Skip to content

middleware: add Deprecation (RFC 9745), make Sunset RFC 8594 only - #1195

Open
VojtechVitek wants to merge 11 commits into
masterfrom
middleware-deprecation-header
Open

VojtechVitek wants to merge 11 commits into
masterfrom
middleware-deprecation-header

Conversation

@VojtechVitek

@VojtechVitek VojtechVitek commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Sunset used to set Deprecation to an HTTP-date, following the old draft. RFC 9745 defines Deprecation as a Structured Field Date (e.g. @1766571600), so that value was unparseable for compliant clients. It also conflated the deprecation date with the sunset date.

  • Add Deprecation(deprecatedAt, links...) per RFC 9745.
  • Sunset now sets only the Sunset header per RFC 8594.
  • Sunset formats the date in UTC so non-UTC times emit a valid GMT date.
  • Both middlewares panic on a zero time, at router construction.

Breaking for anyone relying on Sunset to also set Deprecation: add Deprecation to the chain explicitly.

Also breaking: Sunset used to silently skip the headers on a zero time. A zero time is nearly always an unset value (ignored parse error, missing config field), so it now panics at startup instead of silently dropping the header. Fix: pass a real date, or skip the middleware when no date is set. Both godocs say this.

@VojtechVitek VojtechVitek left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

I will wait for few more days / reviews before merging this one.

Comment thread README.md Outdated
Comment thread README.md
Comment thread middleware/sunset_test.go Outdated
Sunset used to set Deprecation to an HTTP-date, following the old draft.
RFC 9745 defines Deprecation as a Structured Field Date (e.g. @1766571600),
so that value was unparseable for compliant clients. It also conflated the
deprecation date with the sunset date.

- Add Deprecation(deprecatedAt, links...) per RFC 9745.
- Sunset now sets only the Sunset header per RFC 8594.
- Sunset formats the date in UTC so non-UTC times emit a valid GMT date.

Breaking for anyone relying on Sunset to also set Deprecation: add
Deprecation to the chain explicitly.
@VojtechVitek
VojtechVitek force-pushed the middleware-deprecation-header branch from b7c6e26 to 8715ef7 Compare September 29, 2026 23:41

@VojtechVitek VojtechVitek left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 LGTM

Final review

Checked and fine:
- Full go test -race ./... passes for the root and middleware packages.
- go vet and gofmt are clean.
- CI was green on the earlier commits across Go 1.24 to 1.27, on Ubuntu and Windows. It is rerunning on the new push.
- Master hasn't moved, so no rebase is needed.
- CHANGELOG.md is release-generated, so no entry is needed.
- The diff is README, the two middlewares, and their tests.

One wording fix: Sunset godoc said "sunsetAt is a future date". It now says "usually a future date", because the RFC allows past dates.

Known trade-offs to mention to maintainers:
1. Sunset no longer sets Deprecation. It's listed as breaking in the PR description.
2. A zero time now panics at construction. It is also listed as breaking.
3. Links are passed as full RFC 8288 values and are not built for you. This is documented and covered by the review discussion.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants