Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 9 additions & 4 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -38,11 +38,13 @@ jobs:
go-version: ${{ matrix.go-version }}
cache: true

# go.mod's toolchain line and this workflow's Go version must agree:
# fail loudly if they drift rather than test on one Go and pin another.
# go.mod's Go (its toolchain line, or the go line when there is none —
# go mod tidy drops a toolchain line equal to the go line) and this
# workflow's Go must agree: fail loudly if they drift rather than test on
# one Go and pin another.
- name: Toolchain matches go.mod
run: |
want=$(awk '/^toolchain /{print $2}' go.mod)
want=$(awk '/^toolchain /{t=$2} /^go /{g="go"$2} END{print (t != "" ? t : g)}' go.mod)
got=$(go env GOVERSION)
echo "go.mod toolchain: $want · CI: $got"
test -n "$want" && test "$got" = "$want"
Expand Down Expand Up @@ -94,8 +96,11 @@ jobs:
with:
go-version: "1.27.1"
cache: true
# Pinned, so a scanner release never changes the result unannounced. It
# is built with the job's Go (1.27.1): a govulncheck built with an older
# Go refuses a module targeting a newer one.
- name: Install govulncheck
run: go install golang.org/x/vuln/cmd/govulncheck@latest
run: go install golang.org/x/vuln/cmd/govulncheck@v1.8.0
- name: Run govulncheck
run: govulncheck ./...

8 changes: 8 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,14 @@ All notable changes to backendkit are documented here. Format:

## [Unreleased]

### Changed
- **The module now requires Go 1.27.1** (`go 1.27.1`; was `go 1.25.0` with `toolchain go1.27.1`).
Importers need Go 1.27.1 or later; with `GOTOOLCHAIN=auto`, the default, an older `go` command
downloads it. backendkit's language level and `GODEBUG` defaults now match the Go it is built
and tested with. No exported identifier changes. `bff.NewSingleHostProxy` keeps its
`httputil.ReverseProxy.Director` (deprecated since Go 1.26, still supported): callers wrap it,
so moving to `Rewrite` needs a new, additive constructor. CI pins govulncheck to v1.8.0.

## [1.19.0] - 2026-10-03

Minor release on the **v1** line: additive only. The service-side helpers Lakebridge asked for:
Expand Down
3 changes: 2 additions & 1 deletion CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -54,7 +54,8 @@ golangci-lint run ./... # v2.14.0, built with Go 1.27.1
govulncheck ./...
```

CI also fails if the Go version it runs differs from the `toolchain` line in `go.mod`.
CI also fails if the Go version it runs differs from `go.mod`'s (its `go` line, or a `toolchain`
line when there is one).

## Git workflow

Expand Down
2 changes: 1 addition & 1 deletion CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ policy decisions. Contributions are accepted under the project's licence,

## Development setup

Requirements: Go (the `toolchain` line in `go.mod` downloads the exact version, 1.27.1). The
Requirements: Go (the `go` line in `go.mod` downloads the exact version, 1.27.1). The
tests need no database and no network service.

```bash
Expand Down
8 changes: 4 additions & 4 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -119,9 +119,9 @@ to Socrate (`bff`, `pep`) and `ailang` for `aigateway`.

## Requirements

- **Go 1.25 or later** to import the module (the `go` line in `go.mod`). Build your service with
a Go release that still receives security fixes. backendkit itself is built and tested with
Go 1.27.1, pinned by the `toolchain` line.
- **Go 1.27.1 or later** to import the module (the `go` line in `go.mod`, which is also the Go
backendkit is built and tested with). With `GOTOOLCHAIN=auto`, the default, an older `go`
command downloads it.
- **A Socrate server** for the packages that talk to it: `jwtauth`, `socrate`, `bff` and `pep`.
They are written for Socrate's API and claims, not as a generic OAuth toolkit. The other
packages, `ctxutil` included, are plain Go helpers and work without Socrate.
Expand All @@ -140,7 +140,7 @@ go get github.com/ovander/backendkit@v1.19.0
// go.mod
module github.com/your-org/my-service

go 1.25
go 1.27.1

require github.com/ovander/backendkit v1.19.0
```
Expand Down
4 changes: 2 additions & 2 deletions bff/gateway.go
Original file line number Diff line number Diff line change
Expand Up @@ -305,8 +305,8 @@ var clientIPHeaders = []string{"X-Real-IP", "True-Client-IP", "Forwarded"}
func NewSingleHostProxy(upstream *url.URL) *httputil.ReverseProxy {
p := httputil.NewSingleHostReverseProxy(upstream)
p.FlushInterval = -1
director := p.Director
p.Director = func(r *http.Request) {
director := p.Director //nolint:staticcheck // SA1019: v1 API, callers wrap Director; a Rewrite-based proxy is a separate, additive change
p.Director = func(r *http.Request) { //nolint:staticcheck // SA1019: v1 API, callers wrap Director; a Rewrite-based proxy is a separate, additive change
director(r)
for _, h := range clientIPHeaders {
r.Header.Del(h)
Expand Down
2 changes: 1 addition & 1 deletion docs/CLIENT-INTEGRATION.md
Original file line number Diff line number Diff line change
Expand Up @@ -127,7 +127,7 @@ enforce your own authorization first.
go get github.com/ovander/backendkit@latest
```

Requires **Go 1.25+**.
Requires **Go 1.27.1+** (the `go` line of backendkit's `go.mod`).

`backendkit` reads **no environment variables itself** — you pass everything to
constructors explicitly. These are the conventional names used throughout this
Expand Down
12 changes: 4 additions & 8 deletions go.mod
Original file line number Diff line number Diff line change
@@ -1,13 +1,9 @@
module github.com/ovander/backendkit

go 1.25.0

// Build/release with a patched toolchain to pick up Go standard-library security
// fixes (govulncheck GO-2026-4599…GO-2026-5039, and the 2026-08-28 releases).
// The go directive above stays at 1.25.0 so the module remains importable by
// consumers on Go 1.25; this toolchain directive only governs builds where
// backendkit is the main module. Keep it equal to the Go version in CI.
toolchain go1.27.1
// The go line is both the minimum Go for every module that imports backendkit
// and the exact Go it is built and tested with (with no toolchain line, it is
// the toolchain too). CI checks it against the Go CI runs.
go 1.27.1

require (
github.com/golang-jwt/jwt/v5 v5.3.1
Expand Down
Loading