API7 Gateway 3.8.9
JWT Auth — Added store_in_ctx parameter to store validated JWT object in request context.
Release Date: 2025-08-11
Features
Plugins
- JWT Auth (opens in Plugin Hub docs)
- Added
store_in_ctxparameter to store validated JWT object in request context. When set to true (default is false), the plugin stores the validated JWT object in the request context, useful for custom plugins that need to parse JWT to extract permissions.
- Added
- Workflow (opens in Plugin Hub docs)
- Added support for
limit-connplugin integration, allowing dynamic connection limit strategies based on user requests and current APISIX load pressure.
- Added support for
Data Plane
- Supported Kubernetes 1.18 in API7 Enterprise Ingress Controller.
- Backported Chaitin WAF plugin from APISIX to API7 Enterprise.
Console (Dashboard)
- Added audit log record TTL configuration option, allowing users to set automatic deletion time for audit log table data. Default value is 60 days.
- Optimized Dataplane manager SQL statements when updating cached Consumer data.
Developer Portal
- Added support for CAS login.
Fixes
Plugins
- OAS Validator (opens in Plugin Hub docs)
- Fixed issue: Adjusted error level for detailed response errors from
errortowarnwhenverbose_errorsis enabled.
- Fixed issue: Adjusted error level for detailed response errors from
- JWT Auth (opens in Plugin Hub docs)
- Fixed issue: Plugin failed to validate
expclaim whenclaims_to_verify: ["exp"]is set.
- Fixed issue: Plugin failed to validate
- Consumer Restriction (opens in Plugin Hub docs)
- Fixed issue: Improved error messages when using
consumer-restrictionwithbasic-authplugin. Whentypeis set toconsumer_group_idwith blacklist configuration, non-blacklisted consumers now receive appropriate error messages.
- Fixed issue: Improved error messages when using
- Kafka Logger (opens in Plugin Hub docs)
- Fixed issue: Performance degradation when
max_pending_entriesis enabled in service configuration with many routes. The issue was caused by each route creating separate batch processor buffers due to plugin conf deepcopy during service and route merging.
- Fixed issue: Performance degradation when
- Limit Count Advanced (opens in Plugin Hub docs)
- Fixed issue: Plugin panic triggering shared memory deadlock.
Data Plane
- Fixed issue: Error information could not be properly recorded when reading request body in
ctxvariables.
Console (Dashboard)
- Fixed issue: Chinese labels imported from OpenAPI files were displayed as Chinese pinyin instead of original Chinese characters.
- Fixed issue: Route information occasionally stuck in loading state after frequent route switching.
- Fixed issue: PUT API could create credentials for non-existent consumers.
- Fixed issue: Language switching inconsistency where switching to English on login page would revert to Chinese after login.
Developer Portal
- Fixed issue: SAML/OIDC logout did not properly sign out from IDP login state. After SSO logout, only Control Plane login state was cleared while IDP login state remained, causing automatic login success when clicking SSO login button again.