Ad
 
Learn More

Public proxy trust is the Important line in Echo 4.16 and 5.4

Echo v4.16.0 and v5.4.0 are flagged Important as breaking changes. The partner-break line is Context.Scheme() ignoring X-Forwarded-Proto from public CDN and LB peers (HTTPSRedirect loops, HSTS stops), not the upgrading-is-recommended opener.

Written by Watch Changelog Team

•2 min read

Public proxy trust is the Important line in Echo 4.16 and 5.4

So Echo put v4.16.0 and v5.4.0 on the feed, dated September 27, 2026. We flagged both Important as breaking changes. Recency wants the calm security opener: several issues fixed, upgrading is recommended, here is a wall of GHSA ids. Fine. Those are the lines people screenshot when they skim a Go framework note.

The line that matters, to the best of my understanding, is the Behavior changes block. Context.Scheme() now trusts X-Forwarded-Proto (and the sibling forwarded-scheme headers) only when the direct peer is loopback, link-local, private, or a unix socket. Before this, any client could send X-Forwarded-Proto: https over plain HTTP and skip HTTPSRedirect. After this, a proxy that connects from a public address (or 100.64.0.0/10) has its forwarded scheme ignored unless you set Echo#SchemeExtractor with TrustIPRange for that proxy. The note names Cloudflare, CloudFront, Azure Front Door, and GCP external HTTP(S) load balancers including GKE Ingress. Same release: Secure middleware keys HSTS off Context.Scheme(), so those origins also stop sending HSTS until you trust the peer ranges. Private-network proxies (AWS ALB, in-cluster ingress, most PaaS routers) keep working without changes.

There is a long security list in the same note. JSONP callbacks get strict identifier checks. MethodOverride can no longer turn a POST into GET and skip CSRF when registered wrong. Trailing-slash and static redirects percent-encode control characters. Static stops path tricks under guarded routes. Kind of easy to paste the GHSA laundry list into a status update and sound thorough. Kind of useless when the partner ticket is "our app behind CloudFront started redirect looping after the Echo bump."

I keep almost filing Echo under "Go web framework patch, ignore." Kind of the wrong habit when you sell into teams whose origins sit behind a public CDN or cloud LB. Tracking product change here means reading past the upgrade banner and asking which line changes a partner ticket. Let's say the talking point is not "4.16 and 5.4 shipped security fixes." It is public-proxy X-Forwarded-Proto is ignored until you trust the peer ranges (or you get HTTPSRedirect loops and missing HSTS), then yes mention the JSONP, MethodOverride, and static fixes in the same notes. We pull both tags into a uniform entry shape at /sources/echo.releases. Same JSON as everything else. Recency still wants the upgrade banner. Recency is not the public proxy trust change.