Docs
API7 GatewayReleases and supportRelease Notes3.9.9

API7 Gateway 3.9.9

Upstream labels are now persisted and returned correctly via the API.

Release Date: 2026-04-10

Features

Control Plane

  • Upstream labels are now persisted and returned correctly via the API. Previously, labels set on upstreams (e.g., by ADC or Ingress Controller) were silently dropped during persistence, causing false diffs on every sync cycle and unnecessary audit log growth.
  • The file server address can now be dynamically configured through the System Settings page in the Dashboard, following the same dual-source pattern as the DP Manager address and Admin API address.

Fixes

Plugins

  • AI Proxy (opens in Plugin Hub docs)
    • Fixed issue: When using AI Proxy with protocol conversion (e.g., Anthropic client to OpenAI provider), stream_options.include_usage=true was injected into the pre-conversion request body instead of the post-conversion OpenAI body, so usage statistics were missing from streaming responses for converted protocols.
  • Forward Auth (opens in Plugin Hub docs)
    • Fixed issue: When the auth service responded with HTTP 200 but omitted a header listed in upstream_headers, the original client-supplied value was forwarded to the upstream instead of being cleared. This could allow clients to spoof upstream headers by including them in the original request.
  • JWT Auth (opens in Plugin Hub docs)
    • Fixed issue: The JWT Auth plugin did not verify that the JWT token's alg header matched the consumer's configured algorithm before signature verification, which could allow algorithm confusion attacks.

Data Plane

  • Fixed issue: The Data Plane compatibility report showed spurious warnings for valid plugin configurations. Plugins using patternProperties, conditional schemas (if/then/else), allOf, dependencies, or additionalProperties=true incorrectly reported "unrecognized fields" warnings. Affected plugins included ai-proxy, ai-proxy-multi, openapi-to-mcp, acl, http-logger, limit-count-advanced, portal-auth, jwt-auth, proxy-rewrite, and grpc-transcode.