[deps]: Update Rust crate tower-http to 0.7.0 (#1548)
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [tower-http](https://redirect.github.com/tower-rs/tower-http) |
dependencies | minor | `0.6.6` โ `0.7.0` |
---
### Release Notes
<details>
<summary>tower-rs/tower-http (tower-http)</summary>
###
[`v0.7.0`](https://redirect.github.com/tower-rs/tower-http/releases/tag/tower-http-0.7.0)
[Compare
Source](https://redirect.github.com/tower-rs/tower-http/compare/tower-http-0.6.11...tower-http-0.7.0)
[Changes since
0.6.11](https://redirect.github.com/tower-rs/tower-http/compare/tower-http-0.6.11...tower-http-0.7.0)
#### Added
- `csrf`: add cross-site request forgery (CSRF) protection middleware,
porting the cross-origin protection scheme introduced in Go 1.25
([#​699])
```rust
use tower::ServiceBuilder;
use tower_http::csrf::CsrfLayer;
// Rejects cross-origin state-changing requests using `Sec-Fetch-Site`,
// an `Origin` allow-list, and an `Origin`/`Host` fallback. No
per-request
// token state required.
let layer = CsrfLayer::new().add_trusted_origin("https://example.com")?;
let service = ServiceBuilder::new().layer(layer).service_fn(handler);
```
- `timeout`: add `DeadlineBody` for non-resetting body timeouts, applied
via the new `RequestBodyDeadlineLayer` and `ResponseBodyDeadlineLayer`
([#​688])
Unlike `TimeoutBody`, which resets its deadline on every frame,
`DeadlineBody` caps the total time of a body transfer. A slow client
trickling one byte at a time never trips an idle timeout but will trip a
deadline.
```rust
use std::time::Duration;
use tower::ServiceBuilder;
use tower_http::timeout::RequestBodyDeadlineLayer;
// Abort the request body transfer after 30s total, regardless of how
// frequently data arrives.
let service = ServiceBuilder::new()
.layer(RequestBodyDeadlineLayer::new(Duration::from_secs(30)))
.service_fn(handler);
```
- `fs`: add strong `ETag` support to `ServeDir`, including `If-Match`
and `If-None-Match` precondition handling per RFC 9110. `304 Not
Modified` responses now carry the `ETag` and `Last-Modified` validators
([#​691])
- `fs`: add a `Backend` trait to make `ServeDir` work with
non-filesystem sources (e.g. embedded assets or object storage). The
default `TokioBackend` preserves existing behavior. Use
`ServeDir::with_backend()` to plug in custom implementations
([#​684])
```rust
use tower_http::services::fs::ServeDir;
// `MyBackend` implements `tower_http::services::fs::Backend`.
// The default `ServeDir::new()` continues to use `TokioBackend` (local
FS).
let service = ServeDir::with_backend("assets", MyBackend::new());
```
- `fs`: add `html_as_default_extension` option to `ServeDir`, appending
`.html` when the request path has no extension ([#​519])
- `fs`: add `redirect_path_prefix` option to `ServeDir`, prepending a
prefix on trailing-slash redirects so the service can be mounted under a
sub-path ([#​486])
- `validate-request`: add
`ValidateRequestHeaderLayer::has_header_value()` to reject requests when
a header does not have an expected value ([#​360])
- `body`: `UnsyncBoxBody::new()` constructor and
`From<ServeFileSystemResponseBody>` conversion to avoid double-boxing
when combining `ServeDir` responses with other body types
([#​537])
- `limit`: implement `Default` for `limit::ResponseBody` when the
wrapped body also implements `Default` ([#​679])
#### Changed
- **breaking:** `compression`: the middleware now handles the `*`
wildcard and `identity;q=0` in Accept-Encoding per RFC 9110 ยง12.5.3.
Requests that previously fell back to identity (e.g. `*;q=0` or
`identity;q=0` with no other acceptable encoding) now receive a 406 Not
Acceptable response. Clients that explicitly reject all encodings
without listing an alternative will see different behavior.
([#​693])
- **breaking:** `compression`: upgrade the `SizeAbove` predicate
threshold from `u16` to `u64`, allowing minimum sizes above 64 KiB
([#​704])
- **breaking:** remove the implicit no-op `tokio` and
`async-compression` features. These were kept as no-op features in 0.6.x
for backwards compatibility after the switch to `dep:` syntax in
[#​642]. Downstream crates that activate `tower-http/tokio` or
`tower http/async-compression` should remove those feature entries; the
underlying dependencies are still pulled in transitively by the features
that need them (e.g. `compression-gzip`, `fs`, `timeout`).
([#​628])
- **breaking:** `trace`/`classify`: include the gRPC error message in
tracing output. `GrpcCode` and `GrpcFailureClass` are now
`#[non_exhaustive]`, and `GrpcStatus` is exported from the `classify`
module ([#​422])
- **breaking:** `follow-redirect`: `FollowRedirect` now forwards request
`Extensions` to redirected requests instead of dropping them. The
`Standard` policy drops extensions on cross-origin redirections
(same-origin keeps them). Opt out with
`FollowRedirectLayer::preserve_extensions(false)`; keep specific types
with `FilterCredentials::allow_extension::<T>()` or all of them with
`keep_all_extensions()`. ([#​706])
```rust
use tower_http::follow_redirect::FollowRedirectLayer;
// 0.7.0 forwards request `Extensions` across redirects by default.
// Restore the previous behavior (drop all extensions) with:
let layer = FollowRedirectLayer::new().preserve_extensions(false);
```
- **breaking:** `follow-redirect`: header and extension filtering is now
cumulative. A value a policy drops on one hop is no longer replayed on
later hops, so `FilterCredentials` no longer re-sends
`Cookie`/`Authorization` to a same-origin target reached after
cross-origin hop. Custom `Policy::on_request` impls now see the previous
hop's filtered request, not the original. ([#​706])
- `trace`: `DefaultOnRequest`, `DefaultOnResponse`, `DefaultOnFailure`,
and `DefaultOnEos` now explicitly parent their tracing events to the
request span rather than relying on the ambient span context. This fixes
intermittent cases where events could appear without their request span
attached ([#​690])
- `cors`: relax the `Vary` header defaults ([#​674])
- MSRV bumped from 1.64 to 1.65 ([#​684])
#### Fixed
- `fs`: `ServeDir` and `ServeFile` now emit a `Vary: Accept-Encoding`
response
header when precompressed serving is configured, ensuring caches
correctly
distinguish between compressed and uncompressed variants ([#​692])
- **breaking:** `services`: reject a trailing slash for file paths. File
requests with a trailing slash now return `404 Not Found` instead of
serving the file ([#​678])
- `fs`: fix `ServeDir` stripping the file extension when serving with
identity encoding ([#​686])
- `compression`: forward trailers from the inner body after compression
finishes, fixing dropped gRPC status trailers ([#​685])
- `trace`: fire `on_eos` when the inner body reports `is_end_stream`
with a precise content-length ([#​687])
- `on-early-drop`: suppress the early-drop guard when `is_end_stream` is
reported after a data frame ([#​687])
- `set-header`: make `SetMultipleRequestHeaders` and
`SetMultipleResponseHeaders` `Clone` for non-`Clone` HTTP bodies
([#​703])
[#​360]: https://redirect.github.com/tower-rs/tower-http/pull/360
[#​422]: https://redirect.github.com/tower-rs/tower-http/pull/422
[#​486]: https://redirect.github.com/tower-rs/tower-http/pull/486
[#​519]: https://redirect.github.com/tower-rs/tower-http/pull/519
[#​537]: https://redirect.github.com/tower-rs/tower-http/pull/537
[#​628]: https://redirect.github.com/tower-rs/tower-http/pull/628
[#​642]: https://redirect.github.com/tower-rs/tower-http/pull/642
[#​674]: https://redirect.github.com/tower-rs/tower-http/pull/674
[#​678]: https://redirect.github.com/tower-rs/tower-http/pull/678
[#​679]: https://redirect.github.com/tower-rs/tower-http/pull/679
[#​684]: https://redirect.github.com/tower-rs/tower-http/pull/684
[#​685]: https://redirect.github.com/tower-rs/tower-http/pull/685
[#​686]: https://redirect.github.com/tower-rs/tower-http/pull/686
[#​687]: https://redirect.github.com/tower-rs/tower-http/pull/687
[#​688]: https://redirect.github.com/tower-rs/tower-http/pull/688
[#​690]: https://redirect.github.com/tower-rs/tower-http/pull/690
[#​691]: https://redirect.github.com/tower-rs/tower-http/pull/691
[#​692]: https://redirect.github.com/tower-rs/tower-http/pull/692
[#​693]: https://redirect.github.com/tower-rs/tower-http/pull/693
[#​699]: https://redirect.github.com/tower-rs/tower-http/pull/699
[#​703]: https://redirect.github.com/tower-rs/tower-http/pull/703
[#​704]: https://redirect.github.com/tower-rs/tower-http/pull/704
[#​706]: https://redirect.github.com/tower-rs/tower-http/pull/706
#### Thanks
- [@​jlizen](https://redirect.github.com/jlizen)
- [@​seun-ja](https://redirect.github.com/seun-ja)
- [@​Oliboy50](https://redirect.github.com/Oliboy50)
##### New Contributors
- [@​muhamadazmy](https://redirect.github.com/muhamadazmy) made
their first contribution in
[#​679](https://redirect.github.com/tower-rs/tower-http/pull/679)
- [@​Isvane](https://redirect.github.com/Isvane) made their first
contribution in
[#​678](https://redirect.github.com/tower-rs/tower-http/pull/678)
- [@​xiaoyawei](https://redirect.github.com/xiaoyawei) made their
first contribution in
[#​422](https://redirect.github.com/tower-rs/tower-http/pull/422)
- [@​dependabot](https://redirect.github.com/dependabot)\[bot]
made their first contribution in
[#​696](https://redirect.github.com/tower-rs/tower-http/pull/696)
- [@​its-the-shrimp](https://redirect.github.com/its-the-shrimp)
made their first contribution in
[#​519](https://redirect.github.com/tower-rs/tower-http/pull/519)
- [@​yawn](https://redirect.github.com/yawn) made their first
contribution in
[#​699](https://redirect.github.com/tower-rs/tower-http/pull/699)
- [@​Jesse-Bakker](https://redirect.github.com/Jesse-Bakker) made
their first contribution in
[#​703](https://redirect.github.com/tower-rs/tower-http/pull/703)
- [@​junghwan16](https://redirect.github.com/junghwan16) made
their first contribution in
[#​705](https://redirect.github.com/tower-rs/tower-http/pull/705)
- [@​claraphyll](https://redirect.github.com/claraphyll) made
their first contribution in
[#​486](https://redirect.github.com/tower-rs/tower-http/pull/486)
</details>
---
### Configuration
๐
**Schedule**: (in timezone America/Chicago)
- Branch creation
- Between 06:00 AM and 06:59 AM, between day 8 and 14 of the month, and
on Monday, only in January, March, May, July, September, and November
(`* 6 8-14 1,3,5,7,9,11 1`)
- Automerge
- At any time (no schedule defined)
๐ฆ **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.
โป **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
๐ **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/bitwarden/sdk-sm).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNTkuMiIsInVwZGF0ZWRJblZlciI6IjQ0LjMuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> R
renovate[bot] committed
1bee7901fdbce5f767bb341af9bdd6986d1c738f
Parent: 615969a
Committed by GitHub <noreply@github.com>
on 7/30/2026, 9:02:17 PM