Update github.com/danielgtaylor/huma/v2 to v2.39.0

This MR contains the following updates:

Package Type Update Change Pending
github.com/danielgtaylor/huma/v2 require minor v2.38.0 -> v2.39.0 v2.39.1

MR created with the help of gitlab-org/frontend/renovate-gitlab-bot


Release Notes

danielgtaylor/huma (github.com/danielgtaylor/huma/v2)

v2.39.0

Compare Source

v2.39.0

Overview

This release adds a new framework adapter, a handful of developer-facing features, and a large batch of correctness fixes spanning SSE, the Fiber adapter, schema generation, and validation.

Echo v5 Support

The humaecho adapter now supports Echo v5 alongside the existing versions. (#​959)

No More Faulty Duplicate-Schema Panics

Registering operations that use inline structs with differing field names (and an empty operation ID) previously panicked at startup on a false-positive duplicate-schema collision. Conflicting names are now auto-incremented deterministically (Request, Request1, Request2, ...), so the app starts and the generated spec stays readable. (#​893)

Context Propagation to Adapters

WithContext now propagates the context directly into the underlying adapter's own context wrapper (bun, chi, echo, fiber, gin, go, httprouter) instead of relying on a generic sub-context, so cancellation and context values flow correctly through the request lifecycle. (#​867)

SSE Streaming on Fiber / fasthttp

Server-Sent Events (and other streaming responses) previously failed on the Fiber adapters with unable to flush, since fasthttp doesn't implement http.Flusher. SSE now streams correctly on Fiber v2 and v3 via an internal streaming hook, with no new public API and fasthttp remaining an indirect dependency. (#​1059)

More SSE Improvements
  • Response headers are now flushed before the user handler runs, so EventSource.onopen fires immediately rather than waiting for the first event (#​1038)
  • Comments can now be sent over SSE streams, a common way to keep connections alive (#​1054)
New Features
  • Schema.Const for pinning a schema to a single allowed value (#​1004)
  • Customizable docs renderer config for finer control over the documentation UI (#​1024)
  • encoding.TextUnmarshaler support for slice query parameters, matching the existing behavior for scalar params (#​1021)
  • Non-file JSON form-data fields: multipart form fields tagged contentType:"application/json" are now unmarshalled and validated (#​1060)

Validation & Schema Fixes

  • Integer enums no longer always fail validation on query/path parameters; numeric enum values are now compared numerically rather than by strict Go type (#​1050)
  • Content-Type validation is now case-insensitive per RFC 9110, so e.g. Application/Json no longer returns 415 (#​1052)
  • Path parameters are always marked required: true in the generated spec, per the OpenAPI specification (#​1011)
  • Prevented a panic (and dropped response) in uniqueItems validation when array items are unhashable types, now returning 422 correctly (#​1045)
  • The json:",inline" tag is now honored for embedding anonymous fields in schemas (#​1006)
  • Hidden route schemas are no longer leaked into the generated spec (#​1032)

Adapter & Robustness Fixes

  • humafiber (v2): corrected EachHeader iteration (it previously invoked the callback once per byte, breaking cookie reads) and switched BodyReader to Body() for automatic request-body decompression (#​1058)
  • autopatch: prevented chi route-context reuse from recursing internal GET sub-requests back into the generated PATCH handler and panicking (#​1049)
  • Fixed a URL parsing panic in getAPIPrefix when server URLs contain template variables like {port} or {version} (#​1027)
  • The read deadline is now cleared after the request body is read, so a slow handler can't cause a background read to time out and cancel the connection context (#​1028)

Docs UI & Documentation

  • Forms are now permitted in the docs UI CSP (#​1036)
  • Added allow-downloads to the Stoplight CSP so the Export button works (#​1048)
  • Updated Restish references to v2 (#​1041)

What's Changed

New Contributors

Full Changelog: https://github.com/danielgtaylor/huma/compare/v2.38.0...v2.39.0


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻️ Rebasing: Whenever MR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this MR and you won't be reminded about this update again.


  • If you want to rebase/retry this MR, check this box

This MR has been generated by Renovate Bot.

Edited by GitLab Dependency Bot

Merge request reports

Loading