angel3_framework 9.2.0 copy "angel3_framework: ^9.2.0" to clipboard
angel3_framework: ^9.2.0 copied to clipboard

A high-powered HTTP server extensible framework with dependency injection, routing and much more.

Change Log #

9.2.0 #

  • feat: Services, hooked services and @Middleware lookups now work without reflection; annotations are ignored when no reflector is configured instead of throwing an errror. This enabled support for dart compile exe to be used to build applications without reflection.
  • feat: Added Controller(expose: ...) to set the mount path without using reflection through @Expose annotation
  • feat: Added ioc(..., injection: InjectionRequest) for dependency injection without using reflection
  • feat: Added session timeout (default 20 minutes), idle HTTP/2 sessions are now discarded instead of being kept forever
  • feat: Added max size to the content body and rejects larger body with 413 error. The default limit is 10 MB
  • feat: Finalizers now run at most once per response
  • feat: Added max route cache size (default 1024); the production route cache now evicts least recently used entries.
  • feat: Added ResponseContext.attachmentDisposition() and Driver.closeServer()
  • fix: An empty JSON array ([]) in the POST request body no longer causing a 500 errer
  • fix: _http is now nullable and only closed if it was created.
  • fix: The default error handler now HTML-escapes the exception message and errors (XSS)
  • fix: res.redirect() now escapes the URL in the HTML fallback page and no longer emits javascript:, vbscript: or data: (XSS)
  • fix: HookedService.afterAllStream() now emits after-events instead of before-events
  • fix: A missing @CookieValue now uses its defaultValue or returns 400, instead of a 500 error
  • fix: DELETE / on a service now requests "remove all" (id 'null'), subject to allowRemoveAll; services with non-String ids return 405 instead of a 500 error
  • fix: An HTTP/2 request with a malformed header value (e.g. a bare %) no longer crashes the server process
  • fix: HTTP/2 header values are no longer percent-decoded or split on commas
  • fix: req.hostname over HTTP/2 now comes from the :authority header instead of always being localhost
  • fix: HTTP/2 sessions are now reused across multiple requests via the DARTSESSID cookie. Unknown session ids get a new session instead of being adopted
  • fix: Errors raised while creating a request context, or on an HTTP/2 connection, are now logged instead of terminating the server
  • fix: HostnameRouter now passes route parameters (e.g. :id) to the sub-app's handlers
  • fix: HostnameRouter creates each lazily-built app once, even when several requests arrive before creation finishes
  • fix: res.streamFile() with a response encoder (e.g. gzip) no longer sends the uncompressed Content-Length, which crashed the server process
  • fix: Unbuffered responses with several write() calls are now compressed as one gzip/deflate stream instead of one per write
  • fix: Response encoders now skip encodings the client marks q=0 in Accept-Encoding
  • fix: HTTP/2 server pushes are no longer compressed without a content-encoding header
  • fix: A failure while closing an HTTP/1.1 response is now logged instead of terminating the server
  • fix: responseFinalizers now run on unbuffered responses, just before headers are sent, so they can set headers, status and cookies. They still run after the handler, with the full body, on buffered responses. Behaviour change: finalizers that read res.buffer should check res.isBuffered
  • fix: An invalid response header (e.g. a non-ASCII value) now fails with 500 error, thrown where the header is set
  • fix: The HTTP/2 DARTSESSID session cookie is now Secure and HttpOnly
  • fix: The future returned by handleRequest/handleRawRequest now completes after the error response is sent when a handler throws an error, instead of never completing
  • fix: The no reflector startup message is now logged at info instead of warning as it is not longer a mandatory requirement to use Angel3
  • fix: When nothing matches, the driver now returns 404 instead of 500
  • fix: The application and default logger now prints their record only once. Creating an app with a custom logger, or setting app.logger, no longer removes the application's own Logger.root listeners
  • fix: res.download() no longer sends the file's server path as the download name, encodes any filename safely (RFC 6266), uses application/octet-stream for unknown types instead of crashing, reads the file asynchronously, and returns 404 for a missing file. res.streamFile() also returns 404 for a missing file instead of an error that revealed its path
  • fix: startServer now rethrows the original error (e.g. a SocketException when the port is in use) instead of a generic ArgumentError, and closes the bound server if a startup hook fails
  • fix: res.addStream() (and so res.streamFile()) on a buffered response now writes into the buffer, instead of sending directly and leaving the buffer empty
  • fix: HEAD requests are now answered by the matching GET route, without a body, when no explicit HEAD route exists (RFC 9110), including in HostnameRouter sub-apps. Behaviour change: such requests previously returned 404 or reached a fallback route
  • fix: req.accepts() now parses the Accept header instead of matching substrings: application/json no longer matches application/json-patch+json, type wildcards such as text/* are honoured, and types marked q=0 are not accepted
  • fix: Controller methods named put… and head… now map to PUT and HEAD routes. The verb must be a whole word, so posts() or getter() are now GET /posts and GET /getter, not POST /s and GET /ter
  • refactor: With no container passed, it now falls back to the request's container
  • refactor: Resolved various issues with MapService
  • refactor: Consolidated multiple copies of the encoder selection logic

9.1.1 #

  • Updated README with new links to templates

9.1.0 #

  • Require Dart >= 3.13

9.0.0 #

  • Require Dart >= 3.12

8.6.0 #

  • Require Dart >= 3.8
  • Updated lints to 6.0.0
  • Updated dependencies to the latest release

8.5.0 #

  • Require Dart >= 3.6
  • Updated lints to 5.0.0
  • Updated mime to 2.0.0
  • Fixed res.json() will cause 'Bad state: Cannot modify a closed response.' error.

8.4.0 #

  • Require Dart >= 3.3
  • Updated lints to 4.0.0

8.3.2 #

  • Updated README

8.3.1 #

  • Updated repository link

8.3.0 #

  • Updated lints to 3.0.0
  • Fixed linter warnings

8.2.0 #

  • Add addResponseHeader to AngelHttp to add headers to HTTP default response
  • Add removeResponseHeader to AngelHttp to remove headers from HTTP default response

8.1.1 #

  • Updated broken image on README

8.1.0 #

  • Updated uuid to 4.0.0

8.0.0 #

  • Require Dart >= 3.0
  • Updated http to 1.0.0

7.0.4 #

  • Updated Expose fields to non-nullable
  • Updated Controller to use non-nullable field

7.0.3 #

  • Fixed issue #83. Allow Http request to return null headers instead of throwing an exception.

7.0.2 #

  • Added performance benchmark to README

7.0.1 #

  • Fixed BytesBuilder warnings

7.0.0 #

  • Require Dart >= 2.17

6.0.0 #

  • Require Dart >= 2.16
  • Updated container to non nullable
  • Updated angel to non nullable
  • Updated logger to non nullable
  • Refactored error handler

5.0.0 #

  • Skipped release

4.2.4 #

  • Fixed issue 48. Log not working in development

4.2.3 #

  • Fixed res.json() throwing bad state exception

4.2.2 #

  • Added Date to response header
  • Updated Server: Angel3 response header

4.2.1 #

  • Updated package:angel3_container

4.2.0 #

  • Updated to package:belatuk_combinator
  • Updated to package:belatuk_merge_map
  • Updated linter to package:lints

4.1.3 #

  • Updated README

4.1.2 #

  • Updated README
  • Fixed NNBD issues

4.1.1 #

  • Updated link to Angel3 home page
  • Fixed pedantic warnings

4.1.0 #

  • Replaced http_server with belatuk_http_server

4.0.4 #

  • Fixed response returning incorrect status code

4.0.3 #

  • Fixed "Primitive after parsed param injection" test case
  • Fixed "Cannot remove all unless explicitly set" test case
  • Fixed "null" test case

4.0.2 #

  • Updated README

4.0.1 #

  • Updated README

4.0.0 #

  • Migrated to support Dart >= 2.12 NNBD

3.0.0 #

  • Migrated to work with Dart >= 2.12 Non NNBD

2.1.1 #

  • AngelHttp.uri now returns an empty Uri if the server is not listening.

2.1.0 #

  • This release was originally planned to be 2.0.5, but it adds several features, and has therefore been bumped to 2.1.0.
  • Fix a new (did not appear before 2.6/2.7) type error causing compilation to fail. https://github.com/angel-dart/framework/issues/249

2.0.5-beta #

2.0.4+1 #

  • Run Controller.configureRoutes before mounting @Expose routes.
  • Make Controller.configureServer always return a Future.

2.0.4 #

  • Prepare for Dart SDK change to Stream<List<int>> that are now Stream<Uint8List>.
  • Accept any content type if accept header is missing. See this PR.

2.0.3 #

2.0.2+1 #

  • Fix a bug in the implementation of Controller.applyRoutes.

2.0.2 #

  • Make ResponseContext explicitly implement StreamConsumer (though technically it already did???)
  • Split Controller.configureServer to create Controller.applyRoutes.

2.0.1 #

  • Tracked down a bug in Driver.runPipeline that allowed fallback handlers to run, even after the response was closed.
  • Add RequestContext.shutdownHooks.
  • Call RequestContext.close in Driver.sendResponse.
  • AngelConfigurer is now FutureOr<void>, instead of just FutureOr.
  • Use a Container.has<Stopwatch> check in Driver.sendResponse.
  • Remove unnecessary new and const.

2.0.0 #

  • Angel 2! 👼 🚀

2.0.0-rc.10 #

  • Fix an error that prevented AngelHttp2.custom from working properly.
  • Add startSharedHttp2.

2.0.0-rc.9 #

  • Fix some bugs in the HookedService implementation that skipped the outputs of before events.

2.0.0-rc.8 #

  • Fix MapService flaw where clients could remove all records, even if allowRemoveAll were false.

2.0.0-rc.7 #

  • AnonymousService can override readData.
  • Service.map now overrides readData.
  • HookedService.readData forwards to inner.

2.0.0-rc.6 #

  • Make redirect and download methods asynchronous.

2.0.0-rc.5 #

  • Make serializer FutureOr<String> Function(Object).
  • Make ResponseContext.serialize return Future<bool>.

2.0.0-rc.4 #

  • Support resolution of asynchronous injections in controllers and ioc.
  • Inject RequestContext and ResponseContext into requests.

2.0.0-rc.3 #

  • MapService.modify was not actually modifying items.

2.0.0-rc.2 #

  • Fixes Pub analyzer lints (see angel_route@3.0.6)

2.0.0-rc.1 #

  • Fix logic error that allowed content to be written to streaming responses after close was closed.

2.0.0-rc.0 #

  • Log a warning when no reflector is provided.
  • Add AngelEnvironment class.
    • Add Angel.environment.
    • Deprecated app.isProduction in favor of app.environment.isProduction.
  • Allow setting of bodyAsObject, bodyAsMap, or bodyAsList exactly once.
  • Resolve named singletons in resolveInjection.
  • Fix a bug where Service.parseId<double> would attempt to parse an int.
  • Replace as Data cast in Service.dart with a method that throws a 400 on error.

2.0.0-alpha.24 #

  • Add AngelEnv class to core.
  • Deprecate Angel.isProduction, in favor of AngelEnv.

2.0.0-alpha.23 #

  • ResponseContext.render sets charset to utf8 in contentType.

2.0.0-alpha.22 #

  • Update pipeline handling mechanism, and inject a MiddlewarePipelineIterator.
    • This allows routes to know where in the resolution process they exist, at runtime.

2.0.0-alpha.21 #

  • Update for angel_route@3.0.4 compatibility.
  • Add readAsBytes and readAsString to UploadedFile.
  • URI-decode path components in HTTP2.

2.0.0-alpha.20 #

  • Inject the MiddlewarePipeline into requests.

2.0.0-alpha.19 #

  • parseBody checks for null content type, and throws a 400 if none was given.
  • Add ResponseContext.contentLength.
  • Update streamFile to set content length, and also to work on HEAD requests.

2.0.0-alpha.18 #

  • Upgrade http2 dependency.
  • Upgrade uuid dependency.
  • Fixed a bug that prevented body parsing from ever completing with http2.
  • Add Providers.hashCode.

2.0.0-alpha.17 #

  • Revert the migration to lumberjack for now. In the future, when it's more stable, there'll be a conversion, perhaps.

2.0.0-alpha.16 #

  • Use package:lumberjack for logging.

2.0.0-alpha.15 #

  • Remove dependency on body_parser.
  • RequestContext now exposes a Stream<List<int>> get body getter.
    • Calling RequestContext.parseBody() parses its contents.
    • Added bodyAsMap, bodyAsList, bodyAsObject, and uploadedFiles to RequestContext.
    • Removed Angel.keepRawRequestBuffers and anything that had to do with buffering request bodies.

2.0.0-alpha.14 #

  • Patch HttpResponseContext._openStream to send content-length.

2.0.0-alpha.13 #

  • Fixed a logic error in HttpResponseContext that prevented status codes from being sent.

2.0.0-alpha.12 #

  • Remove ResponseContext.sendFile.
  • Add Angel.mimeTypeResolver.
  • Fix a bug where an unknown MIME type on streamFile would return a 500.

2.0.0-alpha.11 #

  • Add readMany to Service.
  • Allow ResponseContext.redirect to take a Uri.
  • Add Angel.mountController.
  • Add Angel.findServiceOf.
  • Roll in HTTP/2. See pkg:angel_framework/http2.dart.

2.0.0-alpha.10 #

  • All calls to Service.parseId are now affixed with the <Id> argument.
  • Added uri getter to AngelHttp.
  • The default for parseQuery now wraps query parameters in Map<String, dynamic>.from. This resolves a bug in package:angel_validate.

2.0.0-alpha.9 #

  • Add Service.map.

2.0.0-alpha.8 #

  • No longer export HTTP-specific code from angel_framework.dart. An import of import 'package:angel_framework/http.dart'; will be necessary in most cases now.

2.0.0-alpha.7 #

  • Force a tigher contract on services. They now must return Data on all methods except for index, which returns a List<Data>.

2.0.0-alpha.6 #

  • Allow passing a custom Container to handleContained and co.

2.0.0-alpha.5 #

  • MapService methods now explicitly return Map<String, dynamic>.

2.0.0-alpha.4 #

  • Renamed waterfall to chain.
  • Renamed Routable.service to Routable.findService.
    • Also Routable.findHookedService.

2.0.0-alpha.3 #

  • Added <Id, Data> type parameters to Service.
  • HookedService now follows suit, and takes a third parameter, pointing to the inner service.
  • Routable.use now uses the generic parameters added to Service.
  • Added generic usage to HookedServiceListener, etc.
  • All service methods take Map<String, dynamic> as params now.

2.0.0-alpha.2 #

  • Added ResponseContext.detach.

2.0.0-alpha.1 #

  • Removed Angel.injectEncoders.
  • Added Providers.toJson.
  • Moved Providers.graphql to Providers.graphQL.
  • Angel.optimizeForProduction no longer calls preInject, as it does not need to.
  • Rename ResponseContext.enableBuffer to ResponseContext.useBuffer.

2.0.0-alpha #

  • Removed random_string dependency.
  • Moved reflection to package:angel_container.
  • Upgraded package:file to 5.0.0.
  • ResponseContext.sendFile now uses package:file.
  • Abandon ContentType in favor of MediaType.
  • Changed view engine to use Map<String, dynamic>.
  • Remove dependency on package:json_god by default.
  • Remove dependency on package:dart2_constant.
  • Moved lib/hooks.dart into package:angel_hooks.
  • Moved TypedService into package:angel_typed_service.
  • Completely removed the AngelBase class.
  • Removed all @deprecated symbols.
  • Service.toId was renamed to Service.parseId; it also now uses its single type argument to determine how to parse a value. * In addition, this method was also made static.
  • RequestContext and ResponseContext are now generic, and take a single type argument pointing to the underlying request/response type, respectively.
  • RequestContext.io and ResponseContext.io are now permanently gone.
  • HttpRequestContextImpl and HttpResponseContextImpl were renamed to HttpRequestContext and HttpResponseContext.
  • Lazy-parsing request bodies is now the default; Angel.lazyParseBodies was replaced with Angel.eagerParseRequestBodies.
  • Angel.storeOriginalBuffer -> Angel.storeRawRequestBuffers.
  • The methods lazyBody, lazyFiles, and lazyOriginalBuffer on ResponseContext were all replaced with parseBody, parseUploadedFiles, and parseRawRequestBuffer, respectively.
  • Removed the synchronous equivalents of the above methods (body, files, and originalBuffer), as well as query.
  • Removed Angel.injections and RequestContext.injections.
  • Removed Angel.inject and RequestContext.inject.
  • Removed a dependency on package:pool, which also meant removing AngelHttp.throttle.
  • Remove the RequestMiddleware typedef; from now on, one should use ResponseContext.end exclusively to close responses.
  • waterfall will now only accept RequestHandler.
  • Routable, and all of its subclasses, now extend Router<RequestHandler>, and therefore only take routes in the form of FutureOr myFunc(RequestContext, ResponseContext res).
  • @Middleware now takes an Iterable of RequestHandlers.
  • @Expose.path now must be a String, not just any Pattern.
  • @Expose.middleware now takes Iterable<RequestHandler>, instead of just List.
  • createDynamicHandler was renamed to ioc, and is now used to run IoC-aware handlers in a type-safe manner.
  • RequestContext.params is now a Map<String, dynamic>, rather than just a Map.
  • Removed RequestContext.grab.
  • Removed RequestContext.properties.
  • Removed the defunct debug property where it still existed.
  • Routable.use now only accepts a Service.
  • Removed Angel.createZoneForRequest.
  • Removed Angel.defaultZoneCreator.
  • Added all flags to the Angel constructor, ex. Angel.eagerParseBodies.
  • Fix a bug where synchronous errors in handleRequest would not be caught.
  • AngelHttp.useZone now defaults to false.
  • ResponseContext now starts in streaming mode by default; the response buffer is opt-in, as in many cases it is unnecessary and slows down response time.
  • ResponseContext.streaming was replaced by ResponseContext.isBuffered.
  • Made LockableBytesBuilder public.
  • Removed the now-obsolete ResponseContext.willCloseItself.
  • Removed ResponseContext.dispose.
  • Removed the now-obsolete ResponseContext.end.
  • Removed the now-obsolete ResponseContext.releaseCorrespondingRequest.
  • preInject now takes a Reflector as its second argument.
  • Angel.reflector defaults to const EmptyReflector(), disabling reflection out-of-the-box.