Docs

API7 Gateway 3.9.13

CAS Auth — The cas-auth plugin now requires a cookie.secret value of at least 32 characters.

Release Date: 2026-05-22

Breaking Changes

Plugins

  • CAS Auth

    Upgrade note

    The cas-auth plugin now requires a cookie.secret value of at least 32 characters. The plugin uses this secret to sign and verify the CAS_REQUEST_URI cookie, preventing a client-controlled cookie from changing the post-login redirect target.

    Before upgrading, update every existing cas-auth configuration with a shared cookie.secret across all gateway nodes.

Upgrade Notes

Upgrade note — proxy cache behavior

The proxy-cache and graphql-proxy-cache plugins now use safer cache behavior by default.

For proxy-cache, responses are isolated by consumer when the request has an authenticated consumer or remote user, unless the configured cache_key already contains an identity-bearing variable. The in-memory strategy also no longer caches responses whose upstream Cache-Control contains private, no-store, or no-cache, and both in-memory and on-disk strategies skip responses with Set-Cookie unless cache_set_cookie is set to true.

For graphql-proxy-cache, cache keys now include host, route, service, and consumer identity by default, and responses with Set-Cookie are skipped unless cache_set_cookie is set to true.

If you intentionally share cached responses across consumers, set consumer_isolation: false. If you intentionally cache responses with Set-Cookie, set cache_set_cookie: true.

Features

Plugins

  • AI Proxy (opens in Plugin Hub docs)
    • Improved OpenAI-compatible streaming response throughput by reducing per-token flush and SSE parsing overhead. In internal single-worker benchmarks with a mock OpenAI upstream, peak streaming throughput increased from 44,102.6 tokens/s to 138,158.7 tokens/s, about 3.13x higher.
    • Improved large JSON request body handling for AI requests that use post_arg.* route variables. In internal benchmarks with 1 MB, 5 MB, and 10 MB OpenAI Chat Completions-compatible request bodies, throughput improved by 5.15x-5.35x when the gateway forwarded the original body, and by 2.47x-2.67x when the gateway rewrote the body before forwarding.
    • Added streaming_flush_interval_ms to control periodic flushing for streaming responses. The default is 10 ms, which reduces per-chunk flush overhead while keeping streaming latency bounded.
  • OpenAPI to MCP (opens in Plugin Hub docs)
    • Added allowed_hosts to restrict which hosts a dynamically resolved base_url may target. When allowed_hosts is not configured, existing behavior is unchanged. The plugin also rejects malformed resolved URLs and non-HTTP(S) schemes with HTTP 400.
  • Proxy Cache (opens in Plugin Hub docs) and GraphQL Proxy Cache (opens in Plugin Hub docs)
    • Added consumer_isolation and cache_set_cookie options to control the new safer cache behavior described in the upgrade note.

Control Plane

  • Alert policies can now automatically create Debug Sessions when alert conditions are triggered. Alert history records whether debug session creation succeeded and includes the created session IDs or error details.
  • Fallback Control Plane storage now supports S3-compatible path-style endpoints, which enables integrations with providers such as MinIO that require bucket names in the URL path.

Console (Dashboard)

  • Added Debug Sessions UI under Gateway Groups, including session list, create, stop, delete, trace list, trace waterfall detail, search and filtering, minimap, URL state sync, field formatting, and keyboard navigation.
  • Added a copy button to delete/disable confirmation dialogs so users can copy the resource identifier before confirming destructive operations.
  • Added search support to the service and route selector on the monitoring page.

Developer Portal

  • Added a Helm chart for deploying the Developer Portal on Kubernetes.

Fixes

Plugins

  • OpenID Connect (opens in Plugin Hub docs)
    • Fixed issue: Client-supplied identity headers (X-Access-Token, X-Userinfo, X-ID-Token, X-Refresh-Token) could be forwarded upstream instead of values validated by the plugin. These headers are now cleared or overwritten so upstream services only receive plugin-controlled identity values.
  • Data Mask (opens in Plugin Hub docs)
    • Fixed issue: The plugin could crash or produce incorrect masked output for multi-value query parameters, valueless query parameters, non-string JSON values, regex failures, and form parsing errors. It also no longer logs original sensitive values when regex substitution fails.
  • ACL (opens in Plugin Hub docs)
    • Fixed issue: external_user_label_field_parser and external_user_label_field_separator could be applied to consumer labels, causing incorrect allow or deny decisions. They now apply only to external-user label extraction.
  • Chaitin WAF (opens in Plugin Hub docs) and Wolf RBAC
    • Fixed issue: The plugins used raw client-supplied IP headers when sending client IP information to their backend services. They now use the trusted real client IP resolved by the gateway.
  • Client Control
    • Fixed issue: When a Global Rule plugin read the request body in the access phase, client-control on a route or service could not apply its body size override first, causing large requests to be rejected unexpectedly.

Control Plane

  • Fixed issue: Deleting a Secret that was still referenced by other resources could leave dangling references and cause gateway runtime errors. Secret deletion is now rejected while references exist.
  • Fixed issue: Data Plane Manager certificates could fail hostname verification for older Data Planes when dp_manager_address contained both domain names and IP addresses.
  • Fixed issue: Malformed gateway version strings in heartbeat payloads could crash compatibility validation. They are now handled as incompatible versions instead of causing a panic.
  • Fixed issue: Invalid stream route CIDR/IP values and invalid post_arg.* JSON path expressions could be accepted by the Control Plane and later rejected or dropped by the Data Plane. These configurations are now rejected at the API level.
  • Fixed issue: Sensitive encrypted field values could appear in logs when decrypting AesEncrypt fields failed. Logs now include only the value length.

Data Plane

  • Fixed issue: Stream routes that referenced a service could keep using stale service-level plugin configuration until the route changed or the worker restarted.
  • Fixed issue: Gateway workers could crash during startup when the etcd or DP Manager response was missing expected revision headers. The gateway now logs the problem and retries.
  • Fixed issue: Stream workers could crash during config sync when status reporting was enabled.
  • Fixed issue: The standard gateway runtime image did not honor the TZ environment variable for IANA timezone names because timezone data was missing.
  • Fixed issue: The tracer could crash on HTTPS or HTTP/2 keepalive connections when tracing was enabled.
  • Fixed issue: The gateway CLI wrote Control Plane mTLS client certificate files to the system temporary directory with overly broad permissions. These files are now written under the gateway config certificate directory with restricted permissions.

Console (Dashboard)

  • Fixed issue: The OpenID Connect plugin code editor could collapse or become unreachable on small or highly zoomed viewports.
  • Fixed issue: Deleting a published service from the service list could show a misleading "service not found" error toast after deletion succeeded.
  • Fixed issue: List table defaults could be mutated by one page and leak invalid sorting parameters into the Gateway Instances page.
  • Fixed issue: The plugin view drawer could show stale or incorrect JSON when switching between local, global, and metadata tabs.
  • Fixed issue: Cached gateway group or portal IDs that no longer existed could lead to blank pages or 404 error toasts instead of redirecting to a valid fallback.