API7 Gateway 3.9.13
CAS Auth — The cas-auth plugin now requires a cookie.secret value of at least 32 characters.
Release Date: 2026-05-22
Breaking Changes
Plugins
-
CAS Auth
Upgrade note
The
cas-authplugin now requires acookie.secretvalue of at least 32 characters. The plugin uses this secret to sign and verify theCAS_REQUEST_URIcookie, preventing a client-controlled cookie from changing the post-login redirect target.Before upgrading, update every existing
cas-authconfiguration with a sharedcookie.secretacross all gateway nodes.
Upgrade Notes
Upgrade note — proxy cache behavior
The proxy-cache and graphql-proxy-cache plugins now use safer cache behavior by default.
For proxy-cache, responses are isolated by consumer when the request has an authenticated consumer or remote user, unless the configured cache_key already contains an identity-bearing variable. The in-memory strategy also no longer caches responses whose upstream Cache-Control contains private, no-store, or no-cache, and both in-memory and on-disk strategies skip responses with Set-Cookie unless cache_set_cookie is set to true.
For graphql-proxy-cache, cache keys now include host, route, service, and consumer identity by default, and responses with Set-Cookie are skipped unless cache_set_cookie is set to true.
If you intentionally share cached responses across consumers, set consumer_isolation: false. If you intentionally cache responses with Set-Cookie, set cache_set_cookie: true.
Features
Plugins
- AI Proxy (opens in Plugin Hub docs)
- Improved OpenAI-compatible streaming response throughput by reducing per-token flush and SSE parsing overhead. In internal single-worker benchmarks with a mock OpenAI upstream, peak streaming throughput increased from 44,102.6 tokens/s to 138,158.7 tokens/s, about 3.13x higher.
- Improved large JSON request body handling for AI requests that use
post_arg.*route variables. In internal benchmarks with 1 MB, 5 MB, and 10 MB OpenAI Chat Completions-compatible request bodies, throughput improved by 5.15x-5.35x when the gateway forwarded the original body, and by 2.47x-2.67x when the gateway rewrote the body before forwarding. - Added
streaming_flush_interval_msto control periodic flushing for streaming responses. The default is 10 ms, which reduces per-chunk flush overhead while keeping streaming latency bounded.
- OpenAPI to MCP (opens in Plugin Hub docs)
- Added
allowed_hoststo restrict which hosts a dynamically resolvedbase_urlmay target. Whenallowed_hostsis not configured, existing behavior is unchanged. The plugin also rejects malformed resolved URLs and non-HTTP(S) schemes with HTTP 400.
- Added
- Proxy Cache (opens in Plugin Hub docs) and GraphQL Proxy Cache (opens in Plugin Hub docs)
- Added
consumer_isolationandcache_set_cookieoptions to control the new safer cache behavior described in the upgrade note.
- Added
Control Plane
- Alert policies can now automatically create Debug Sessions when alert conditions are triggered. Alert history records whether debug session creation succeeded and includes the created session IDs or error details.
- Fallback Control Plane storage now supports S3-compatible path-style endpoints, which enables integrations with providers such as MinIO that require bucket names in the URL path.
Console (Dashboard)
- Added Debug Sessions UI under Gateway Groups, including session list, create, stop, delete, trace list, trace waterfall detail, search and filtering, minimap, URL state sync, field formatting, and keyboard navigation.
- Added a copy button to delete/disable confirmation dialogs so users can copy the resource identifier before confirming destructive operations.
- Added search support to the service and route selector on the monitoring page.
Developer Portal
- Added a Helm chart for deploying the Developer Portal on Kubernetes.
Fixes
Plugins
- OpenID Connect (opens in Plugin Hub docs)
- Fixed issue: Client-supplied identity headers (
X-Access-Token,X-Userinfo,X-ID-Token,X-Refresh-Token) could be forwarded upstream instead of values validated by the plugin. These headers are now cleared or overwritten so upstream services only receive plugin-controlled identity values.
- Fixed issue: Client-supplied identity headers (
- Data Mask (opens in Plugin Hub docs)
- Fixed issue: The plugin could crash or produce incorrect masked output for multi-value query parameters, valueless query parameters, non-string JSON values, regex failures, and form parsing errors. It also no longer logs original sensitive values when regex substitution fails.
- ACL (opens in Plugin Hub docs)
- Fixed issue:
external_user_label_field_parserandexternal_user_label_field_separatorcould be applied to consumer labels, causing incorrect allow or deny decisions. They now apply only to external-user label extraction.
- Fixed issue:
- Chaitin WAF (opens in Plugin Hub docs) and Wolf RBAC
- Fixed issue: The plugins used raw client-supplied IP headers when sending client IP information to their backend services. They now use the trusted real client IP resolved by the gateway.
- Client Control
- Fixed issue: When a Global Rule plugin read the request body in the access phase,
client-controlon a route or service could not apply its body size override first, causing large requests to be rejected unexpectedly.
- Fixed issue: When a Global Rule plugin read the request body in the access phase,
Control Plane
- Fixed issue: Deleting a Secret that was still referenced by other resources could leave dangling references and cause gateway runtime errors. Secret deletion is now rejected while references exist.
- Fixed issue: Data Plane Manager certificates could fail hostname verification for older Data Planes when
dp_manager_addresscontained both domain names and IP addresses. - Fixed issue: Malformed gateway version strings in heartbeat payloads could crash compatibility validation. They are now handled as incompatible versions instead of causing a panic.
- Fixed issue: Invalid stream route CIDR/IP values and invalid
post_arg.*JSON path expressions could be accepted by the Control Plane and later rejected or dropped by the Data Plane. These configurations are now rejected at the API level. - Fixed issue: Sensitive encrypted field values could appear in logs when decrypting
AesEncryptfields failed. Logs now include only the value length.
Data Plane
- Fixed issue: Stream routes that referenced a service could keep using stale service-level plugin configuration until the route changed or the worker restarted.
- Fixed issue: Gateway workers could crash during startup when the etcd or DP Manager response was missing expected revision headers. The gateway now logs the problem and retries.
- Fixed issue: Stream workers could crash during config sync when status reporting was enabled.
- Fixed issue: The standard gateway runtime image did not honor the
TZenvironment variable for IANA timezone names because timezone data was missing. - Fixed issue: The tracer could crash on HTTPS or HTTP/2 keepalive connections when tracing was enabled.
- Fixed issue: The gateway CLI wrote Control Plane mTLS client certificate files to the system temporary directory with overly broad permissions. These files are now written under the gateway config certificate directory with restricted permissions.
Console (Dashboard)
- Fixed issue: The OpenID Connect plugin code editor could collapse or become unreachable on small or highly zoomed viewports.
- Fixed issue: Deleting a published service from the service list could show a misleading "service not found" error toast after deletion succeeded.
- Fixed issue: List table defaults could be mutated by one page and leak invalid sorting parameters into the Gateway Instances page.
- Fixed issue: The plugin view drawer could show stale or incorrect JSON when switching between local, global, and metadata tabs.
- Fixed issue: Cached gateway group or portal IDs that no longer existed could lead to blank pages or 404 error toasts instead of redirecting to a valid fallback.