axum-extra-v0.12.6
mtkresearch/BreezeAppaxum-extra-v0.12.6Apr 14, 2026by yanns
AI Summary
Updates the library to fix header injection vulnerabilities and enforce stricter syntax requirements for path variables in the `vpath!` macro.
Key Highlights
- Fixed header parameter injection in `Content-Disposition` filenames
- Enforces new `{var}` syntax in `vpath!` macro, rejecting old `:var` and `*var` formats
- Improved error messages for multipart body limit exceeded
Breaking Changes
- The `vpath!` macro now rejects old path variable formats (`:var` and `*var`). Only `{var}` is allowed.
New Features
- Header injection security fix
- Multipart limit error message improvement
Full Release Notes
- **fixed:** Escape backslashes and double quotes in `Content-Disposition` filenames to prevent header parameter injection in `Attachment` and `FileStream` ([#3664])
- `vpath!` macro now stops the compilation if your path is using deprecated path variables in the old `107` format, such as `:var` and `*var`. the only allowed way now is `{var}`. ([#3618])
- **fixed:** Return specific error message when multipart body limit is exceeded ([#3611])
[#3664]: https://github.com/tokio-rs/axum/pull/3664
[#3618]: https://github.com/tokio-rs/axum/pull/3618
[#3611]: https://github.com/tokio-rs/axum/pull/3611