Repository navigation
middleware: add Deprecation (RFC 9745), make Sunset RFC 8594 only - #1195
Open
VojtechVitek wants to merge 11 commits into
Open
VojtechVitek wants to merge 11 commits into
VojtechVitek wants to merge 11 commits into
Conversation
VojtechVitek
commented
Sep 29, 2026
VojtechVitek
left a comment
Contributor
Author
There was a problem hiding this comment.
LGTM
I will wait for few more days / reviews before merging this one.
johnmaguire
reviewed
Sep 29, 2026
Sunset used to set Deprecation to an HTTP-date, following the old draft. RFC 9745 defines Deprecation as a Structured Field Date (e.g. @1766571600), so that value was unparseable for compliant clients. It also conflated the deprecation date with the sunset date. - Add Deprecation(deprecatedAt, links...) per RFC 9745. - Sunset now sets only the Sunset header per RFC 8594. - Sunset formats the date in UTC so non-UTC times emit a valid GMT date. Breaking for anyone relying on Sunset to also set Deprecation: add Deprecation to the chain explicitly.
VojtechVitek
force-pushed
the
middleware-deprecation-header
branch
from
September 29, 2026 23:41
b7c6e26 to
8715ef7
Compare
A zero time is almost always an unset value (ignored parse error, missing config field). Failing at router construction surfaces it at startup instead of silently dropping the header.
VojtechVitek
commented
Sep 30, 2026
VojtechVitek
left a comment
Contributor
Author
There was a problem hiding this comment.
🤖 LGTM
Final review
Checked and fine:
- Full go test -race ./... passes for the root and middleware packages.
- go vet and gofmt are clean.
- CI was green on the earlier commits across Go 1.24 to 1.27, on Ubuntu and Windows. It is rerunning on the new push.
- Master hasn't moved, so no rebase is needed.
- CHANGELOG.md is release-generated, so no entry is needed.
- The diff is README, the two middlewares, and their tests.
One wording fix: Sunset godoc said "sunsetAt is a future date". It now says "usually a future date", because the RFC allows past dates.
Known trade-offs to mention to maintainers:
1. Sunset no longer sets Deprecation. It's listed as breaking in the PR description.
2. A zero time now panics at construction. It is also listed as breaking.
3. Links are passed as full RFC 8288 values and are not built for you. This is documented and covered by the review discussion.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Sunset used to set Deprecation to an HTTP-date, following the old draft. RFC 9745 defines Deprecation as a Structured Field Date (e.g. @1766571600), so that value was unparseable for compliant clients. It also conflated the deprecation date with the sunset date.
Breaking for anyone relying on Sunset to also set Deprecation: add Deprecation to the chain explicitly.
Also breaking: Sunset used to silently skip the headers on a zero time. A zero time is nearly always an unset value (ignored parse error, missing config field), so it now panics at startup instead of silently dropping the header. Fix: pass a real date, or skip the middleware when no date is set. Both godocs say this.