classpath. It also introduces \PluginModuleParametersInjector\ to inject application module parameters using the DI container and adds utility functions in \Types.jvm.kt\ for handling type hierarchies and nullable types.
ktor-server/ktor-server-plugins/ktor-server-di/jvm/src/io/ktor/server/plugins/di · high confidence
JVM-specific server engine and configuration implementations
This change introduces the JVM-specific implementations for the Ktor server core, including the \EmbeddedServer\ with its auto-reload and shutdown hook logic, the \HoconConfigLoader\ for parsing HOCON/JSON/properties configuration files, and the \ApplicationEnvironmentBuilder\ for setting up the server environment. It also adds JVM-specific utilities for SSL connector configuration, classloader management for auto-reloading, and static content handling such as ETag generation and date formatting.
ktor-server/ktor-server-core/jvm · high confidence
JVM-specific utility implementations for Ktor
This change introduces the JVM-specific implementations for the \ktor-utils\ module, providing platform-specific behavior for core utilities. It includes thread-safe and standard attribute maps, LRU caching, and secure nonce generation with background re-seeding. It also adds JVM-specific I/O adapters for NIO channels, file reading/writing via \RandomAccessFile\, and \InputStream\/\OutputStream\ conversions. Furthermore, it implements JVM-native compression (GZip/Deflate) and cryptographic functions (SHA-1/256, HMAC) to support content encoding and security features on the JVM target.
ktor-utils/jvm · high confidence
Jetty client engine auto-registration via ServiceLoader
The Jetty HTTP client engine is now automatically discovered and registered by the Ktor client framework on the JVM. A new ServiceLoader configuration file has been added to the resources, declaring io.ktor.client.engine.jetty.JettyEngineContainer as the implementation for HttpClientEngineContainer, allowing users to use the Jetty engine without manual configuration.
ktor-client/ktor-client-jetty/jvm/resources · high confidence
Logging plugin API stabilization with body filtering and format options
The Ktor client logging plugin now exposes a stable public API, defined by the new ABI dump files, which includes a \LoggingFormat\ enum allowing users to choose between \Default\ and \OkHttp\-style log outputs. The plugin supports configurable log levels (\ALL\, \BODY\, \HEADERS\, \INFO\, \NONE\) and provides a \LogBodyFilter\ interface, enabling custom logic to filter or sanitize request and response bodies before they are logged. Additionally, the API includes built-in logger implementations (\DEFAULT\, \SIMPLE\, \EMPTY\, \ANDROID\) and a \sanitizeHeader\ configuration method for masking sensitive header values.
ktor-client/ktor-client-plugins/ktor-client-logging · high confidence
MockEngine now supports request history tracking and WriteChannelContent conversion
The MockEngine implementation has been updated to track request history, allowing users to inspect the sequence of requests made during a test via the new \requestHistory\ property on the engine instance. Additionally, utility functions for converting \OutgoingContent\ (including \WriteChannelContent\) to byte arrays and packets have been added to \MockUtils\, ensuring that large or streamed request bodies are correctly handled during mock testing.
ktor-client/ktor-client-mock/common · high confidence
Native CIO Server support added
This change introduces support for the Native CIO server, enabling the Ktor client to operate on native platforms using the new native memory model. The diff shows the addition of SerializerInitializer files for both JS and POSIX targets, which register the KotlinxSerializer to handle JSON serialization automatically upon initialization. This ensures that the JSON serialization plugin is correctly wired up for native clients, aligning with the broader migration to the new native memory model and the renaming of Features to Plugins in the client API.
ktor-client/ktor-client-plugins/ktor-client-json/ktor-client-serialization/posix · medium confidence
Native POSIX network selector and socket utilities implementation
This change introduces the native POSIX implementation for Ktor's network selector and socket utilities, enabling Ktor to run on native platforms (such as Linux, macOS, and Android Native). It adds the core \SelectorHelper\ which manages file descriptor selection via \pselect\ and handles wake-up signals through a non-blocking pipe, ensuring robust event loop behavior. The update also includes native-specific socket address handling for IPv4, IPv6, and Unix domain sockets, along with low-level POSIX wrappers for socket operations (bind, connect, send, recv, etc.), providing the foundational networking capabilities required for non-JVM targets.
ktor-network/nix · high confidence
Native POSIX platform support for Ktor utilities
This change introduces the first-class implementation of Ktor's utility layer for POSIX-based native targets (such as iOS, macOS, and Linux). It provides native-specific implementations for core infrastructure, including thread-safe collections (ConcurrentMap, LockFreeMPSCQueue), cryptographic operations (secure random, SHA-1/256), date/time handling, and logging. It also adds native support for network address resolution, pipeline execution, and coroutine stack traces, enabling Ktor applications to run on native platforms with full access to underlying system resources.
ktor-utils/posix · high confidence
Native POSIX socket implementation for Ktor Network
This change introduces the native POSIX implementation for the Ktor network layer, enabling TCP and UDP socket communication on native platforms. It provides the core infrastructure including a SelectorManager for event-driven I/O, native socket builders for TCP and UDP, and utilities for address resolution and socket options. This implementation allows Ktor applications to perform network operations directly on native targets without relying on JVM-specific networking APIs.
ktor-network/posix · high confidence
Native Windows utility implementations for crypto, threading, and time
This change introduces platform-specific implementations for the mingwX64 target, enabling core utility functions on Windows Native. It adds secure random generation using the Windows BCrypt API, provides stub implementations for stack collection and signal handling, and implements high-precision system time retrieval via Windows FILETIME to ensure accurate millisecond timestamps.
ktor-utils/mingwX64 · high confidence
Native serialization extension provider registration
The native POSIX implementation for kotlinx serialization now exposes an internal API to register custom serialization extension providers. Users can utilize the new \addExtensionProvider\ function to inject additional providers into the serialization pipeline on native targets, enabling extensibility of the serialization behavior.
ktor-shared/ktor-serialization/ktor-serialization-kotlinx/posix · high confidence
Native stacktrace collection for Darwin platforms
Added a new Darwin-specific implementation for collecting native thread stacktraces. This change introduces \ThreadInfoDarwin.kt\, which utilizes platform-specific C APIs to capture and symbolicate stack traces, enabling better debugging and error reporting for native timeouts and crashes on macOS/iOS environments.
ktor-utils/darwin · high confidence
New API Key authentication plugin for Ktor Server
A new API Key authentication plugin has been added to Ktor Server, allowing developers to secure endpoints by validating an API key sent in a configurable HTTP header (defaulting to X-Api-Key). The implementation includes both a standard DSL extension for configuring the provider within the Authentication plugin and a new experimental, typesafe DSL that enables strongly-typed principal extraction and integration with the typesafe authentication routing API.
ktor-server/ktor-server-plugins/ktor-server-auth-api-key/common, ktor-server/ktor-server-plugins/ktor-server-auth-ldap/jvm · high confidence
New API surface for client-side request compression and response decompression
The Ktor Client Encoding plugin now exposes a public API allowing users to configure and enable compression for outgoing request bodies and decompression of incoming response bodies. This includes the \ContentEncoding\ plugin registration, a \ContentEncodingConfig\ class with a \Mode\ enum (supporting \CompressRequest\, \DecompressResponse\, and \All\), and convenience methods like \gzip()\, \deflate()\, and \identity()\. Additionally, a \compress()\ extension function is available on \HttpRequestBuilder\ for per-request control, and an \appliedDecoders\ property is exposed on \HttpResponse\ to inspect which decoders were applied.
ktor-client/ktor-client-plugins/ktor-client-encoding/api · high confidence
New BOM Remover plugin for Ktor Client
A new plugin, BOMRemover, has been added to Ktor Client to handle Byte Order Mark (BOM) removal. This feature is now available across a wide range of platforms, including Android Native, iOS, macOS, Linux, Windows, JavaScript, and WebAssembly, as indicated by the newly published KLib ABI dump.
ktor-client/ktor-client-plugins/ktor-client-bom-remover · high confidence
New CSRF protection plugin for Ktor servers
A new CSRF plugin has been added to Ktor, providing configurable mitigations for cross-site request forgery attacks. The plugin allows developers to validate requests by checking the Origin header against a list of allowed origins, ensuring the Origin matches the Host header, or verifying custom headers with specific predicates. It includes sensible defaults for local development (allowing localhost, 127.0.0.1, and 0.0.0.0) and handles failures by returning a 400 Bad Request response if the response has not yet been committed, aligning with OWASP best practices.
ktor-server/ktor-server-plugins/ktor-server-csrf/common/src/io/ktor/server/plugins/csrf · high confidence
New CallId coroutine context element and helper function
A new CallId feature has been added to the Ktor shared library, introducing a coroutine context element (KtorCallIdContextElement) and a helper function (withCallId) that allow developers to attach and propagate a unique call ID within the coroutine context. This enables better tracing and debugging of asynchronous operations by ensuring the call ID is available throughout the execution chain.
ktor-shared/ktor-call-id/common · high confidence
New CallId plugin for Ktor Client
The Ktor Client now includes a new CallId plugin, allowing users to automatically generate and attach unique identifiers to outgoing HTTP requests. This feature enables better request tracing and debugging by providing a consistent ID across client-side operations. The plugin exposes configuration options for customizing header names, generating IDs via suspend functions, and intercepting request builders.
ktor-client/ktor-client-plugins/ktor-client-call-id · high confidence
New ConditionalHeaders plugin for HTTP caching optimization
The ConditionalHeaders plugin is now available, allowing servers to optimize bandwidth by avoiding the transmission of unchanged content bodies. It supports standard HTTP caching headers, specifically Last-Modified and ETag, enabling clients to receive 304 Not Modified responses when resources have not changed since the last request. Users can configure custom version providers to define how versions are determined for specific content types, such as CSS or JavaScript files.
ktor-server/ktor-server-plugins/ktor-server-conditional-headers/common/src/io/ktor/server/plugins/conditionalheaders · high confidence
New Curl client engine for desktop platforms
A new \Curl\ HttpClient engine is now available for Kotlin/Native desktop targets, allowing users to create HTTP clients via \HttpClient(Curl)\. This engine leverages the libcurl library and introduces a dedicated \CurlProcessor\ that manages request execution and WebSocket frame handling through a single-threaded event loop backed by a task queue, ensuring non-blocking performance and proper lifecycle management of curl handles.
ktor-client-curl · high confidence
New Dependency Injection plugin for Ktor Server
This change introduces the \ktor-server-di\ plugin, providing a new dependency injection mechanism for Ktor applications. Users can now register dependencies via a Kotlin DSL (\dependencies { provide\<...\> { ... } }\) or through configuration files (\ktor.application.dependencies\). The plugin supports covariant key mapping (e.g., injecting an interface implemented by a concrete class), configurable conflict resolution policies (Default, IgnoreConflicts, OverridePrevious), and async resolution for concurrent startup modes. It also includes lifecycle management with shutdown hooks and validation of dependencies during application startup.
ktor-server-di · high confidence
New ForwardedHeaders and XForwardedHeaders plugins for reverse proxy support
This change introduces two new server plugins, ForwardedHeaders and XForwardedHeaders, which allow Ktor servers behind a reverse proxy to correctly identify the original client's host, protocol, and IP address. The ForwardedHeaders plugin parses the standard HTTP Forwarded header, while the XForwardedHeaders plugin handles the legacy X-Forwarded-\* headers (such as X-Forwarded-Host, X-Forwarded-Proto, and X-Forwarded-For). Both plugins provide configuration options to control how multiple header values are handled, including taking the first or last value, skipping a specific number of proxies, or skipping known proxy hosts.
ktor-server-forwarded-header · high confidence
New HTTP method shortcuts and request builder utilities
The client API now includes convenience extension functions for HTTP methods (GET, POST, PUT, PATCH, OPTIONS, HEAD) that accept a URL directly, alongside \prepare\*\ variants for streaming. It also introduces \basicAuth\ and \bearerAuth\ helper functions for setting authorization headers, a \cookie\ function for managing cookie headers, and utilities to set the host, port, and query parameters on request builders.
ktor-client/ktor-client-core/common/src/io/ktor/client/request · high confidence
New HTTP utility classes and functions in ktor-http/common
This change introduces a suite of new utilities in the ktor-http/common module to improve HTTP handling. It adds a CacheControl class for structured Cache-Control header management, an AsciiBitSet for efficient ASCII character membership checks, and a LinkHeader class for RFC 5988 Link headers. Additionally, it provides new extension functions for setting and parsing HTTP headers (such as ETag, Content-Type, and Cache-Control), improved URL encoding and decoding functions, and enhanced cookie date parsing that supports RFC 6265 standards.
ktor-http/common · high confidence
New JVM-specific session storage and serialization implementations
The JVM implementation of the Sessions plugin now includes new platform-specific components: a directory-based session storage (\directorySessionStorage\) that persists session data to files on disk with optional caching, a reflection-based session serializer (\reflectionSessionSerializer\) for backward-compatible serialization of session objects, and a JVM-specific cache storage implementation using soft references and timeouts. Additionally, support for deferred session fetching on public endpoints is enabled via a system property flag. These changes provide new persistence options and serialization strategies specifically for the JVM target.
ktor-server/ktor-server-plugins/ktor-server-sessions/jvm · high confidence
New Java 11 HTTP Client engine for Ktor
Users can now use the native Java 11 HTTP Client as a backend engine for Ktor on the JVM. This new engine allows sending requests and streaming request bodies using the standard JDK implementation. It also automatically configures the JDK to accept custom Host headers, removing a previous restriction where the JDK would reject user-supplied Host headers.
ktor-client-java · high confidence
New Java HTTP Client engine based on JDK HttpClient
This change introduces a new \JavaHttpEngine\ for the Ktor client, built on top of the Java 11+ \java.net.http.HttpClient\. It enables HTTP/2 by default, supports WebSockets and Server-Sent Events (SSE), and allows custom configuration of the underlying JDK client via a \config\ block. The engine also handles proxy settings, respects request and connect timeouts, and correctly filters or delegates HTTP headers according to JDK restrictions.
ktor-client/ktor-client-java/jvm · high confidence
New Jetty Jakarta server engine implementation
This change introduces a new \JettyApplicationEngineBase\ and supporting classes for the \ktor-server-jetty-jakarta\ module, enabling Ktor applications to run on Jetty 12 with Jakarta EE namespaces. The implementation provides a standalone engine that initializes a Jetty \Server\ with configurable \HttpConfiguration\ and \SecureRequestCustomizer\ settings, allowing users to adjust TLS options like SNI host validation. It also includes a new WebSocket connection handler (\JettyWebsocketConnection\) that manages input and output channels for upgraded connections, and an internal \EndPointChannels\ utility to bridge Jetty's I/O endpoints with Ktor's coroutine-based channels.
ktor-server-jetty-jakarta, ktor-server/ktor-server-servlet-jakarta/jvm · high confidence
New KDoc annotator tool for adding feedback links to documentation
A new build-logic module, \kdoc-annotator\, has been added to automatically manage feedback links in KDoc comments. This tool scans Kotlin source files to add a 'Report a problem' link to public API documentation, removes existing links from test sources, and handles path exclusions to avoid scanning generated or build directories. It includes integration and unit tests to verify correct behavior for single-line and multi-line KDoc, handling of KDoc tags, and path pattern matching.
build-logic/kdoc-annotator, kdoc-annotator · high confidence
New Ktor Client Resources plugin for type-safe URL construction
A new \ktor-client-resources\ plugin has been added, enabling type-safe request building using the \@Resource\ annotation. Users can now define resource classes with path templates and generate URLs directly via the new \HttpClient.href()\ extension functions, simplifying the creation of typed HTTP requests without manual string concatenation.
ktor-client-resources · high confidence
New Ktor Client Tracing plugin for HTTP and WebSocket request monitoring
The Ktor client now includes a new tracing plugin that allows you to monitor and log the lifecycle of HTTP requests and WebSocket connections. By wrapping the HTTP client engine, this plugin intercepts key events—such as request initiation, response header receipt, body processing, and failures—and exposes them through a customizable \Tracer\ interface. It also provides detailed tracing for WebSocket sessions, capturing frame sends and receives, enabling developers to integrate with external observability tools or debug network behavior more effectively.
ktor-client/ktor-client-plugins/ktor-client-tracing/common · high confidence
New MicrometerMetrics plugin for Ktor server
Introduces the MicrometerMetrics plugin, allowing users to integrate Micrometer-based monitoring into Ktor applications. Users can configure the metric name prefix, specify a custom MeterRegistry (such as Prometheus), and enable JVM metrics like memory, GC, and thread usage. The plugin supports configuring histogram and percentile distributions for request timers, applying filters to exclude specific calls from metrics collection, and customizing route label strings.
ktor-server-metrics-micrometer · high confidence
New MockEngine implementation with request history and thread-safe handler execution
The ktor-client-mock module now provides a new MockEngine implementation that allows tests to run without network calls. This engine tracks a history of executed requests and responses via the new \requestHistory\ and \responseHistory\ properties, enabling verification of call sequences. It introduces thread-safe execution of request handlers using synchronized blocks and supports configurable handler reuse through the \MockEngineConfig\. A new \Queue\ inner class facilitates building mock responses incrementally by appending handlers, and the engine correctly propagates coroutine context during handler execution.
ktor-client-mock · high confidence
New OpenAPI plugin for generating static documentation UI
The \ktor-server-openapi\ plugin is introduced, allowing developers to serve generated OpenAPI documentation UI (via Swagger Codegen) at a specified path. It supports loading specifications from files or routing definitions, with a default output directory of \docs\. The plugin includes a warning for OpenAPI 3.1.x specifications, as the underlying HTML generator officially supports 3.0.x, and recommends using the separate \swaggerUI\ plugin for 3.1 specs.
ktor-server/ktor-server-plugins/ktor-server-openapi/jvm/src/io/ktor/server/plugins/openapi · high confidence
New OpenAPI runtime API for route description and security scheme registration
This change introduces a new runtime API in the \ktor-server-routing-openapi\ plugin, allowing developers to explicitly describe OpenAPI operations and manage security schemes at the route level. Users can now use the \Route.describe\ function to configure operation metadata and \Route.hide\ to exclude routes from documentation. Additionally, the \Application\ object gains \registerSecurityScheme\ (along with convenience methods like \registerBasicAuthSecurityScheme\ and \registerJWTSecurityScheme\) to define security schemes, which are automatically inferred from installed authentication providers (Basic, Bearer, Session, API Key, OAuth2, JWT, Digest) and merged into the generated OpenAPI specification. The API also includes \OpenApiDoc.plus\ operators to combine route information and security schemes into the final document.
ktor-server/ktor-server-plugins/ktor-server-routing-openapi/common · high confidence
New OpenAPI schema data model and serialization infrastructure
The \ktor-openapi-schema\ module now includes a comprehensive set of new data classes and serialization utilities to represent OpenAPI 3.1.1 structures, including \JsonSchema\, \Operation\, \MediaType\, \Encoding\, \ExampleObject\, \ExternalDocs\, and \OpenApiDoc\. This change introduces a robust serialization framework featuring \GenericElement\ for deferred JSON/YAML deserialization, custom serializers for \ContentType\ and \AdditionalProperties\, and \DelegateMixinSerializer\ classes to handle OpenAPI extension properties (x- fields) during serialization and deserialization.
ktor-openapi-schema · high confidence
New OpenApiDocSource API for flexible OpenAPI document generation
The \ktor-server-routing-openapi\ plugin introduces a new \OpenApiDocSource\ sealed interface that allows users to configure how the OpenAPI specification is generated. This API supports multiple sources: static text, file-based documents, and dynamic generation from the application's routing tree. The routing-based source provides fine-grained control, allowing users to customize JSON schema inference strategies, define security schemes, select specific routes to include, and choose serialization formats (JSON or YAML). This enables more flexible and customizable OpenAPI documentation within Ktor applications.
ktor-server-routing-openapi · high confidence
New OpenID Connect plugin for Ktor server
This change introduces the \Oidc\ plugin, a first-class OpenID Connect implementation for Ktor server authentication. It supports the Authorization Code Flow with PKCE for user login (with optional session management) and resource-server Bearer authentication via locally verified JWTs or RFC 7662 token introspection. The plugin automatically handles provider metadata discovery and periodic refresh, and includes utilities for secure state cookie encryption and token refresh responses.
ktor-server-auth-oidc · high confidence
New RequestBodyLimit plugin for enforcing incoming request size constraints
A new RequestBodyLimit plugin has been introduced, allowing developers to configure and enforce maximum limits on the size of incoming request bodies. The plugin operates by checking the Content-Length header against the configured limit before processing and actively monitoring the byte stream during reception to throw a PayloadTooLargeException if the limit is exceeded, thereby preventing potential issues with excessively large payloads.
ktor-server/ktor-server-plugins/ktor-server-body-limit/common/src/io/ktor/server/plugins/bodylimit · high confidence
New ResourcesFormat serialization class for Ktor Resources
The Ktor Resources plugin now includes a new \ResourcesFormat\ class in the \io.ktor.resources.serialization\ package. This class provides methods to serialize resource instances into path patterns, query parameters, and generic parameters, as well as to deserialize resources from parameters. It serves as the core serialization format for converting between Ktor Resource objects and HTTP query/path representations.
ktor-resources · high confidence
New TLS cipher suite and algorithm definitions for Ktor Network
The ktor-network-tls module now includes explicit definitions for TLS cipher suites, hash algorithms, and signature algorithms. Users can now access a standardized list of supported cipher suites (including ECDHE and RSA variants with AES-GCM and AES-CBC) via the new CIOCipherSuites object, and the underlying TLS handshake logic utilizes these definitions to negotiate secure connections using specific hash and signature algorithm pairs like SHA256withRSA or SHA384withECDSA.
ktor-network-tls · high confidence
New call manipulation and caching APIs for HttpClientCall
The client call API now includes a \replaceResponse\ extension function that allows you to substitute the response headers and content of an existing \HttpClientCall\, enabling use cases like response decompression or header modification without re-fetching data. Additionally, a new \save\ function caches the entire response body in memory, returning a new \HttpClientCall\ that releases the original network connection and allows the content to be read multiple times safely. These changes are supported by new internal delegation classes (\DelegatedCall\, \SavedHttpCall\) and updated core call handling logic in \HttpClientCall\.
ktor-client/ktor-client-core/common/src/io/ktor/client/call · high confidence
New client plugins API with hook-based extension points
This change introduces a new \io.ktor.client.plugins.api\ package that provides a modern, hook-based API for building HttpClient plugins. It replaces the older plugin model with \ClientPlugin\, \ClientPluginBuilder\, and \ClientHook\ interfaces, allowing developers to create plugins using the \createClientPlugin\ factory function. The new API exposes specific extension points via \onRequest\, \onResponse\, \transformRequestBody\, and \transformResponseBody\ methods, which intercept the client's request and response pipelines at precise stages (State, Transform) to modify requests, inspect responses, or transform body content.
ktor-client/ktor-client-core/common/src/io/ktor/client/plugins/api · high confidence
New common server application core API
The \ktor-server-core/common\ module now provides the foundational API for the Ktor server application lifecycle, including the \Application\ class, \ServerConfig\ builder, and the \ApplicationCallPipeline\ with its standard phases (Setup, Monitoring, Plugins, Validators, Call, Fallback). This change introduces the common plugin system (\Plugin\, \ApplicationPlugin\, \RouteScopedPlugin\) and the \PluginBuilder\ DSL for intercepting calls (\onCall\, \onCallReceive\, \onCallRespond\). It also adds convenience extensions for accessing the server's configured \port\ and \host\ from \ApplicationConfig\, and defines the core event definitions for application startup and shutdown.
ktor-server/ktor-server-core/common · high confidence
New experimental JSON converter and Flow/Sequence serialization support
This change introduces an experimental \jsonIo\ extension for the ContentNegotiation plugin that uses a new \ExperimentalJsonConverter\ backed by kotlinx-io for more efficient, replayable JSON streaming. It also adds support for serializing \kotlinx.coroutines.flow.Flow\<T\>\ as JSON arrays and deserializing JSON arrays into \Sequence\<T\>\, enabling lazy, stream-based processing of large JSON collections.
ktor-shared/ktor-serialization/ktor-serialization-kotlinx/ktor-serialization-kotlinx-json/common · high confidence
New form submission and preparation APIs for HTTP requests
This change introduces a new \formBuilders.kt\ file in the Ktor client core module, providing convenient extension functions for \HttpClient\ to handle form data. Users can now use \submitForm\ and \prepareForm\ to send \x-www-form-urlencoded\ parameters (optionally encoded in the query string for GET requests), as well as \submitFormWithBinaryData\ and \prepareFormWithBinaryData\ to send \multipart/form-data\ payloads, simplifying the creation of form-based HTTP requests.
ktor-client/ktor-client-core/common/src/io/ktor/client/request/forms · high confidence
New internal utility functions and event definitions for Ktor client
This change introduces several new internal utilities and event definitions within the Ktor client core. It adds \ByteChannelUtils.observable\ to enable download progress tracking by wrapping a byte channel with a listener, and defines a set of client lifecycle events (\HttpRequestCreated\, \HttpRequestIsReadyForSending\, \HttpResponseReceived\, \HttpResponseReceiveFailed\, \HttpResponseCancelled\) to allow users to observe request and response states. Additionally, it provides helper functions for managing HTTP headers (\dropCompressionHeaders\, \buildHeaders\), constants for the HTTP connection pool (\DEFAULT\_HTTP\_POOL\_SIZE\, \DEFAULT\_HTTP\_BUFFER\_SIZE\), and utility functions for coroutine dispatchers and exception unwrapping. These additions support enhanced observability, progress reporting, and internal header management for HTTP clients.
ktor-client/ktor-client-core/common/src/io/ktor/client/utils · high confidence
New public API surface for HTTP header and content handling
The ktor-http module now exposes a stabilized public API for core HTTP constructs, including the ContentDisposition, ContentType, Cookie, and HeaderValueWithParameters classes, along with comprehensive parsing and rendering utilities for headers and cookies. This change introduces new constants for standard MIME types (such as application/problem+json, wasm, and yaml) and provides robust, RFC-compliant handling for Content-Disposition (including filename\* encoding), Cache-Control directives, and cookie encoding strategies, enabling developers to construct and parse HTTP messages with greater type safety and consistency.
ktor-http · high confidence
New public APIs for Call ID, Zstd encoding, Events, and HTMX attributes
This release introduces stable public APIs for several shared components. The Call ID module now exposes \withCallId\ and \KtorCallIdContextElement\ for managing request identifiers in coroutine contexts. Zstd encoding is available via \Zstd\ and \ZstdEncoder\ classes for streaming compression and decompression. The Events module provides \Events\ and \EventDefinition\ for generic event handling, including \raiseCatching\. Finally, the HTMX module exposes comprehensive constants for attributes, CSS classes, events, and request/response headers, along with a DSL extension \hx\ for building HTML attributes in kotlinx.html, enabling seamless integration of HTMX features in server-side generated content.
ktor-shared · high confidence
New server plugins and HTML template utilities
This release introduces several new server-side capabilities: the AutoHeadResponse plugin automatically handles HEAD requests by reusing GET route logic; the HSTS plugin enforces Strict-Transport-Security headers with support for host-specific configurations, preload directives, and custom directives; the XHttpMethodOverride plugin allows tunneling HTTP verbs via the X-HTTP-Method-Override header to work around client limitations; and the RequestValidation plugin provides a flexible system for validating request bodies using custom validators or type-specific blocks, including an optional content-length check. Additionally, the HTML builder module adds Template, Placeholder, and PlaceholderList classes to enable structured, composable HTML generation with nested layouts and list rendering.
(repo-wide) · high confidence
New server plugins for caching headers and type-safe resource routing
This change introduces two new server plugins. The Caching Headers plugin allows configuring Cache-Control and Expires headers via a configurable options provider, automatically merging multiple directives according to RFC rules. The Resources plugin provides type-safe routing support, enabling developers to define routes using annotated resource classes and handle requests with typed parameters for HTTP methods like GET, POST, PUT, DELETE, and PATCH.
ktor-server-resources, ktor-server/ktor-server-plugins/ktor-server-caching-headers/common/src/io/ktor/server/plugins/cachingheaders, ktor-server/ktor-server-plugins/ktor-server-resources/common · high confidence
New server testing API with test client engine and external service mocking
The \ktor-server-test-host\ module introduces a new testing API that allows users to spin up a local test server and interact with it using a built-in \TestHttpClientEngine\. This engine bridges HTTP requests directly to the server's internal call handling, supporting features like HTTP timeouts and, on JVM targets, WebSocket upgrades. The new API also provides an \ExternalServicesBuilder\ to register mock external services by host, enabling tests to isolate the application under test from real external dependencies.
ktor-server-test-host · high confidence
New standalone Jetty Jakarta engine implementation
This location introduces a new standalone Jetty Jakarta engine implementation for Ktor, including the \Jetty\ application engine factory, \JettyApplicationEngine\, and \EngineMain\ for command-line execution. The implementation provides a complete request handling pipeline via \JettyKtorHandler\, \JettyApplicationCall\, and dedicated request/response body readers and writers, along with server initialization logic for HTTP/HTTPS connectors and WebSocket upgrade support.
ktor-server/ktor-server-jetty-jakarta/jvm · high confidence
New typed Digest authentication API with RFC 7616 support
The JVM auth plugin now includes a new, type-safe DSL for Digest authentication (\digest\<P\>\) that supports multiple hash algorithms (MD5, SHA-256, SHA-512-256), Quality of Protection (qop) options like \auth\ and \auth-int\, and user hash privacy features. This typed API allows developers to define a specific principal type for the authentication scheme, providing better compile-time safety compared to the previous untyped provider. The implementation also introduces a new \DigestCredential\ class and a \DigestAuthenticationProvider\ that handles the full RFC 7616 challenge-response flow, including nonce management and body hashing for \auth-int\.
ktor-server/ktor-server-plugins/ktor-server-auth/jvm · high confidence
OkHttp engine factory and container implementation for JVM/Android
The OkHttp client engine for JVM and Android platforms is now implemented with a public \OkHttp\ factory object and an \OkHttpEngineContainer\. Users can instantiate the HTTP client using \HttpClient(OkHttp)\ and configure it via the \engine\ block with \OkHttpConfig\. The engine supports Android 5.0 and newer, and includes a feedback link for reporting issues directly from the KDoc.
ktor-client-okhttp · high confidence
Out-of-the-box Protobuf content conversion support
Users can now easily enable Protocol Buffers serialization in Ktor by calling the new \protobuf()\ extension function on the \ContentNegotiation\ configuration. This function registers the \application/protobuf\ content type and uses a default \ProtoBuf\ instance that preserves default values during serialization, removing the need for manual setup of the converter.
ktor-shared/ktor-serialization/ktor-serialization-kotlinx/ktor-serialization-kotlinx-protobuf/common · high confidence
POSIX JSON plugin implementation for Ktor Client
The POSIX target for the Ktor Client JSON plugin is now implemented, providing the platform-specific default serializer and configuration. Users on POSIX platforms (including Native) will now have access to the JSON client plugin with a default serializer that utilizes the first available serializer in the registry, and a configuration for ignored types that is currently empty by default.
ktor-client/ktor-client-plugins/ktor-client-json/posix/src/io/ktor/client/plugins/json · high confidence
Placeholder directories added for Ktor Client Resources plugin
Empty placeholder directories (\.gitkeep\) have been added for the \ktor-client-resources\ plugin in the JS, JVM, and POSIX target modules. This establishes the module structure for the new locations feature but does not yet include any functional implementation or code changes for users.
ktor-client/ktor-client-plugins/ktor-client-resources/js, ktor-client/ktor-client-plugins/ktor-client-resources/jvm, ktor-client/ktor-client-plugins/ktor-client-resources/posix · medium confidence
Reflection-based JSON schema inference for OpenAPI
This change introduces a new JVM-specific reflection engine for inferring OpenAPI JSON schemas from Kotlin types. It provides the \SchemaReflectionAdapter\ interface and \ReflectionJsonSchemaInference\ class, allowing the framework to automatically generate schema definitions by inspecting Kotlin classes, properties, and annotations at runtime. This enables seamless integration with serialization frameworks on the JVM by supporting features like value classes, sealed types, and custom discriminator properties through the adapter.
ktor-shared/ktor-openapi-schema/ktor-openapi-schema-reflect/jvm · high confidence
Repository development environment and contributor guidelines established
The repository now includes foundational configuration and documentation files to standardize the development experience. A \.editorconfig\ file enforces consistent code formatting (UTF-8, LF line endings, 4-space indentation for Kotlin, 2-space for JSON/YAML) and integrates ktlint rules. A \.gitpod.yml\ file enables instant cloud-based development environments with preconfigured tasks to install dependencies and build the project. New documentation files \AGENTS.md\ and \AI\_POLICY.md\ provide guidelines for contributors, including build commands, code style expectations, ABI validation procedures, and policies for using AI-assisted coding tools. Additionally, standard repository files like \.gitignore\, \.gitattributes\, \CODE\_OF\_CONDUCT.md\, and \CONTRIBUTING.md\ have been added or updated to support community contributions.
(repo-wide) · high confidence
SSE plugin adds optional serialization and heartbeat support
The SSE server plugin now supports sending serialized objects instead of plain strings, configurable via a new \serialize\ parameter in \SSEServerContent\. Additionally, the implementation includes logic to manage a heartbeat job, ensuring connections remain active. These changes enhance the plugin's capability to handle complex data types and maintain stable client connections.
ktor-server-sse · high confidence
Server-Sent Events (SSE) plugin introduces serialization support and heartbeat capabilities
The Ktor SSE plugin now supports sending typed data objects by automatically serializing them into the SSE \data\ field via a provided serializer function, allowing developers to send complex types like JSON without manual string conversion. Additionally, a built-in heartbeat mechanism has been added to the \ServerSSESession\, enabling automatic periodic event transmission to keep connections alive or send dynamic status updates, configurable with a custom period, static event, or a dynamic event provider.
ktor-server/ktor-server-plugins/ktor-server-sse/common · high confidence
Support for Blob-based multipart form data in Ktor Client for JS and Wasm
Ktor Client now supports sending Blob objects as part of multipart form data on Kotlin/JS and Kotlin/Wasm platforms. This change introduces platform-specific implementations of the \blobChannelProvider\ function, enabling the conversion of JavaScript/Wasm Blob instances into byte streams for HTTP requests. Users can now include binary data represented as Blobs in their form submissions on these targets.
ktor-client/ktor-client-core/js/src/io/ktor/client/request, ktor-client/ktor-client-core/wasmJs/src/io/ktor/client/request · high confidence
Support for client-side request body compression
The Ktor client now supports compressing request bodies (e.g., using GZip or Deflate) before sending them to the server, in addition to the existing capability to decompress response bodies. This change introduces the \ContentEncoding\ plugin configuration with a new \Mode.All\ option that enables compression for outgoing requests, allowing users to reduce bandwidth usage for large payloads. A new JVM-specific implementation ensures that content encoding headers are handled correctly during this process.
ktor-client/ktor-client-plugins/ktor-client-encoding/jvm · high confidence
Tracing plugin API and test infrastructure added
The Ktor client tracing module now exposes a public API defining the Tracer interface and the TracingWrapper engine factory, enabling users to instrument HTTP and WebSocket requests with custom tracing logic. This change also introduces a TestTracer implementation and comprehensive unit tests (TracingWrapperTest) to verify that request, response, and WebSocket frame events are correctly captured and reported by the tracer.
ktor-client/ktor-client-plugins/ktor-client-tracing · high confidence
Typesafe Authentication DSL and Session Authentication Scheme
The \ktor-server-auth\ module introduces a typesafe Authentication DSL and a typed Session Authentication Scheme. This includes new core classes like \AuthenticationConfig\, \AuthenticationProvider\, and \AuthenticationFailedCause\ to structure authentication logic, alongside a new \SessionAuthenticationScheme\ that automatically configures session transports (cookie, header, etc.) and integrates with CSRF protection. The update also adds convenience types such as \UserIdPrincipal\, \UserPasswordCredential\, and \UserHashedTableAuth\ to simplify common authentication patterns.
ktor-server-auth · high confidence
Unix domain socket support for WatchOS
WatchOS applications can now use Unix domain sockets for local networking. This change adds the necessary platform-specific socket packing and unpacking utilities to the WatchOS target, enabling native code to correctly handle Unix socket paths on watchOS devices.
ktor-network/watchos · high confidence
Velocity templating plugin for Ktor server
The Ktor server now includes a Velocity plugin that allows you to render Apache Velocity templates as views. This addition provides a \VelocityContent\ class and a \respondTemplate\ extension function, enabling developers to easily return HTML responses generated from Velocity templates with support for model data, custom content types, and ETags. A separate \VelocityTools\ plugin is also introduced to configure and inject standard or custom Velocity tools into the rendering engine.
ktor-server/ktor-server-plugins/ktor-server-velocity/jvm · high confidence
WasmJs support added to Ktor client JSON serialization
This change adds initial support for the WasmJs target to the Ktor client's JSON serialization plugin. It introduces a \SerializerInitializer\ that registers the \KotlinxSerializer\ for eager initialization on WasmJs, and provides a \JsonExtensionsWasm\ implementation that currently returns \null\ for \deserializeSequence\, indicating that sequence-based deserialization is not yet supported on this platform.
ktor-client/ktor-client-plugins/ktor-client-json/ktor-client-serialization/wasmJs, ktor-client/ktor-client-plugins/ktor-client-resources/wasmJs, ktor-shared/ktor-serialization/ktor-serialization-kotlinx/ktor-serialization-kotlinx-json/wasmJs · high confidence
WebRTC client support for JVM
The WebRTC client is now available on the JVM platform. This change introduces the JVM-specific implementation layer, including utility functions to map internal WebRTC types to the underlying Java WebRTC library (dev.onvoid.webrtc) and test infrastructure with mock audio and video factories to enable testing on the JVM.
ktor-client/ktor-client-webrtc/jvm · high confidence
WebSocket session tracing support added
The ktor-client-tracing module now includes a WebSocketSessionTracer that wraps the underlying WebSocket session to intercept and trace incoming and outgoing data channels, enabling distributed tracing for WebSocket connections.
ktor-client-tracing · high confidence
YAML configuration now supports variable expansion and environment variable substitution
The YAML configuration loader now allows properties to reference environment variables using \$ENV\_VAR\, \${ENV\_VAR}\, or \"$ENV\_VAR:default\_value"\ syntax, with literal dollar signs escapable via \$$\. It also supports resolving internal configuration references (e.g., \${other.key}\) within YAML values, ensuring references are resolved only once to prevent infinite loops. This enables dynamic configuration based on the runtime environment and internal config structure.
ktor-server/ktor-server-config-yaml/jvmAndPosix · high confidence
Zstandard compression support added to Ktor Server
The Zstandard (zstd) compression algorithm is now available as a standalone plugin for Ktor Server. Users can enable zstd encoding via the \CompressionConfig.zstd()\ function, which allows configuring the compression level, or use \CompressionConfig.zstdStandard()\ to enable zstd alongside gzip, deflate, and identity encoders. This change introduces the \ZstdEncoder\ integration within the \io.ktor.server.plugins.compression.zstd\ package.
ktor-server/ktor-server-plugins/ktor-server-compression/ktor-server-compression-zstd/jvm/src/io/ktor/server/plugins/compression · high confidence
iOS WebRTC media capture and track implementation
The iOS implementation for the WebRTC client now includes native support for media devices and tracks. This change introduces \IosMediaDevices\ to handle the creation of audio and video tracks using the iOS WebRTC framework, including SSL initialization and platform-specific constraints (e.g., echo cancellation, auto gain control). It also adds \IosAudioTrack\ and \IosVideoTrack\ classes to wrap native \RTCMediaStreamTrack\ objects, providing a unified API for track management, state, and resource cleanup on iOS.
ktor-client/ktor-client-webrtc/ios/src/io/ktor/client/webrtc/media · high confidence
iOS-specific video capture implementations for WebRTC client
The Ktor WebRTC client now includes platform-specific implementations for video capture on iOS devices. On physical iOS devices (arm64), the client uses the device camera via \CameraVideoCapturer\, while on iOS simulators (arm64 and x64), it falls back to \SimulatorVideoCapturer\. This ensures that video capture functionality works correctly across different iOS runtimes and hardware configurations.
ktor-client/ktor-client-webrtc/iosArm64, ktor-client/ktor-client-webrtc/iosSimulatorArm64, ktor-client/ktor-client-webrtc/iosX64 · high confidence
Removals
Removal of legacy Ktor core hosting, routing, and configuration APIs
The \ktor-core\ module has removed its entire legacy application hosting, routing, and configuration subsystem. This includes the deletion of the \Config\ interface and its implementations (\ContextConfig\, \MemoryConfig\), the \Application\ and \ApplicationConfig\ classes, and the \ApplicationLoader\ which previously handled development-mode file watching and class loading. The old routing engine, defined by \RoutingEntry\, \RoutingBuilder\, and various \RoutingSelector\ types, has been removed, along with supporting HTTP utilities like \HttpStatusCode\, \ContentType\, and \ApplicationRequest\/\ApplicationResponse\ traits. This change eliminates the previous manual interceptor-based request handling and path-matching logic in favor of the framework's new architecture.
ktor-core · high confidence
Removal of legacy Servlet integration components
The \ktor-servlet\ module has removed its legacy servlet hosting implementation, specifically deleting the \ServletApplicationHost\ and \ServletApplicationRequest\ source files along with the module's IntelliJ IDEA configuration file. This eliminates the manual servlet container wiring and request/response mapping that previously allowed Ktor applications to run directly within a Java EE servlet container.
ktor-servlet · high confidence
Removed legacy Jetty hosting implementation
The \ktor-jetty\ module has removed its previous Jetty server hosting and routing implementation, specifically deleting the \JettyApplicationHost\ class and the \CommandLine\ entry point. This eliminates the manual Jetty server setup, session management, and resource handling logic that was previously contained in this location.
ktor-jetty · high confidence
API
Android WebRTC client API surface defined
The public API for the Android WebRTC client is now established, exposing classes for managing peer connections, media tracks (audio/video), RTP senders, and data channels. This includes specific Android implementations like \AndroidWebRtcEngine\ and \AndroidWebRtcPeerConnection\, along with utility extensions to access native WebRTC objects via \getNative\ methods for data channels, peer connections, and senders.
ktor-client/ktor-client-webrtc/api/android · high confidence
Apache HTTP client engine API surface published
The public API for the Apache-based HTTP client engine is now defined and validated. This includes the \Apache\ engine factory singleton, the \ApacheEngineConfig\ configuration class (exposing settings for timeouts, SSL context, redirects, and custom client/request customization), and the \ApacheEngineContainer\ for engine registration. This change establishes the binary compatibility baseline for the Apache engine module.
ktor-client/ktor-client-apache/api · high confidence
Established binary compatibility API for the Jetty HTTP client engine
The Jetty client engine now has a defined public API surface, exposing the \Jetty\ engine factory, \JettyEngineConfig\ for configuration (including client cache size and SSL context settings), and the \JettyEngineContainer\ for engine registration. This change formalizes the binary compatibility contract for the Jetty engine, ensuring stable interfaces for users integrating this specific HTTP client implementation.
ktor-client/ktor-client-jetty/api · high confidence
Ktor Client Core public API dump introduced
The public API surface for ktor-client-core is now explicitly defined and version-controlled via new ABI dump files (ktor-client-core.api and ktor-client-core.klib.api). This establishes a formal contract for the core client module, covering the HttpClient, engine interfaces, plugin system, and key classes like SSESession and CacheStorage, ensuring binary compatibility is enforced for all platforms.
ktor-client/ktor-client-core/api · high confidence
OkHttp engine public API exposed for configuration and extension
The OkHttp client engine now exposes its public API surface, allowing users to configure the underlying OkHttp client via \OkHttpConfig\. This includes methods to add interceptors, set a custom DNS resolver, enable duplex streaming, provide a preconfigured OkHttp client instance, and specify a WebSocket factory. The engine also exposes its supported capabilities and coroutine context.
ktor-client/ktor-client-okhttp/api · high confidence
Public API surface for Ktor Client Resources plugin published
The public API for the \ktor-client-resources\ plugin is now explicitly defined and published, exposing the \Resources\ plugin installation, the \RESOURCE\ attribute key, and extension functions on \HttpClient\ for building requests (such as \get\, \post\, \put\, \delete\, \href\, and their \prepare\ variants) using resource classes. This change establishes the stable contract for the KLib ABI across all supported targets (including Android Native, iOS, JS, and JVM), ensuring that consumers can reliably access the resources feature's entry points.
ktor-client/ktor-client-plugins/ktor-client-resources/api · high confidence
WebRTC Client JVM API stabilization and data channel support
The JVM API for the Ktor WebRTC client has been updated to expose the public interface for data channels, including event handling (Open, Closed, Error, etc.) and configuration options like buffer overflow policies. The entry point for creating WebRTC engines on the JVM is now explicitly defined via \JvmWebRtc\, and the API surface includes concrete implementations for peer connections, data channels, and media tracks, providing a stable contract for JVM-based WebRTC integration.
ktor-client/ktor-client-webrtc/api/jvm · high confidence
Architecture
Migrate Ktor compiler plugin to the Ktor organization
The Ktor compiler plugin has been migrated from its previous location into the Ktor organization, reorganizing the source code under the \io.ktor.compiler\ package. This change introduces the standard Kotlin compiler plugin service descriptors (\CommandLineProcessor\ and \CompilerPluginRegistrar\) and registers the OpenAPI generation extensions (FIR analysis and IR code generation) as part of the main Ktor codebase, ensuring the plugin is now maintained and versioned alongside the rest of the Ktor framework.
ktor-compiler-plugin · high confidence
Migrate build logic from buildSrc to isolated composite build
The project's shared build configuration has been moved from the legacy \buildSrc\ directory to a new \build-logic\ module, which is included as a composite build in the root \settings.gradle.kts\. This change replaces the previous build source structure with isolated projects, improving build stability and preventing stale state issues. The new module includes precompiled script plugins for base configuration, code style (Kotlinter), Dokka generation, Kotlin Multiplatform setup, publishing, and optional Android/CocoaPods support, along with internal services for project tagging, version resolution, and dependency constraint management.
build-logic · high confidence
ktor-test-server moved to a separate included build
The internal test server used for Ktor's integration tests has been extracted into its own standalone Gradle module (ktor-test-server). This change isolates the test infrastructure, providing a dedicated build service to manage the server lifecycle and a configurable verbose mode for logging exceptions, while exposing the standard test endpoints (auth, caching, websockets, etc.) required by the client and server test suites.
ktor-test-server · high confidence
Behavioural changes
Add W3C Fetch API type definitions for Ktor JS client
The Ktor HTTP client for JavaScript now includes explicit Kotlin/JS external type definitions for the W3C Fetch API (LibDom.kt) and ES5 standard library types (LibEs5.kt). This change provides strongly-typed interfaces for core web APIs such as Request, Response, Headers, Body, and various Stream types, replacing previous reliance on dynamic types or standard library fetch APIs to improve type safety and integration with the browser's native networking capabilities.
ktor-client/ktor-client-core/js/src/io/ktor/client/fetch · high confidence
Add WASM-JS specific JavaScript utility functions
A new utility file for the WASM-JS target provides internal helper functions for JavaScript interop, including object creation, property access, and byte array conversions. It also introduces a specific implementation for converting Event objects to strings by serializing key properties (message, target, type, isTrusted) via JSON, ensuring consistent event handling behavior on this platform.
ktor-client/ktor-client-core/wasmJs/src/io/ktor/client/utils · high confidence
Add stub files to server modules for multiplatform support
Empty stub files have been added to the common source sets of the ktor-server, ktor-server-host-common, and ktor-server-tests modules. These stubs serve as placeholders to satisfy the build system's requirements for common code in these modules, likely facilitating the support for additional targets like JS and WasmJS as indicated by the commit context.
ktor-server/common, ktor-server/ktor-server-host-common/common, ktor-server/ktor-server-tests/common · medium confidence
Added KLib ABI dump and Darwin placeholder for Ktor Client iOS
The Ktor Client iOS module now includes an explicit KLib ABI dump file (ktor-client-ios.klib.api) covering all Apple platforms (iOS, macOS, tvOS, watchOS) to support ABI validation, alongside a new darwin directory placeholder to structure the native implementation.
ktor-client/ktor-client-ios · high confidence
Android WebRTC client adds strict type conversion utilities
The Android implementation of the Ktor WebRTC client now includes a new utility file that strictly maps internal WebRTC types to native Android WebRTC objects. This change ensures that session descriptions, bundle policies, ICE transport policies, connection states, and data channel messages are converted with explicit type safety, reducing the risk of runtime errors during signaling and media handling.
ktor-client/ktor-client-webrtc/android · high confidence
Apache HTTP client engine deprecated in favor of Apache 5
The existing Apache HTTP client engine for the JVM is now deprecated and displays a warning when used. Users are advised to migrate to the Apache 5 engine (io.ktor.client.engine.apache5.Apache5) to avoid deprecation warnings and ensure continued support.
ktor-client-apache · high confidence
Apache HTTP client engine registration for JVM
The Apache HTTP client engine is now explicitly registered for the JVM target via a service provider configuration file. This ensures that the Apache engine container is discoverable by the Ktor client framework on JVM platforms, enabling users to utilize the Apache engine implementation.
ktor-client/jvm, ktor-client/ktor-client-apache/jvm/resources · high confidence
Auth plugin API stabilization with configurable refresh and token clearing
The Ktor Client Auth plugin exposes a stable public API (ABI) that allows users to configure authentication providers (Basic, Bearer, Digest) with greater control. Bearer authentication now supports a \nonCancellableRefresh\ option to prevent refresh requests from being cancelled, and the \refreshTokens\ callback receives a \RefreshTokensParams\ object containing the HTTP client, the original response, and the old tokens, enabling more robust token renewal logic. Additionally, users can now explicitly clear stored authentication tokens via \clearAuthTokens\ on the HTTP client or \clearToken\ on individual providers, and configure custom logic to determine which responses trigger re-authorization.
ktor-client/ktor-client-plugins/ktor-client-auth · high confidence
Auth plugin re-architecture with configurable re-auth triggers and single-provider simplification
The Auth plugin has been refactored to support more flexible authentication flows. Users can now customize which HTTP responses trigger re-authentication via the new \reAuthorizeOnResponse\ configuration, moving beyond the default 401 check. The logic for selecting an authentication provider has been simplified: when only a single \AuthProvider\ is configured, it is used automatically without requiring a \WWW-Authenticate\ header in the response. Additionally, the plugin now includes logic to prevent infinite loops during token refresh cycles and ensures that fresh tokens are used when available, improving reliability for long-lived sessions.
ktor-client/ktor-client-plugins/ktor-client-auth/common/src/io/ktor/client/plugins/auth · high confidence
Automatic segment pool configuration for Android to improve I/O performance
On Android devices with sufficient memory, the Ktor client now automatically configures the kotlinx-io segment pool size to 2MB. This change enables segment reuse by default, preventing performance degradation that occurred when segments were not pooled on Android runtimes.
ktor-client/ktor-client-core/jvm/src/io/ktor/client/io · high confidence
Bearer and Digest authentication providers rewritten with new configuration APIs
The Bearer and Digest authentication providers have been completely rewritten to support modern configuration patterns. For Bearer auth, the provider now includes a \nonCancellableRefresh\ option to prevent token refresh cancellation, a \cacheTokens\ flag to control token caching behavior, and a \realm\ property to match specific protection spaces. The \RefreshTokensParams\ class now exposes a \markAsRefreshTokenRequest()\ method to handle refresh requests without adding duplicate authorization headers. For Digest auth, the provider now strictly follows RFC 7616, supporting algorithm negotiation (defaulting to MD5), proper nonce count tracking per protection space, and qop validation. The old \username\/\password\ configuration properties are now deprecated in favor of a new \credentials\ block, and the provider no longer sends auth headers preemptively by default.
ktor-client-auth · high confidence
CIO server uses standard IO dispatcher on POSIX platforms
The CIO server engine now utilizes the standard kotlinx.coroutines IO dispatcher for its internal bridge operations on POSIX systems. This change, implemented in the new CoroutineUtilsNix module, ensures that the server leverages the platform's default thread pool for IO-bound tasks, aligning its behavior with standard coroutine practices on these operating systems.
ktor-server/ktor-server-cio/posix · high confidence
CORS plugin refactored to route-scoped plugin with deprecation of legacy version
The CORS plugin has been refactored from a global application plugin to a route-scoped plugin (io.ktor.server.plugins.cors.routing.CORS), allowing it to be installed on specific routes rather than globally. The legacy global CORS plugin is now deprecated with an ERROR level, directing users to migrate to the new route-scoped version. The new implementation intercepts OPTIONS preflight requests before routing, ensuring consistent CORS handling even for same-origin requests when preflight headers are present. Configuration options remain similar, supporting host allowlists, header customization, credential handling, and max-age settings.
ktor-server/ktor-server-plugins/ktor-server-cors/common/src/io/ktor/server/plugins/cors · high confidence
CallId plugin now supports custom verification and rejection of illegal IDs
The CallId plugin has been updated to allow developers to verify retrieved or generated call IDs using custom predicates or specific character dictionaries. If a call ID fails verification, the plugin can now be configured to reject the request by throwing a RejectedCallIdException, providing a way to enforce stricter ID formats or security policies compared to the previous behavior of simply ignoring or replacing illegal IDs.
ktor-server/ktor-server-plugins/ktor-server-call-id/common/src/io/ktor/server/plugins/callid · high confidence
CallLogging plugin restructured with ANSI color support and MDC integration
The CallLogging plugin implementation has been refactored to support ANSI-colored log output (enabled by default, configurable via \disableDefaultColors\) and improved Mapped Diagnostic Context (MDC) handling. The plugin now installs the ANSI console on startup and ensures it is uninstalled on application teardown to prevent resource leaks. Additionally, MDC entries are now properly scoped to the request lifecycle using coroutine context, ensuring diagnostic data is available during call processing and cleaned up afterwards. The plugin also exposes a \processingTimeMillis\ extension function for calculating request duration.
ktor-server/ktor-server-plugins/ktor-server-call-logging/jvm/src/io/ktor/server/plugins/calllogging · high confidence
Compression plugin refactored to new routing and pipeline API
The server compression plugin has been rewritten to align with the new Ktor routing and pipeline architecture. This change introduces dedicated pipeline phases for content encoding and decoding, allowing the plugin to hook into the request receive pipeline for decompression and the response send pipeline for compression. Users benefit from more robust handling of request body decompression, including configurable limits on encoding chain length and decoded content size to prevent decompression bombs, as well as the ability to track which decoders were applied via the new \appliedDecoders\ property on the request.
ktor-server/ktor-server-plugins/ktor-server-compression/jvm/src/io/ktor/server/plugins/compression · high confidence
Compression plugin supports request decompression and configurable security limits
The Ktor compression plugin now supports decompressing incoming request bodies in addition to compressing outgoing responses, controlled via a new \mode\ setting (CompressResponse, DecompressRequest, or All). To protect against decompression bomb attacks, the plugin introduces configurable limits for the maximum number of chained content encodings (\maxEncodingChainLength\) and the maximum size of the decoded request body (\maxDecodedContentLength\).
ktor-server-compression · high confidence
Configure Gradle Daemon to use JDK 21
The project now explicitly configures the Gradle Daemon to run on JDK 21. A new \gradle/gradle-daemon-jvm.properties\ file has been added, specifying JDK 21 as the toolchain version and providing download URLs for various platforms (Linux, macOS, Windows, FreeBSD) to ensure consistent build environments.
gradle · high confidence
Content Negotiation plugin API stabilization and new header control options
The public API for the Ktor Client Content Negotiation plugin is now stabilized, introducing the \ContentNegotiation\ plugin object and \ContentNegotiationConfig\ for configuring serializers. Users can now explicitly control HTTP Accept headers via the new \acceptHeaderMergeStrategy\ and \defaultAcceptHeaderQValue\ settings, and prevent automatic header injection using the \exclude\ extension on \HttpRequestBuilder\. The API also adds \ignoreType\ and \clearIgnoredTypes\ methods to the configuration to manage type handling, alongside the \ContentTypeMergeStrategy\ interface for custom merging logic.
ktor-client/ktor-client-plugins/ktor-client-content-negotiation/api · high confidence
Content Negotiation plugin adds Accept header control and JSON suffix matching
The ContentNegotiation plugin now allows users to control how registered content types are merged into the request's Accept header via a new \acceptHeaderMergeStrategy\ configuration option, including a \SkipIfPresent\ strategy to prevent automatic injection when headers are already set. Additionally, the plugin introduces support for structured syntax suffixes (RFC 6839), enabling converters registered for base types like \application/json\ to automatically handle extended types such as \application/problem+json\ through the new \JsonContentTypeMatcher\.
ktor-client/ktor-client-plugins/ktor-client-content-negotiation/common/src/io/ktor/client/plugins/contentnegotiation · high confidence
Content Negotiation plugin refactored for multi-platform support
The Content Negotiation plugin's core implementation has been rewritten in common code to support JS and WasmJS targets, replacing platform-specific modules. This refactoring introduces a new \ContentNegotiationConfig\ class that manages converter registrations, ignored types, and custom Accept header contributors. The request and response conversion logic has been consolidated into \RequestConverter\ and \ResponseConverter\, which now handle body transformation, charset negotiation, and Accept header compliance checking in a unified manner.
ktor-server/ktor-server-plugins/ktor-server-content-negotiation/common/src/io/ktor/server/plugins/contentnegotiation · high confidence
Darwin Legacy engine deprecated and refactored for iOS compatibility
The Darwin Legacy client engine is now deprecated in favor of the standard Darwin engine, with configuration properties like \requestConfig\ and \sessionConfig\ marked as errors to encourage migration to \configureRequest\ and \configureSession\. The engine implementation has been refactored to support Server-Sent Events (SSE) and ensures the underlying session is properly closed when the engine is closed. Additionally, the legacy engine now supports custom \NSURLSession\ instances via a new delegate-based API (\usePreconfiguredSession\ with \KtorLegacyNSURLSessionDelegate\) and includes specific handling for HTTP proxy configuration and certificate pinning headers.
ktor-client/ktor-client-darwin-legacy/darwin/src/io/ktor/client/engine/darwin · high confidence
Darwin charset encoding/decoding now uses Foundation APIs
The Darwin platform implementation for character set handling has been replaced with a new file (CharsetDarwin.kt) that leverages Apple's Foundation framework (NSString, NSData) for encoding and decoding. This change updates how text is converted to and from bytes on Darwin targets, supporting UTF-8, ISO-8859-1, UTF-16, and other encodings via native string APIs instead of previous methods.
ktor-io/darwin · high confidence
Darwin client ABI dumps added for legacy and current engines
KLib ABI dump files have been added for both the \ktor-client-darwin-legacy\ and \ktor-client-darwin\ modules, establishing the public API surface for the Darwin HTTP client engine on Apple platforms. This change enables KLib ABI validation to ensure binary compatibility for the legacy engine (exposing \LegacyPinnedCertificate\, \DarwinLegacyClientEngineConfig\, and \KtorLegacyNSURLSessionDelegate\) and the current engine (exposing \PinnedCertificate\, \DarwinClientEngineConfig\, and \KtorNSURLSessionDelegate\), supporting all iOS, macOS, tvOS, and watchOS targets.
ktor-client/ktor-client-darwin-legacy/api, ktor-client/ktor-client-darwin/api · high confidence
Darwin client engine restructured with new configuration API and improved URL handling
The Darwin client engine has been refactored to replace the deprecated \requestConfig\ and \sessionConfig\ properties with new \configureRequest\ and \configureSession\ methods, and \usePreconfiguredSession\ now requires an explicit \KtorNSURLSessionDelegate\. The engine now supports SOCKS proxies, handles semicolon characters in URLs for older macOS/iOS versions, and includes a new \KtorNSURLSessionDelegate\ to bridge \NSURLSession\ to Ktor. Additionally, the old \Ios\ engine type has been deprecated in favor of \Darwin\.
ktor-client/ktor-client-darwin/darwin · high confidence
Default ignored types for content negotiation now include InputStream
The content negotiation plugins for both Ktor Client and Ktor Server on the JVM platform now automatically ignore \InputStream\ types during serialization and deserialization. This change prevents the framework from attempting to process \InputStream\ instances as serializable content, which aligns with the expectation that these streams are handled directly rather than converted via content negotiation converters.
ktor-client/ktor-client-plugins/ktor-client-content-negotiation/jvm, ktor-server/ktor-server-plugins/ktor-server-content-negotiation/jvm · high confidence
Deprecate JVM-specific FileCacheStorage in favor of common kotlinx.io implementation
The JVM-specific \FileStorage\ function in \io.ktor.client.plugins.cache.storage\ is now deprecated. It serves as a thin wrapper that converts a \java.io.File\ directory into a \kotlinx.io.files.Path\ and delegates to the common package implementation. Users should migrate to the common \FileStorage\ API that uses \kotlinx.io\ for file system operations, which provides a unified approach across platforms.
ktor-client/ktor-client-core/jvm/src/io/ktor/client/plugins/cache · high confidence
Deprecation of legacy Base64 and Hex encoding utilities
The \ktor-utils/common\ module introduces new utility files that deprecate the existing \encodeBase64\, \decodeBase64String\, \hex\, and \hexToByteArray\ functions. These legacy helpers are now marked with \DeprecationLevel.WARNING\ and direct users to replace them with the Kotlin standard library's \Base64.Default\ encoder/decoder and \kotlin.text\ hex conversion functions. This change aims to reduce code duplication and align Ktor's encoding behavior with the standard library's stricter, non-lenient decoding rules.
ktor-utils/common · high confidence
Deprecation of legacy JSON client API in favor of ContentNegotiation
The legacy \JsonSerializer\ interface in the \ktor-client-json\ plugin is now deprecated with an error level, requiring users to migrate to the \ContentNegotiation\ plugin and its converters. This change is part of the migration to Ktor 2.0, and the \JsonContentTypeMatcher\ class has been introduced to handle JSON content type matching, including case-insensitive checks for JSON suffixes.
ktor-client/ktor-client-plugins/ktor-client-json/common/src/io/ktor/client/plugins/json · high confidence
Deprecation of the DarwinLegacy HTTP client engine
The \DarwinLegacy\ engine, which targets Darwin-based operating systems (macOS, iOS, tvOS) using \NSURLSession\, is now deprecated. Users will see a compiler warning when instantiating this engine and are advised to migrate to the standard \Darwin\ engine instead. This change is part of a broader effort to consolidate the Darwin client implementations and remove legacy code paths.
ktor-client-darwin-legacy · high confidence
Deprecation of the legacy Jetty server engine
The \ktor-server-jetty\ module, which provides the legacy Jetty-based server engine, is now deprecated and will be removed in the next major release. Users are advised to migrate to the \ktor-server-jetty-jakarta\ module, as the current implementation references an outdated version of Jetty. The deprecation applies to the entire engine factory, the \EngineMain\ entry point, and the underlying application engine classes in this location.
ktor-server/ktor-server-jetty/jvm · high confidence
Disable automatic engine dispatcher switching by default on JVM
On JVM platforms, Ktor Client no longer automatically switches to the engine's dispatcher for handling HTTP responses by default. This behavior is now opt-in via the system property \io.ktor.client.statement.useEngineDispatcher\ (defaulting to false), whereas non-JVM platforms continue to use the engine dispatcher by default. This change gives users explicit control over threading behavior on JVM to avoid potential performance or concurrency issues associated with the previous default.
ktor-client/ktor-client-core/jvm/src/io/ktor/client/statement, ktor-client/ktor-client-core/nonJvm/src/io/ktor/client/statement · high confidence
Dropwizard metrics plugin rewritten for new plugin API
The Dropwizard metrics plugin has been rewritten to use the new ApplicationPlugin API, changing how metrics are registered and tracked. Users will now see metrics organized under a configurable base name (defaulting to 'ktor.calls') and the plugin utilizes internal hooks like CallFailed, RoutingCallStarted, and ResponseSent for more precise request lifecycle monitoring. This change also introduces support for registering JVM metric sets (memory, garbage collection, threads, etc.) via a new configuration option.
ktor-server/ktor-server-plugins/ktor-server-metrics/jvm · high confidence
Enforce KTOR issue prefix in commit messages
A new prepare-commit-msg git hook has been added to validate commit messages. It requires commits to start with a valid KTOR issue key (e.g., KTOR-1001), while allowing exceptions for fixup, WIP, or tilde-prefixed commits. Commits that do not meet these criteria will be rejected.
githook · high confidence
Fix infinite loop in charset decoding on Linux and MinGW
The charset decoding implementation for Linux and MinGW targets has been updated to prevent infinite loops when processing truncated or incomplete UTF-8 byte sequences. The new \CharsetLinux.kt\ and \CharsetMingw.kt\ files introduce logic that detects when a multi-byte character is split across buffer segments; instead of looping indefinitely, the code now consolidates remaining bytes or throws a \MalformedInputException\ for invalid sequences, ensuring robust handling of malformed input.
ktor-io/linux, ktor-io/mingwX64 · high confidence
FreeMarker plugin rewritten for the new Plugins API
The Ktor FreeMarker plugin has been rewritten to use the new Plugins API, replacing the previous implementation. This change introduces a new \FreeMarkerContent\ class and a \respondTemplate\ extension function, allowing users to render FreeMarker templates as responses. The plugin now hooks into the \BeforeResponseTransform\ phase to process templates and handle optional ETag support, providing a more integrated and modern approach to template rendering within Ktor applications.
ktor-server/ktor-server-plugins/ktor-server-freemarker/jvm · high confidence
GsonSerializer is deprecated with ERROR level
The GsonSerializer class in the Ktor Gson client plugin is now marked with DeprecationLevel.ERROR, meaning it can no longer be used in new code. Users must migrate to the ContentNegotiation plugin and its converters as specified in the migration guide.
ktor-client/ktor-client-plugins/ktor-client-json/ktor-client-gson/jvm/src/io/ktor/client/plugins/gson · high confidence
HTTP/3 support and Netty engine refactoring
The Netty engine now supports HTTP/3, introducing a new handler that dispatches application calls via the call event loop while keeping user code off the QUIC event loop for better performance. This change also includes a new EventLoopGroupProxy that automatically selects the optimal native transport (KQueue on macOS, Epoll on Linux) with a fallback to NIO, and refactors request handling to expose raw query parameters and improve error handling for query string parsing.
ktor-server-netty · high confidence
HttpCache plugin rewritten with new CacheStorage API and RFC-compliant validation
The HttpCache plugin has been refactored to use a new \CacheStorage\ interface (replacing the deprecated \HttpCacheStorage\) and now strictly adheres to HTTP caching standards. Key behavioral changes include: respecting the \s-maxage\ directive for shared clients, supporting the \only-if-cached\ request directive, correctly handling the \max-stale\ directive to allow stale responses with warnings, and properly validating cached entries using ETags and Last-Modified headers. The plugin now includes a \clearAllCaches()\ API for clearing storage and adds trace logging for debugging cache decisions. Users relying on the old \HttpCacheStorage\ API will see deprecation errors and must migrate to the new \CacheStorage\-based configuration.
ktor-client/ktor-client-core/common/src/io/ktor/client/plugins/cache · high confidence
Implement streaming response body reading for the JS browser engine
The JS browser client engine now supports streaming response bodies via a new internal implementation in BrowserFetch.kt. This change replaces previous approaches by utilizing the W3C fetch API's ReadableStream to read response chunks into a ByteReadChannel, enabling efficient handling of large responses without loading the entire body into memory at once.
ktor-client/ktor-client-core/js/src/io/ktor/client/engine/js/browser · high confidence
Implementation of internal infrastructure for HTTP partial content support
This change introduces the core internal components required to handle HTTP Range requests within the Ktor server. It adds a new pipeline phase and hook (\BodyTransformedHook\) that intercepts response bodies to allow modification before sending. It also defines \PartialOutgoingContent\, a sealed class hierarchy that wraps original content into specific types: \Bypass\ (for full responses with Accept-Ranges headers), \Single\ (for single byte-range responses returning 206 Partial Content), and \Multiple\ (for multipart byte-range responses). Additionally, a utility function \isNotHostAddress\ is added to the forwarded headers module, likely to support host validation logic used in conjunction with these header manipulations.
ktor-server-partial-content, ktor-server/ktor-server-plugins/ktor-server-forwarded-header/common/src/io/ktor/server/plugins/forwardedheaders · high confidence
Initial KLib ABI dump for Ktor Curl client
The Ktor Curl client engine now includes a KLib ABI dump file (ktor-client-curl.klib.api) that defines the public binary interface for Linux ARM64, Linux x64, macOS ARM64, macOS x64, and MinGW x64 targets. This dump explicitly exposes the CurlClientEngineConfig class with its caInfo, caPath, and sslVerify properties, the Curl engine factory, and specific exception classes (CurlIllegalStateException, CurlRuntimeException), establishing the baseline for ABI validation.
ktor-client/ktor-client-curl/api · high confidence
Introduce kotlinx.serialization converter with extension support and improved error reporting
The kotlinx.serialization module now provides a new \KotlinxSerializationConverter\ and \KotlinxWebsocketSerializationConverter\ that support both string (e.g., JSON) and binary (e.g., ProtoBuf, CBOR) formats. A new extension mechanism (\KotlinxSerializationExtension\) allows format-specific logic to be applied during serialization and deserialization. The converter now respects the \SerializersModule\ for JSON schema inference, ensuring contextual serializers are reflected in generated schemas. Additionally, serializer lookup for generic types has been improved with better error messages that identify specific non-serializable type arguments, and null handling has been refined to prevent crashes on empty or null bodies.
ktor-shared/ktor-serialization/ktor-serialization-kotlinx/common · high confidence
Introduce legacy Darwin engine implementation for older macOS/iOS versions
The Darwin client engine now includes a new \legacy\ sub-module containing internal utilities and session handling logic designed to support older macOS and iOS versions. This addition introduces specific URL encoding workarounds to handle semicolon characters in paths (which were restricted in older systems) and ensures proper socket timeout configuration and session lifecycle management for legacy environments.
ktor-client/ktor-client-darwin-legacy/darwin/src/io/ktor/client/engine/darwin/internal · high confidence
Introduce new JS HTTP client engine implementation
The JS HTTP client engine has been replaced with a new implementation (JsClientEngine) that manages the underlying fetch and WebSocket connections. This change introduces support for Server-Sent Events (SSE) and WebSockets as first-class capabilities, including specific handling for WebSocket subprotocols and frame queue backpressure. The engine now correctly handles connection establishment by waiting for open/error events before proceeding, and it adapts response bodies and headers to the Ktor model, ensuring compatibility with both browser and Node.js environments.
ktor-client/ktor-client-core/js/src/io/ktor/client/engine/js · high confidence
Introduces a typed JWT authentication DSL with improved key handling
The JWT authentication plugin now provides a new typed DSL (jwt\<P\>) that allows developers to specify the principal type directly, resulting in type-safe access to user credentials after authentication. This change also refactors the underlying verification logic to fetch JSON Web Keys (JWKs) on Dispatchers.IO to prevent blocking the event loop, and adds support for EC keys when the JWK algorithm is null, ensuring broader compatibility with various key providers.
ktor-server/ktor-server-plugins/ktor-server-auth-jwt/jvm · high confidence
Introduces internal utility classes for Dropwizard metrics tracking
The Dropwizard metrics plugin now includes a new utility file defining internal data structures (RoutingMetrics, CallMeasure) and associated attribute keys. These components provide the underlying mechanism for tracking routing and call-level metrics within the plugin, supporting the plugin's internal state management for performance monitoring.
ktor-server-metrics · high confidence
Introduces new HttpClientEngine API and engine configuration model
The HTTP client engine layer has been refactored to use a new \HttpClientEngine\ interface and \HttpClientEngineFactory\ for creating and managing engine instances, replacing the previous internal structure. This change introduces \HttpClientEngineCapability\ to allow engines to declare support for features like timeouts or WebSocket, enabling plugins to adapt behavior accordingly. Engine configuration is now centralized in \HttpClientEngineConfig\, which exposes settings for the coroutine dispatcher, pipelining, and proxy support (including SOCKS via \ProxyBuilder\). Additionally, internal utilities for header merging, user-agent handling, and coroutine context propagation have been updated to align with this new engine lifecycle.
ktor-client/ktor-client-core/common/src/io/ktor/client/engine · high confidence
Introduces platform-specific IO configuration hook for non-JVM targets
The Ktor client core now includes a new \PlatformStaticConfig\ file that declares an \expect fun configurePlatform()\ for common code and provides an \actual\ implementation for non-JVM platforms. This change establishes the infrastructure to allow platform-specific IO configuration, specifically supporting the default enabling of the kotlinx-io segment L2 cache on Android, while ensuring the hook is a no-op on other non-JVM targets.
ktor-client/ktor-client-core/common/src/io/ktor/client/io, ktor-client/ktor-client-core/nonJvm/src/io/ktor/client/io · high confidence
JSON plugin adds JVM-specific defaults and ignored types
The JVM implementation of the JSON client plugin now includes a DefaultJvm.kt file that uses ServiceLoader to discover available JsonSerializer instances and selects the best match, providing a clear error message with dependency suggestions if none are found. Additionally, JsonPluginJvm.kt defines DefaultIgnoredTypes to automatically ignore InputStream instances during serialization, preventing potential issues when serializing stream objects.
ktor-client/ktor-client-plugins/ktor-client-json/jvm/src/io/ktor/client/plugins/json · high confidence
JVM HttpClient now uses ServiceLoader for automatic engine selection
The JVM implementation of the HttpClient constructor has been updated to automatically select the HTTP engine at runtime using Java's ServiceLoader. Instead of requiring explicit engine configuration, the client now scans the classpath for all available HttpClientEngineContainer implementations, ranks them by priority, and uses the highest-priority one. If no engine implementations are found on the classpath, an exception is thrown. This change simplifies the API by removing the need for manual engine wiring in standard JVM usage.
ktor-client/ktor-client-core/jvm/src/io/ktor/client · high confidence
JVM WebSocket implementation refactored with configurable backpressure and frame validation
The JVM WebSocket module has been restructured to introduce configurable backpressure for incoming and outgoing frame queues via the new \WebSocketChannelsConfig\ parameter in \RawWebSocket\. This allows users to control queue capacities to prevent memory issues. Additionally, the implementation now validates control frame sizes in the \Frame\ constructor and enforces maximum frame sizes during reading in \WebSocketReader\, closing connections with appropriate error codes when limits are exceeded. The change also includes a new \Serializer\ for frame serialization and updated \DeflaterUtils\ for compression handling.
ktor-shared/ktor-websockets/jvm · high confidence
JVM YAML configuration now reads from system properties and environment variables
The JVM-specific YAML configuration loader now supports reading values from system properties and environment variables via the new \getSystemPropertyOrEnvironmentVariable\ implementation. This allows configuration values to be overridden at runtime using standard JVM mechanisms, enhancing flexibility for deployment environments without requiring changes to the YAML files themselves.
ktor-server/ktor-server-config-yaml/jvm · high confidence
JVM proxy configuration now supports SOCKS proxies
The JVM-specific proxy configuration implementation has been updated to include a \socks\ builder method, allowing users to configure SOCKS proxies in addition to HTTP proxies. This change also ensures that SOCKS proxy types are correctly mapped and resolved, fixing a previous issue where SOCKS proxies were incorrectly treated as direct connections.
ktor-client/ktor-client-core/jvm/src/io/ktor/client/engine · high confidence
JVM-specific CIO engine infrastructure and DNS resolver
The CIO client engine on JVM now includes a service container registration (META-INF/services) and a JVM-specific DNS resolver that wraps java.net.InetAddress in an interruptible coroutine, allowing timeouts to properly cancel blocking DNS lookups. Additionally, the engine can now automatically discover HTTP proxy settings from the JVM's global ProxySelector, and connection handling has been updated to respect HTTP/1.0 Connection: Close defaults and preserve exceptions during timeout mapping.
ktor-client/ktor-client-cio/jvm · high confidence
JVM-specific HTTP utilities and blocking bridge improvements
This update introduces several JVM-specific implementations for the ktor-http module. It adds platform-specific functions for detecting file content types from Java File and Path objects, and implements HTTP date header parsing (If-Modified-Since, Last-Modified, Expires, Date) using Java's SimpleDateFormat. URL handling is enhanced with JVM-specific constructors and utilities, including a fix for hosts containing underscores in the takeFrom method. The module also introduces a dedicated coroutine dispatcher for blocking bridges to prevent event loop exhaustion, deprecates the blocking InputStream provider for multipart file items, and adds a bypass method for OutputStreamContent to improve performance on servlet engines.
ktor-http/jvm · high confidence
JVM-specific client utility implementations introduced
The JVM module now includes platform-specific utility files for the CIO engine, coroutine dispatchers, and exception handling. This introduces a JVM-specific ByteBuffer pool for HttpClient, configures the client dispatcher to use Kotlin's built-in IO dispatcher with limited parallelism, and implements exception unwrapping logic that correctly handles cancellation exception cycles.
ktor-client/ktor-client-core/jvm/src/io/ktor/client/utils · high confidence
JVM-specific exception handling and status file serving for StatusPages
The StatusPages plugin now includes JVM-specific implementations for selecting the most specific exception handler and serving static status files. The new \StatusPagesJvm.kt\ adds a \statusFile\ function that serves HTML files based on a pattern (e.g., \error-\#.html\) and an \exception\ function that registers handlers for specific exception classes. Additionally, \StatusPagesUtilsJvm.kt\ provides the \selectNearestParentClass\ logic to find the closest matching exception type in the hierarchy, ensuring that the most specific exception handler is selected when an error occurs.
ktor-server/ktor-server-plugins/ktor-server-status-pages/jvm/src/io/ktor/server/plugins/statuspages · high confidence
JWT authentication provider now fails fast if validation is not configured
The JWT authentication plugin in Ktor now throws an IllegalArgumentException at startup if the \validate\ (authentication) function is not provided during configuration. Previously, this might have resulted in runtime errors or silent failures when attempting to authenticate requests; the change ensures that misconfigured JWT authentication is detected immediately upon application initialization, preventing unexpected behavior during request processing.
ktor-server-auth-jwt · high confidence
JacksonSerializer marked as error-level deprecation
The JacksonSerializer class in the Ktor Jackson client plugin is now deprecated with DeprecationLevel.ERROR, meaning it will cause a compilation failure if used. Users must migrate to the ContentNegotiation plugin and its associated converters as outlined in the migration guide for version 2.0.
ktor-client/ktor-client-plugins/ktor-client-json/ktor-client-jackson/jvm/src/io/ktor/client/plugins/jackson · high confidence
Jetty HTTP/2 client engine implementation
The Jetty client engine for the JVM has been updated to use HTTP/2 by default. This change introduces a new engine configuration class, JettyEngineConfig, which allows users to configure SSL settings, set the client instance cache size, and apply raw Jetty client customizations. The underlying engine, JettyHttp2Engine, now manages HTTP/2 sessions and streams, supporting timeout configurations via the HttpTimeout plugin and handling request body transmission through Jetty's HTTP/2 frame API.
ktor-client/ktor-client-jetty/jvm · high confidence
Jetty engine restructured with new configuration and WebSocket I/O internals
The Jetty server engine has been refactored to expose new configuration options for server customization, including hooks to configure the Jetty Server and HttpConfiguration objects, as well as a configurable idle timeout for connections. Additionally, the underlying WebSocket I/O implementation has been rewritten using Kotlin coroutines and a dedicated byte buffer pool to improve connection handling and resource management.
ktor-server-jetty · high confidence
JsonPlugin deprecated in favor of ContentNegotiation with ignored type support
The \JsonPlugin\ is now deprecated with an error level, directing users to migrate to the \ContentNegotiation\ plugin as per the 2.0 migration guide. To support this transition, the plugin's configuration now includes \ignoreType\ and \removeIgnoredType\ methods, allowing users to explicitly manage types that should be excluded from JSON serialization/deserialization processes.
ktor-client-json · high confidence
KotlinxSerializer class deprecated with ERROR level
The \KotlinxSerializer\ class in the Ktor client serialization plugin is now deprecated at the \ERROR\ level, meaning it will cause a compilation failure if used. Users must migrate to the \ContentNegotiation\ plugin and its converters as outlined in the migration guide for Ktor 2.0.
ktor-client/ktor-client-plugins/ktor-client-json/ktor-client-serialization/common/src/io/ktor/client/plugins/kotlinx · high confidence
Ktor Client JSON plugin introduces type ignoring and migrates to kotlinx-io
The Ktor Client JSON plugin now allows users to explicitly ignore specific types during serialization and deserialization via new \ignoreType\, \removeIgnoredType\, and \clearIgnoredTypes\ configuration methods, providing finer control over how JSON data is mapped. Additionally, the underlying I/O layer has been migrated from the legacy \kotlinx-io\ implementation to the new \kotlinx-io\ library, updating the \JsonSerializer\ interface to use \kotlinx.io.Source\ for reading operations. This change is reflected in the updated public API for the core \JsonPlugin\, as well as its bundled serializers (Gson, Jackson, and Kotlinx Serialization), which now implement the updated \JsonSerializer\ contract.
ktor-client/ktor-client-plugins/ktor-client-json · high confidence
Ktor Client plugins migrated to new API and lifecycle model
The core client plugins (including HttpRequestRetry, HttpCallValidator, HttpRedirect, BodyProgress, and UserAgent) have been rewritten to use the new plugin API and lifecycle hooks. This migration introduces a new request lifecycle model where each request is bound to its own SupervisorJob, ensuring that request cancellation correctly propagates to the underlying engine and preventing resource leaks. The new API also standardizes how plugins intercept request and response pipelines, improving consistency and reliability across the client.
ktor-client/ktor-client-core/common/src/io/ktor/client/plugins · high confidence
Logging plugin refactored with new internal logger and configurable body filtering
The Ktor client logging plugin has been restructured to use a new internal \HttpClientCallLogger\ class for managing request and response log buffers, replacing the previous implementation. This change introduces a configurable \bodyFilter\ property in \LoggingConfig\, allowing users to apply custom logic to filter, modify, or exclude HTTP response bodies before they are logged. The plugin also retains support for the OkHttp-style logging format and header sanitization, ensuring that sensitive data can still be masked while providing more granular control over body content visibility.
ktor-client/ktor-client-plugins/ktor-client-logging/common/src/io/ktor/client/plugins/logging · high confidence
Migrate CIO HTTP builder to kotlinx-io and add JVM-specific pooling control
The CIO HTTP request/response builder in the JVM module has been rewritten to use kotlinx-io (Source) instead of the previous BytePacketBuilder, changing how HTTP packets are constructed and built. Additionally, a new JVM-specific internal utility (CharArrayPoolJvm) was added to expose a system property (ktor.internal.cio.disable.chararray.pooling) that allows users to disable character array pooling for the CIO implementation.
ktor-http/ktor-http-cio/jvm · high confidence
Migrate I/O layer to kotlinx-io
The common I/O implementation has been migrated to use the kotlinx-io library, replacing the previous internal buffer and channel abstractions. This change introduces new \ByteReadChannel\ and \ByteWriteChannel\ interfaces backed by kotlinx-io \Source\ and \Sink\ types, along with updated operations for reading and writing data. Existing APIs that relied on the old internal structures are now deprecated in favor of the new kotlinx-io-based equivalents, ensuring a consistent foundation for future I/O improvements.
ktor-io/common · high confidence
Migrate JVM/Posix file cache storage to kotlinx.io
The file-based cache storage implementation for JVM and POSIX platforms has been rewritten to use the \kotlinx.io\ library instead of the previous I/O stack. This change updates the underlying file operations (reading, writing, and deleting cache files) to leverage \kotlinx.io.files.FileSystem\ and \SystemFileSystem\, while preserving the existing caching behavior and API surface for users.
ktor-client/ktor-client-core/jvmAndPosix · high confidence
Native POSIX client now uses fixed thread-pool dispatchers
The Ktor client on POSIX platforms (iOS, macOS, Linux, etc.) now creates its background dispatchers using a fixed thread pool via \newFixedThreadPoolContext\ instead of the previous implementation. This change ensures that client coroutines run on a dedicated set of threads, which can improve stability and predictability for network operations on native targets.
ktor-client/ktor-client-core/posix/src/io/ktor/client/utils · high confidence
Netty engine rewritten with new coroutine integration and HTTP/3 support
The Netty server engine has been completely rewritten to improve coroutine integration, performance, and protocol support. The new implementation introduces a dedicated \NettyDispatcher\ to ensure coroutine continuations are dispatched onto the Netty event loop, preserving thread affinity across suspension points. It adds support for HTTP/3 (QUIC) alongside existing HTTP/1.1 and HTTP/2 capabilities, including cleartext HTTP/2 (h2c). The engine now features a more robust response pipeline that tracks streaming responses separately to prevent SSE blocking, implements flush consolidation to reduce overhead, and provides configurable limits for running requests, timeouts, and buffer sizes via \application.conf\. Additionally, the rewrite includes better resource cleanup, graceful shutdown handling, and fixes for various race conditions and memory leaks present in the previous version.
ktor-server/ktor-server-netty/jvm · high confidence
New CacheStorage API with removal and clearing capabilities
The HTTP client cache storage layer introduces a new \CacheStorage\ interface to replace the deprecated \HttpCacheStorage\. This new API adds explicit methods to remove specific cached entries (\remove\), clear all entries for a URL (\removeAll\), and clear the entire cache (\clear\), giving users finer control over cache lifecycle. The implementation includes \CachingCacheStorage\ for in-memory caching with a delegate, \UnlimitedStorage\ for unlimited in-memory storage, and \DisabledStorage\ for disabling caching, all supporting the new synchronous-style operations within the common codebase.
ktor-client/ktor-client-core/common/src/io/ktor/client/plugins/cache/storage · high confidence
New Gradle build settings conventions for caching, configuration cache, and repository management
The build system now includes a set of new Gradle settings conventions that improve build performance and reliability. A cache redirector is introduced to route repository downloads through JetBrains' cache infrastructure, speeding up dependency resolution in CI and local builds. Configuration cache support is enabled with specific workarounds for Kotlin metadata transformation tasks to prevent out-of-memory errors. Repository management is centralized, ensuring consistent access to Maven Central, Google, and Ktor EAP repositories, while Develocity build scans are configured to report sync modes and obfuscate user data. Additionally, Kotlin User Project settings allow building against Kotlin compiler snapshots with configurable language and API versions, and test filtering to exclude flaky or stress tests during snapshot builds.
build-settings-logic · high confidence
New JavaScript WebSocket session implementation
The JavaScript platform now uses a dedicated JsWebSocketSession implementation for handling WebSocket connections. This change introduces native support for binary frames via ArrayBuffer and handles text frames as strings, while explicitly disabling unsupported features like ping-pong intervals, timeouts, masking, and extensions by throwing exceptions when accessed. The session manages incoming and outgoing frame channels, ensuring proper cleanup of event listeners and channels upon connection closure or coroutine completion.
ktor-client/ktor-client-core/js/src/io/ktor/client/plugins/websocket · high confidence
New Jetty HTTP/2 client engine implementation
The Ktor Jetty client engine has been replaced with a new implementation that uses the Jetty HTTP/2 client directly. This change introduces a new \JettyResponseListener\ to handle HTTP/2 stream events, allowing for more efficient data processing and better error handling for HTTP/2 specific scenarios like push promises and stream resets. Users of the \ktor-client-jetty\ module will now benefit from improved performance and stability when making HTTP/2 requests.
ktor-client-jetty · high confidence
New client plugins API and engine base implementation
The client core introduces a new plugin architecture and engine lifecycle management. A new \HttpClientEngineBase\ abstract class simplifies custom engine creation by handling dispatcher and coroutine context setup. The \DefaultRequest\ plugin is updated to support request attributes and ensures user-provided headers take precedence over defaults. The \HttpTimeout\ plugin now explicitly excludes WebSocket and SSE connections from request timeouts. A new \HttpSend\ plugin centralizes the send pipeline, introducing a configurable \maxSendCount\ to limit request retries and prevent infinite loops. The \HttpCookies\ plugin is refactored to capture cookies from request headers and store them with raw encoding. Additionally, the client now supports Server-Sent Events (SSE) with a new \SSE\ plugin, configurable buffer policies for diagnostics, and reconnection support.
ktor-client-core · high confidence
New common ByteChannel implementation with kotlinx-io integration
The ktor-io module introduces a new common \ByteChannel\ implementation that replaces the previous platform-specific IO layer with \kotlinx-io\ primitives (\Source\ and \Sink\). This change provides a unified, multiplatform byte channel API available across JVM, Native, JS, and WasmJS targets, featuring a bounded internal buffer (1MB default) to prevent unbounded memory growth, proper cancellation propagation through \CloseToken\, and a new \onClose\ hook for executing actions upon channel closure. The public API surface is updated to expose \readBuffer\ and \writeBuffer\ properties for direct access to the underlying \kotlinx-io\ buffers, and the module now includes comprehensive tests for channel lifecycle, buffering, and charset decoding edge cases.
ktor-io · high confidence
New common test dispatcher with platform-specific implementations
The \ktor-test-dispatcher\ module now provides a unified testing infrastructure across platforms. A new common API (\testSuspend\) is declared via \expect\/\actual\ to support JVM, WasmJS, and other targets, ensuring consistent test execution semantics. The common layer also introduces \runTestWithRealTime\ to allow tests to bypass virtual time when necessary, and deprecates the legacy \testSuspend\ in favor of the standard \kotlinx.coroutines.test.runTest\.
ktor-test-dispatcher/common · high confidence
Non-JVM engine loader and proxy configuration implementation
The non-JVM source set now includes the core engine discovery mechanism and proxy configuration support. A new \Loader.kt\ file introduces the \engines\ registry, allowing HTTP client engines to be auto-discovered and selected by priority when no explicit engine is provided. Additionally, \ProxyConfig.nonJvm.kt\ provides the actual implementations for proxy configuration, including the \ProxyConfig\ class, \ProxyBuilder\ for creating HTTP and SOCKS proxies, and address resolution, ensuring consistent proxy behavior across non-JVM platforms.
ktor-client/ktor-client-core/nonJvm/src/io/ktor/client/engine · high confidence
Non-JVM server core platform implementations added
This change introduces the \nonJvm\ source set for \ktor-server-core\, providing platform-specific implementations required for non-JVM targets (such as Wasm/Wasi). Key additions include stub implementations for hot reload (disabled), SSL configuration (throws an error as it is unsupported), and default content/transform pipelines. It also defines the \ApplicationEnvironment\ interface and builder for these platforms, configures config loading via the \CONFIG\_FILE\ environment property, and sets a default form field limit of 50 MB.
ktor-server/ktor-server-core/nonJvm · high confidence
OkHttp engine engine reimplementation with new configuration options
The OkHttp engine implementation has been rewritten to support new configuration options including preconfigured OkHttpClient instances, custom DNS resolvers, duplex streaming for HTTP/2, and WebSocket factory injection. The engine now uses a built-in LRU cache for OkHttpClient instances and ensures response body cleanup happens on the engine dispatcher to prevent thread leaks. WebSocket sessions now respect ping intervals from both Ktor and OkHttp configurations, with OkHttp's setting taking priority. The engine also properly handles reserved WebSocket close codes by falling back to internal error codes.
ktor-client/ktor-client-okhttp/jvm · high confidence
POSIX HttpClient now selects the highest-priority registered engine by default
The POSIX implementation of the HttpClient factory function has been updated to automatically select the default HTTP client engine. It iterates through all registered engine factories, ranks them by priority, and uses the one with the highest priority. If no engines are registered, an exception is thrown. This change centralizes engine selection logic in the POSIX module, relying on the global registry of engine factories.
ktor-client/ktor-client-core/posix/src/io/ktor/client · high confidence
Platform-specific environment variable handling for Windows and POSIX targets
The Ktor server engine now uses native platform APIs to manage environment variables on Windows (mingwX64) and POSIX systems (nix). On Windows, environment properties are manipulated via \SetEnvironmentVariable\ and read using \GetEnvironmentStringsW\, while POSIX targets use standard \setenv\, \unsetenv\, and direct access to the \environ\ array. This ensures that Ktor-specific environment properties (those prefixed with \ktor.\) are correctly set, cleared, and retrieved according to the underlying operating system's conventions.
ktor-server/ktor-server-core/mingwX64, ktor-server/ktor-server-core/nix · high confidence
Platform-specific handling of content encoding checks in Ktor Client
The Ktor Client encoding plugin now applies platform-specific logic to determine whether to decode compressed responses. On Darwin (iOS/macOS) platforms, the plugin skips manual decoding checks because the underlying system handles content encoding automatically. On non-Darwin POSIX platforms, the plugin retains the previous behavior of decoding responses whenever a Content-Encoding header is present.
ktor-client/ktor-client-plugins/ktor-client-encoding/darwin, ktor-client/ktor-client-plugins/ktor-client-encoding/nonDarwinPosix · high confidence
RateLimit plugin now intercepts requests during the Validators phase
The RateLimit plugin has been refactored to execute its logic in the ApplicationCallPipeline.Validators phase instead of the previous Plugins phase. This behavioral change ensures that rate limiting is applied before routing and other plugin logic, which fixes issues where the limit was bypassed if a nested authentication block rejected the request. The change is implemented via new interceptor configurations (RateLimitInterceptors and RateLimitApplicationInterceptors) that manage the rate limiter instances and response header modifications within this earlier pipeline stage.
ktor-server/ktor-server-plugins/ktor-server-rate-limit/common/src/io/ktor/server/plugins/ratelimit · high confidence
Refactor auth providers with new token caching and credential configuration API
The auth providers (Basic, Bearer, etc.) now use a shared \AuthTokenHolder\ to manage credential caching, allowing credentials to be cached or recomputed on every request via the new \cacheTokens\ configuration option. The configuration API has been updated to use \credentials {}\ and \sendWithoutRequest {}\ blocks instead of direct property setters, with the old properties removed. Additionally, the Basic auth provider now performs case-insensitive matching for the auth scheme, and token clearing is handled more robustly to avoid race conditions.
ktor-client/ktor-client-plugins/ktor-client-auth/common/src/io/ktor/client/plugins/auth/providers · high confidence
Refactored HTTP response handling and execution model
The client's response handling has been restructured to improve clarity and control over execution contexts. The \HttpResponse\ class now exposes a \rawContent\ property for accessing unprocessed network data, while the previously named \content\ property has been deprecated in favor of \readRawBytes()\ to better reflect its behavior. Additionally, \HttpStatement.execute\ and body blocks now support configurable dispatcher switching via the \useEngineDispatcher\ flag (defaulting to disabled on JVM for backward compatibility), allowing these operations to run on the engine's dispatcher for safer IO handling on non-JVM platforms and preparing for a default change in Ktor 4.0.
ktor-client/ktor-client-core/common/src/io/ktor/client/statement · high confidence
Removes hardcoded Develocity accessors to support Gradle 9.5+
The build system now removes hardcoded Develocity accessors that were incompatible with Gradle 9.5 and later versions. This change ensures compatibility with the updated Gradle version (9.5.1) by eliminating the specific code patterns that caused conflicts, allowing the build settings logic to function correctly with the newer Gradle release.
build-settings-logic/develocity-patched · high confidence
Rename jsAndWasmShared to web
The \jsAndWasmShared\ source set has been renamed to \web\ across the Ktor codebase. This change affects the internal implementation files for client encoding, JSON handling, HTTP URL building, I/O utilities, server CIO, session management, and serialization, ensuring that web-specific platform code is now organized under the new \web\ directory structure.
(repo-wide) · high confidence
ResponseObserver plugin now supports call filtering and deprecates legacy wrapping functions
The ResponseObserver plugin in the Ktor client now allows users to install a filter predicate to dynamically control whether the interceptor executes for specific HTTP calls, enabling more granular control over which responses are observed. Additionally, the legacy \wrap\ and \wrapWithContent\ functions in the observer package have been deprecated in favor of the \replaceResponse\ API, guiding users toward the newer, more robust method for modifying response content.
ktor-client/ktor-client-core/common/src/io/ktor/client/plugins/observer · high confidence
Restructure CIO HTTP engine into modular source files
The CIO HTTP engine implementation in ktor-http/ktor-http-cio/common has been reorganized from a single monolithic source file into distinct modules (CIOMultipartDataBase, ChunkedTransferEncoding, HttpBody, HttpHeadersMap, HttpParser, RequestResponseBuilderCommon, and internal utilities). This change improves code maintainability and readability by separating concerns such as multipart parsing, chunked transfer encoding, header management, and HTTP request/response parsing into their own files, while preserving the existing functionality and behavior of the CIO engine.
ktor-http/ktor-http-cio/common · high confidence
Restructure Ktor Client JS project layout
The Ktor Client JS module has been reorganized to flatten the Gradle project hierarchy. This change introduces empty placeholder files (.gitkeep) in the api, js, and wasmJs directories, indicating a structural shift in how the module's source and API artifacts are organized, likely to support the new hierarchy without breaking existing build configurations.
ktor-client/ktor-client-js · medium confidence
Rewritten Apache HTTP client engine with improved stability and SSE support
The Apache HTTP client engine has been completely rewritten to address previous stability issues, including request freezes and concurrent access errors. This new implementation introduces support for Server-sent Events (SSE) and allows configuring request, connect, and socket timeouts. It also adds support for HTTP proxies and improves error handling by properly mapping timeout exceptions. Note that this engine is deprecated in favor of the Apache5 engine.
ktor-client/ktor-client-apache/jvm · high confidence
Rewritten JVM CIO network implementation with NIO selector and timeout support
The JVM CIO (Common I/O) networking layer has been completely rewritten to use Java NIO selectors for managing socket readiness, replacing the previous implementation. This change introduces a new \InterestSuspensionsMap\ to track coroutine continuations for read, write, accept, and connect operations, ensuring thread-safe suspension management. The update adds support for configurable socket timeouts (read, write, connect) that automatically close channels if activity stalls. It also fixes several socket issues, including a self-connect problem where clients could inadvertently connect to themselves, and improves UDP datagram handling with a dedicated byte buffer pool. Additionally, the implementation now supports Unix domain sockets and uses reflection to safely access Java 7+ socket options like \SO\_REUSEPORT\ on older Android APIs.
ktor-network/jvm · high confidence
Servlet engine refactored for async processing and proper lifecycle management
The Ktor servlet integration has been rewritten to support asynchronous request processing, introducing dedicated \AsyncServletApplicationCall\ and \BlockingServletApplicationCall\ implementations to handle request body reading and response writing via non-blocking channels. A new \KtorServletContainerInitializer\ and \KtorServletContextListener\ ensure that application lifecycle events (start/stop) are correctly triggered during WAR deployment, preventing resource leaks and ensuring \ApplicationStarted\ fires at deployment time rather than on the first request. Additionally, the engine now exposes servlet request attributes as call attributes, supports HTTP/2 push via reflection, and provides a \webResources\ routing function to serve static web content.
ktor-server/ktor-server-servlet/jvm · high confidence
Sessions plugin restructured with new storage, transport, and serialization APIs
The Sessions plugin has been refactored to provide a more modular and multiplatform architecture. A new caching layer (CacheStorage) is introduced to optimize session reads and writes, while session data handling is now exposed via a unified CurrentSession interface with type-safe extension functions for getting, setting, and clearing sessions. Transport mechanisms are now distinct classes (SessionTransportCookie, SessionTransportHeader) allowing sessions to be stored in cookies or headers with configurable attributes like max age and security flags. Serialization is handled by dedicated serializers (KotlinxSessionSerializer) supporting kotlinx.serialization, including a backward-compatible mode for legacy formats. Additionally, security is enhanced with new transformers (SessionTransportTransformerEncrypt, SessionTransportTransformerMessageAuthentication) that provide authenticated encryption and MAC signing for session data.
ktor-server-sessions · high confidence
Sessions plugin rewritten with new provider model and deferred loading
The Sessions plugin has been completely rewritten to use a new provider-based architecture (SessionProvider, SessionTracker, SessionTransport) that replaces the previous custom serializer approach. This change introduces a \sendOnlyIfModified\ option to skip resending unchanged session data, adds a \BeforeSend\ hook for response lifecycle control, and supports deferred session fetching for public endpoints to improve performance. The new model also includes a \Cache\ interface for storage optimization, a \SessionStorageMemory\ implementation for development, and explicit support for SameSite cookie attributes.
ktor-server/ktor-server-plugins/ktor-server-sessions/common · high confidence
Stabilized OpenAPI schema names for sealed subtypes on non-JVM platforms
The non-JVM implementation of the OpenAPI schema inference now provides stable, deterministic component names for sealed subtype schemas. Previously, name generation could vary or collide; the new logic extracts consistent identifiers from serializer descriptors and applies a fallback strategy based on serial names, ensuring that generated OpenAPI documentation accurately and uniquely represents sealed class hierarchies.
ktor-shared/ktor-openapi-schema/nonJvm · high confidence
Stabilized common network socket API and selector interfaces
The \ktor-network/common\ module now exposes a stabilized, public API for low-level network operations, replacing internal or experimental constructs with formal \expect\ declarations and public interfaces. This includes the \Selectable\ and \SelectorManager\ interfaces for managing I/O readiness, the \aSocket()\ builder for creating TCP and UDP sockets, and comprehensive socket option classes (\SocketOptions\, \TypeOfService\) for configuring behaviors like backlog size, buffer sizes, and broadcast. The change also introduces specific interfaces for datagram handling (\Datagram\, \BoundDatagramSocket\, \ConnectedDatagramSocket\) and adds a convenience property \ServerSocket.port\ to easily retrieve the bound port of a server socket.
ktor-network/common · high confidence
Standardize Chrome test configuration and disable global Mocha timeout
The test environment now uses a dedicated Chrome headless launcher with specific flags (such as --no-sandbox and --disable-web-security) to ensure stable execution, particularly in containerized or CI environments. Additionally, the global Mocha test timeout has been disabled (set to 0) to allow individual tests to manage their own timeouts, preventing premature test failures due to slow operations.
karma · high confidence
Swagger UI plugin adds deep linking, OAuth2 redirect support, and OpenAPI 3.1 compatibility warnings
The Swagger UI plugin now supports deep linking via a new \deepLinking\ configuration option, serves an \oauth2-redirect.html\ endpoint to handle OAuth2 flows (with a configurable \oauth2RedirectUrl\ for reverse proxy scenarios), and includes a favicon. It also introduces a warning when an OpenAPI 3.1.x specification is served with a Swagger UI version older than 5.0.0, as older versions do not support the 3.1 spec, and defaults to Swagger UI version 5.31.0.
ktor-server/ktor-server-plugins/ktor-server-swagger/jvm/src/io/ktor/server/plugins/swagger · high confidence
Thymeleaf plugin rewritten for new API with enhanced response options
The Thymeleaf plugin has been rewritten to align with the new Ktor plugins API, introducing a new \respondTemplate\ extension function and a \ThymeleafContent\ class. This change allows users to explicitly set the HTTP status code when responding with a template, pass a specific locale for rendering, and return specific Thymeleaf fragments from routes. The plugin now supports null values in the template model and integrates with the new \BeforeResponseTransform\ hook for processing.
ktor-server/ktor-server-plugins/ktor-server-thymeleaf/jvm · high confidence
Tomcat engine module deprecated in favor of Jakarta variant
The \ktor-server-tomcat\ module is now deprecated and will be removed in the next major release because it relies on an outdated version of Tomcat. Users should migrate to the \ktor-server-tomcat-jakarta\ module. The existing \Tomcat\ engine factory and \EngineMain\ entry points remain available but are marked with deprecation annotations to guide this transition.
ktor-server/ktor-server-tomcat/jvm · high confidence
Unified fetch execution for browser and Node.js environments
The JS client engine now uses a shared \commonFetch\ utility to handle HTTP requests, allowing the same code path to operate in both browser and Node.js contexts. For browser environments, the standard \fetch\ API is used directly, while Node.js environments apply custom \nodeOptions\ to the request configuration before calling fetch. This change also ensures that the underlying fetch operation is automatically aborted if the client call is cancelled or completes, improving resource management across both platforms.
ktor-client/ktor-client-core/js/src/io/ktor/client/engine/js/compatibility · high confidence
WebJars plugin adds caching headers and ETag support by default
The WebJars plugin now automatically includes caching headers and ETags for served assets, improving performance by allowing browsers to cache static resources more effectively. This change is part of a broader rewrite of the plugin to the new API, which also introduces internal utilities for extracting WebJar paths and handling input streams as outgoing content.
ktor-server-webjars · high confidence
WebJars plugin now includes caching headers and ETag support by default
The WebJars plugin has been rewritten to automatically include Last-Modified, ETag, and Cache-Control (Max-Age) headers in HTTP responses for served assets. By default, the ETag is derived from the WebJar version, the Max-Age is set to 90 days, and the Last-Modified date is based on the application's start time. These features require the ConditionalHeaders and CachingHeaders plugins to be installed, and all behaviors are configurable via the new WebjarsConfig DSL.
ktor-server/ktor-server-plugins/ktor-server-webjars/jvm · high confidence
WebRTC client API stabilization and data channel support
The \ktor-client-webrtc\ module introduces a stable public API surface, including the new \WebRtcClientEngineFactory\ interface for platform-specific engine creation and a comprehensive \WebRtcPeerConnection\ class that exposes connection state, ICE candidates, and statistics via Kotlin Flows. Users can now utilize data channels for bidirectional communication, with dedicated \WebRtcDataChannel\ and \DataChannelEvent\ types, alongside refined media track creation through the \MediaTrackFactory\ interface. This change also standardizes configuration options, such as making \IceServer.urls\ a list, and adds platform-specific implementations for Android, iOS, JS, and WASM.
ktor-client/ktor-client-webrtc/api · high confidence
WebSocket control frame validation and channel backpressure configuration
The WebSocket implementation now enforces the RFC 6455 limit of 125 bytes for control frames (Close, Ping, Pong), throwing a specific \FrameTooBigException\ or \ProtocolViolationException\ when this limit is exceeded. Additionally, users can now configure backpressure for incoming and outgoing frame queues via \WebSocketChannelsConfig\, allowing them to set channel capacities and define overflow strategies (suspend or close) to manage memory and flow control.
ktor-shared/ktor-websockets/common · high confidence
WebSocket protocol validation and extension handling improvements
The WebSocket implementation now enforces stricter protocol compliance by validating control frame sizes (limiting payloads to 125 bytes as per RFC 6455) and rejecting improper continuation frames or fragmented control frames. The deflate extension has been fixed to handle recursion issues and correctly process tail messages during decompression. Additionally, the API now provides clearer close reason codes and improved extension header parsing for better interoperability.
ktor-websockets · high confidence
WebSocket routing now returns Route and supports extension negotiation
The \webSocket\ and \webSocketRaw\ routing builders now return the \Route\ instance, allowing them to be chained or stored in route variables. Additionally, \webSocketRaw\ accepts a \negotiateExtensions\ parameter to control whether installed WebSocket extensions are negotiated during the handshake, and the \WebSockets\ plugin configuration exposes a \channels\ block to set backpressure limits on incoming and outgoing frame queues.
ktor-server-websockets · high confidence
WebSocket serialization now supports explicit TypeInfo for nullable types
The \WebsocketChannelSerialization\ module introduces \sendSerializedBase\ and \receiveDeserializedBase\ functions that accept an explicit \TypeInfo\ parameter alongside the existing reified generic versions. This change enables proper handling of nullable types during deserialization; the implementation now checks \typeInfo.isNullable\ to allow null results without throwing a \WebsocketDeserializeException\, preventing errors when receiving null JSON bodies or nullable fields.
ktor-shared/ktor-websocket-serialization/common · high confidence
Zstd encoding implementation migrated to standalone JVM module
The Zstd content encoder is now provided as a standalone module on the JVM, introducing a new implementation that utilizes the streaming API from the \com.github.luben.zstd\ library. This change replaces previous approaches with a streaming-based compression and decompression mechanism, which improves performance and correctly handles source data split across multiple frames.
ktor-shared/ktor-encoding-zstd/jvm · high confidence
Zstd encoding moved to standalone module
The Zstd content encoder has been relocated to the new ktor-encoding-zstd module, making it available as a separate dependency rather than part of the shared Ktor core. This change allows users to include Zstd support only when needed, reducing the footprint for applications that do not use this compression algorithm.
ktor-encoding-zstd · high confidence
ktor-utils module rewritten for Kotlin Multiplatform with zero-allocation collections
The ktor-utils module has been completely rewritten to support Kotlin Multiplatform (JVM, Native, JS, WasmJS), introducing a new public API surface. Key changes include a new \AttributeKey\ class that identifies instances by identity rather than name, a new \CaseInsensitiveMap\ implementation using open-addressing hash tables to eliminate wrapper object allocations, and a new \StringValues\ interface with a builder pattern for efficient HTTP header storage. The module also adds platform detection utilities (\PlatformUtils\), common date/time enums (\Month\, \WeekDay\), and native-specific thread utilities for Android Native targets.
ktor-utils · high confidence
Fixes
Fix MDC context propagation in client response body logging
The response observer plugin now correctly captures the MDC (Mapped Diagnostic Context) from the current coroutine context when logging client response bodies. This ensures that diagnostic context data is preserved and available in logs, resolving an issue where MDC information was previously lost during response body observation.
ktor-client/ktor-client-core/jvm/src/io/ktor/client/plugins/observer · high confidence
Fix iOS publication by adding Darwin stub
A new stub file (Stub.kt) has been added to the Ktor Client iOS Darwin module to resolve publication issues. This file contains a minimal internal function placeholder, ensuring the module builds and publishes correctly for iOS targets.
ktor-client/ktor-client-ios/darwin · high confidence
JS client: Renamed toRaw helper to avoid Vue/Vite bundling collisions
The internal \toRaw\ function in the Ktor JS client core has been renamed to \ktor\_toRaw\ via \@JsName\ to prevent name collisions with Vue's \toRaw\ export when using Vite bundlers. This change ensures that the Ktor client utilities do not interfere with Vue's reactivity system in shared JavaScript environments, resolving potential runtime conflicts during the build process.
ktor-client/ktor-client-core/js/src/io/ktor/client/utils · high confidence
Test coverage
Add web-platform test infrastructure files; Added Android instrumentation tests for WebRTC client setup and permissions; Added HTTP/2 test suite for Ktor Client; Added JS and wasmJs test result implementations; Added JVM tests for CallLogging plugin behavior and ANSI terminal handling; Added JVM tests for SSE streaming, client configuration inheritance, and HTTPS security; Added JVM tests for client content negotiation; Added JVM-specific tests for the Dependency Injection plugin; Added JVM/Posix-specific coroutine utilities for test host; Added POSIX-specific test base for Ktor server testing; Added WebSocket engine test suite; Added base test class for Kotlinx serialization; Added base test infrastructure for Ktor kotlinx serialization; Added comprehensive test coverage for Ktor Client Auth plugin; Added iOS-specific test utilities for WebRTC client; Added integration and unit tests for the RateLimit plugin; Added internal WebSocket testing infrastructure for the JVM test host; Added platform-specific test infrastructure for Ktor client engines; Added regression tests for iOS WebRTC delegate retention and video capturer behavior; Added server test suites for HTTP, configuration, stress, and plugins; Added stub tests for Android Native WebRTC client; Added test coverage for Curl engine capabilities and behaviors; Added test coverage for Ktor client core features; Added test coverage for StatusPages plugin behavior; Added test coverage for client plugins; Added test for DigestAuthProvider initialization under thread saturation; Added test for StethoTracer; Added test for request cancellation memory leak fix; Added test suite for Apache HTTP client engine; Added test utilities and mocks for WebRTC client testing; Added test utility classes for client testing; Added test utility for multipart form data serialization; Added tests for CSRF plugin validation and configuration; Added tests for HTTP cache file storage behavior; Added tests for HTTP header merging behavior; Added tests for Jetty HTTP/2 engine client caching; Added tests for Ktor Client CallId plugin behavior; Added tests for Ktor client content encoding plugin; Added tests for MockEngine execution order and request inspection; Added tests for Node.js-specific fetch options in Ktor Client JS; Added tests for OpenAPI documentation generation from file and routing sources; Added tests for RequestBodyLimit plugin and ByteReadChannel limit application; Added tests for RequestValidation plugin; Added tests for Swagger UI configuration and security; Added tests for WebRTC data channels, engine, and media tracks; Added tests for client core components; Added tests for multipart Blob support in Ktor Client; Added tests for the Ktor Dependency Injection plugin; Added unit tests for the deprecated Darwin Legacy engine; Expanded JVM client test coverage; Expanded common test suite for Ktor Client; Migrate serialization tests to testApplication DSL; New JUnit 5 test utilities for serialization and error collection; New JVM server test suites for client certificates, compression, connections, content, hooks, and lifecycle; New JVM test infrastructure for server engine testing; New KLib ABI validation for Jetty Jakarta client engine; New base test class for Ktor client engine tests; New base test infrastructure for Ktor client engines; New common test-host implementation for JS and WasmJS targets; New test infrastructure with unified timeouts and retry support; WebSocket plugin test coverage and default port fix.
Dependencies
Introduce build-logic for centralized build configuration
The project now includes a \build-logic\ subproject that centralizes build configuration. This module defines the Kotlin DSL for the build, integrating dependencies for the Kotlin compiler, serialization, AtomicFU, Dokka, Develocity, Gradle Doctor, Kotlinter, Maven publishing, and the Android Gradle Plugin. It also introduces a \kdoc-annotator\ application to automate KDoc annotation across the codebase, excluding specific build and test directories.
(dependencies) · high confidence
Updated bundled libcurl headers to version 8.20.0
The Ktor Curl client's bundled libcurl headers in the desktop interop layer have been updated to version 8.20.0. This update brings the interop layer in sync with the latest libcurl release, ensuring compatibility with new features and fixes available in the underlying HTTP library.
ktor-client/ktor-client-curl/desktop/interop · high confidence
Upgrade Gradle wrapper to version 9.7.1
The project's Gradle wrapper has been updated to use Gradle 9.7.1. This change ensures that builds are executed with the specified version of the Gradle build tool, pulling the distribution from the configured cache redirector. Users will benefit from the features, performance improvements, and bug fixes included in this specific Gradle release.
gradle/wrapper · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 45 → 63 (+18.4)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 85 → 90 (+4.6)
- Architecture 96 → 96 (-0.0)
- Maturity 49 → 60 (+11.6)
- Readiness 36 → 58 (+22.5)
- Security 39 → 61 (+22.5)
Resolved (117)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- Duplicated block (11 lines × 2) (ktor-server/ktor-server-core/jvm/src/io/ktor/server/http/content/StaticContent.kt)
- Duplicated block (12 lines × 2) (ktor-client/ktor-client-core/js/src/io/ktor/client/engine/js/JsClientEngine.kt)
- Duplicated block (12 lines × 2) (ktor-network/posix/src/io/ktor/network/sockets/UDPSocketBuilderNative.kt)
- Duplicated block (12 lines × 2) (ktor-server/ktor-server-test-suites/jvm/src/io/ktor/server/testing/suites/ContentTestSuite.kt)
- Duplicated block (12 lines × 2) (ktor-server/ktor-server-test-suites/jvm/src/io/ktor/server/testing/suites/SustainabilityTestSuite.kt)
- Duplicated block (12 lines × 3) (ktor-server/ktor-server-test-suites/jvm/src/io/ktor/server/testing/suites/ContentTestSuite.kt)
- Duplicated block (13 lines × 2) (ktor-network/jvm/src/io/ktor/network/sockets/DatagramSocketImpl.kt)
- Duplicated block (13 lines × 2) (ktor-utils/common/src/io/ktor/util/HashFunction.kt)
- Duplicated block (14 lines × 2) (ktor-server/ktor-server-test-suites/common/src/io/ktor/server/testing/suites/WebSocketEngineSuite.kt)
- Duplicated block (14 lines × 2) (ktor-server/ktor-server-test-suites/jvm/src/io/ktor/server/testing/suites/ContentTestSuite.kt)
- Duplicated block (15 lines × 2) (ktor-network/nix/src/io/ktor/network/selector/SelectUtilsNix.kt)
- Duplicated block (16 lines × 2) (ktor-compiler-plugin/src/io/ktor/openapi/ir/inference/ResourceRouteCallInference.kt)
- Duplicated block (16 lines × 2) (ktor-network/jvm/src/io/ktor/network/sockets/JavaSocketOptions.kt)
- Duplicated block (16 lines × 2) (ktor-server/ktor-server-core/jvm/src/io/ktor/server/http/content/StaticContent.kt)
- Duplicated block (16 lines × 2) (ktor-server/ktor-server-test-suites/jvm/src/io/ktor/server/testing/suites/SustainabilityTestSuite.kt)
- Duplicated block (17 lines × 2) (ktor-server/ktor-server-test-suites/common/src/io/ktor/server/testing/suites/HttpServerCommonTestSuite.kt)
- Duplicated block (17 lines × 3) (ktor-utils/common/src/io/ktor/util/CaseInsensitiveMap.kt)
- Duplicated block (18 lines × 2) (ktor-server/ktor-server-core/common/src/io/ktor/server/engine/EmbeddedServer.kt)
- …and 97 more
New (377)
- AbstractAtomicDesc.prepare (cognitive 16) (ktor-utils/common/src/io/ktor/util/internal/LockFreeLinkedList.kt)
- AcceptEncoding.match (cognitive 16) (ktor-http/common/src/io/ktor/http/header/AcceptEncoding.kt)
- BaseApplicationResponse.commitHeaders (cognitive 16) (ktor-server/ktor-server-core/common/src/io/ktor/server/engine/BaseApplicationResponse.kt)
- BaseApplicationResponse.commitHeaders (cyclomatic 16) (ktor-server/ktor-server-core/common/src/io/ktor/server/engine/BaseApplicationResponse.kt)
- ByteReadChannelOperationsKt.internalReadLineTo (cognitive 49) (ktor-io/common/src/io/ktor/utils/io/ByteReadChannelOperations.kt)
- ByteReadChannelOperationsKt.internalReadLineTo (cyclomatic 35) (ktor-io/common/src/io/ktor/utils/io/ByteReadChannelOperations.kt)
- CIOReaderKt.attachForReadingDirectImpl (cognitive 16) (ktor-network/jvm/src/io/ktor/network/sockets/CIOReader.kt)
- CIOReaderKt.attachForReadingImpl (cognitive 17) (ktor-network/posix/src/io/ktor/network/sockets/CIOReader.kt)
- CIOWriterKt.attachForWritingDirectImpl (cognitive 17) (ktor-network/jvm/src/io/ktor/network/sockets/CIOWriter.kt)
- CORSKt.buildPlugin (cognitive 19) (ktor-server/ktor-server-plugins/ktor-server-cors/common/src/io/ktor/server/plugins/cors/CORS.kt)
- CORSKt.buildPlugin (cyclomatic 18) (ktor-server/ktor-server-plugins/ktor-server-cors/common/src/io/ktor/server/plugins/cors/CORS.kt)
- CallHandlerAnalyzer.visitCall (cognitive 20) (ktor-compiler-plugin/src/io/ktor/openapi/ir/CallHandlerAnalyzer.kt)
- Change coupling: BasicAuthProvider.kt ↔ BearerAuthProvider.kt (ktor-client/ktor-client-plugins/ktor-client-auth/common/src/io/ktor/client/plugins/auth/providers/BasicAuthProvider.kt)
- Change coupling: BasicAuthProvider.kt ↔ DigestAuthProvider.kt (ktor-client/ktor-client-plugins/ktor-client-auth/common/src/io/ktor/client/plugins/auth/providers/BasicAuthProvider.kt)
- Change coupling: DelegatedCall.kt ↔ Logging.kt (ktor-client/ktor-client-core/common/src/io/ktor/client/plugins/observer/DelegatedCall.kt)
- Change coupling: DelegatedCall.kt ↔ ResponseObserver.kt (ktor-client/ktor-client-core/common/src/io/ktor/client/plugins/observer/DelegatedCall.kt)
- Change coupling: GsonConverter.kt ↔ JacksonConverter.kt (ktor-shared/ktor-serialization/ktor-serialization-gson/jvm/src/GsonConverter.kt)
- Change coupling: JsClientEngine.kt ↔ JsUtils.js.kt (ktor-client/ktor-client-core/js/src/io/ktor/client/engine/js/JsClientEngine.kt)
- Change coupling: JsClientEngine.kt ↔ Utils.kt (ktor-client/ktor-client-core/js/src/io/ktor/client/engine/js/JsClientEngine.kt)
- Change coupling: JsonPlugin.kt ↔ GsonSerializer.kt (ktor-client/ktor-client-plugins/ktor-client-json/common/src/io/ktor/client/plugins/json/JsonPlugin.kt)
- …and 357 more
Changes since last survey
- 106 commits — 85 feature/other, 21 fixes
By area
- gradle/libs.versions.toml — 19 commits
- ktor-server/ktor-server-plugins — 13 commits
- ktor-server/ktor-server-netty — 11 commits
- ktor-http/common — 7 commits
- ktor-server/ktor-server-core — 6 commits
- ktor-client/ktor-client-plugins — 5 commits
- (repo) — 4 commits
- (root) — 3 commits
- ktor-shared/ktor-openapi-schema — 3 commits
- build-logic/src — 2 commits
- ktor-client/ktor-client-core — 2 commits
- ktor-client/ktor-client-okhttp — 2 commits
- ktor-compiler-plugin/testData — 2 commits
- ktor-io/common — 2 commits
- ktor-server/ktor-server-cio — 2 commits
- ktor-server/ktor-server-jetty-jakarta — 2 commits
- ktor-utils/jvm — 2 commits
- .devcontainer/Dockerfile — 1 commit
- .github/workflows — 1 commit
- build-logic/kdoc-annotator — 1 commit
Notable commits
- fix: Fix Jetty bodyWriter leaking suspended coroutines on aborted writes
- fix: Fix KTOR-9722 cannot be initialized with a congested pool (#5768)
- fix: Fix KTOR-9731 CIO: HttpRequestLifecycle cancels call too soon, sending an incomplete response (#5819)
- fix: Fix KTOR-9760 Digest Auth: URI and HA2 are empty for a URL without a path (#5805)
- fix: Fix KTOR-9794 Digest Auth: NullPointerException when the server does not expect Digest auth (#5870)
- fix: Fix KTOR-9816 Escape $ in application.yaml file (#5827)
- fix: Fix KTOR-9825 Unescape quoted-pair at the end of a header parameter value
- fix: Fix KTOR-9827 Authorization header removed from refresh token request (#5826)
- fix: Fix KTOR-9892 Digest Auth client: nc and qop ... (#5875)
- fix: Fix KTOR-9901 Client tests fail on Java 8 (#5885)
- fix: Fix Netty handler application referencing
- fix: Fixes from codex for 3.6 (#5824)
- fix: KTOR-8524 Fix lifecycle events in Tomcat ServletApplicationEngine (#5856)
- fix: KTOR-9443 Fix invalid IR encoding with extension values
- fix: KTOR-9477 Fix mac comparison to prevent session forgery
- fix: KTOR-9657 Fix shortening recursive refs in schema (#5809)
- fix: KTOR-9788 Fix exception in call handler coroutine due to bad state (#5835)
- fix: KTOR-9875 Fix Netty runningLimit enforcement and reparent to handlerJob
- fix: KTOR-9875 Fix bottleneck in Netty pipelining
- fix: KTOR-9875 Fix double release on h2c upgrade
- …and 86 more
Architecture
- Containers 0 added · 0 removed · contexts 72 added · 0 removed · edges 228 added · 0 removed
Added bounded contexts (72)
- build-logic
- kdoc-annotator
- ktor-client-android
- ktor-client-apache
- ktor-client-apache5
- ktor-client-auth
- ktor-client-cio
- ktor-client-core
- ktor-client-curl
- ktor-client-darwin
- ktor-client-darwin-legacy
- ktor-client-encoding
- ktor-client-java
- ktor-client-jetty
- ktor-client-jetty-jakarta
- ktor-client-json
- ktor-client-logging
- ktor-client-mock
- ktor-client-okhttp
- ktor-client-resources
- …and 52 more
Added dependency edges (228)
- ktor-client-android → ktor-client-core
- ktor-client-android → ktor-io
- ktor-client-apache → ktor-client-core
- ktor-client-apache → ktor-http
- ktor-client-apache → ktor-io
- ktor-client-apache5 → ktor-client-core
- ktor-client-apache5 → ktor-http
- ktor-client-apache5 → ktor-io
- ktor-client-auth → ktor-client-core
- ktor-client-auth → ktor-http (coupling)
- ktor-client-auth → ktor-io
- ktor-client-auth → ktor-utils
- ktor-client-cio → ktor-client-core
- ktor-client-cio → ktor-http (coupling)
- ktor-client-cio → ktor-io
- ktor-client-cio → ktor-network
- ktor-client-cio → ktor-network-tls
- ktor-client-cio → ktor-utils
- ktor-client-core → ktor-events
- ktor-client-core → ktor-http (coupling)
- …and 208 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
ktorio/ktor was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit d08fd0382b2acf314b2beb430b66ba148845a892 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-dd72cc24c749.