chore(deps): bump github.com/dreego-stack/dreego from 0.7.0 to 0.10.9
Open
Number: #18
Type: Pull Request
State: Open
Type: Pull Request
State: Open
Author:
dependabot[bot]
Association: Unknown
Comments: 1
Association: Unknown
Comments: 1
Created:
September 30, 2026 at 07:24 PM UTC
(about 4 hours ago)
(about 4 hours ago)
Updated:
September 30, 2026 at 07:24 PM UTC
(about 4 hours ago)
(about 4 hours ago)
Description:
Bumps github.com/dreego-stack/dreego from 0.7.0 to 0.10.9.
Changelog
Sourced from github.com/dreego-stack/dreego's changelog.
v0.10.9 - 2026-09-26
- Feat:
PROFILE "name"header directive binds a route (and a(group)/subtree) to anApp.Profilewith its own session store, CSRF switch and cookie policy; without a profile the previous global session+CSRF behavior is unchanged- Feat:
App.Profile/App.ApplyProfileletmain.godefine CSRF/session profiles as code objects and scope them per route pattern- Feat:
GOIMPORTaccepts any resolvable import path (stdlib,go.moddependencies and own module paths) and supports aliases (GOIMPORT { myauth "statuna/auth" }); a missing module or base-name collision fails with a clear error instead of a static allowlist rejection- Feat: every generated
dree.gocarries a// Code generated by dreego …marker;dreego generateonly overwrites or deletes marked files and refuses an unmarkeddree.goinstead of deleting it silently- Feat: each route folder generates its own Go package; the root
www/routes/dree.gocollects every sub-packageRegister, so package-level declarations no longer collide across folders- Feat: the
dreego.Contextinterface exposesSet,Delete,Get,FormValue,QueryandDestroySession, matching whatSSRContextalready implemented- Feat:
c.Flash(key, msg),c.FlashGet(key)(reads and consumes) andc.FlashPeek(key)(reads without consuming) store flash messages in the session store- Feat:
c.CSRFInput()renders the complete hiddencsrf_tokenfield;dreego generatewarns when ag-actionform has nocsrf_tokenfield; a CSRF rejection is routed throughApp.SetErrorHandler(403)when registered- Docs: new recipes for calling app code from
<server>sections, machine/webhook endpoints and session/auth basics, plus a Context/SSRContext/RenderContext method tablev0.10.8 - 2026-09-21
- Bug:
c.Writeappends; charset=utf-8only when the caller-supplied content type has no charset, so a caller-provided charset is no longer duplicated- Feat:
SafeURLallows thewebcalandcaldavschemes for calendar subscriptions- Docs:
dreego.config.jsonis documented in the website root (www/by default), not the project root- Docs: the CLI install path
github.com/dreego-stack/dreego/cmd/dreego@…is documented and the module-root pitfall explainedv0.10.7 - 2026-09-21
- Bug: apply
|rawand other expression filters in attribute, URL, script, and style contexts instead of emitting invalid Go (undefined: raw)- Bug: allow
{#if}conditions on strings, numbers, and slices by routing them through a truthiness helper (empty string, zero, and empty collections are false), fixing the non-compiling_docs/forms.mdexamplev0.10.6 - 2026-09-21
- Bug:
<server>sections that mix Go declarations and statements now compile; the leading declaration block (type/func/var/const) and any top-level func are emitted at package level and the remaining statements stay inside the render function, instead of emitting the whole section at package level- Bug: declarations at the top of a
<server>section are hoisted to package level, so route files in one directory can share types, consts, funcs, and stores- Bug: request-local
vardeclarations that follow a statement stay inside the render function, so they are not turned into shared package state- Bug: the generated GET handler no longer overwrites a
Content-Typealready written by a<server type="custom">routev0.10.5 - 2026-09-21
- Bug:
dreego fmtis now semantics-preserving for body-level layouts; a document-level<head>nested in<body>is no longer hoisted and trailing</html>/</body>are no longer dropped- Bug:
dreego fmtreorders only whitespace-separated root sections and preserves every token and the surrounding text- Bug:
dreego fmtno longer rewrites string-literal contents; whitespace and|normalization stays outside"…",'…', and`…`values such as{{ "a b" }}or{#if x == "a | b"}- Bug:
dreego fmtpreserves<server>,<client>, and<style>sections byte for byte, including Go raw-string contents and alignment spacing- Test: round-trip property matrix over the scaffold layouts and body-level layout variants that asserts fmt never changes the lexed section structure or skeleton tags
- Test: literal guards and an exact code-section comparison that fail against the previous whitespace collapsing
- Test:
dreego fmt --checknever writes, including on a body-level layoutv0.10.4 - 2026-09-20
- Breaking: remove the
dreego initcommand;dreego newis the single scaffold entry point (it already creates the module,initdid not)- Bug:
dreego newnow always writes the module-qualified import (the removedinitcould emit the broken relative import"./www")- Feat: the scaffolded
main.godeclares the listening port as aportconstant, withDREEGO_PORTas the container override; theDockerfile/docker-compose.ymlread that variable instead of hardcoding 8080- Fix: the
web-appstarter no longer writes handwrittennotes_store.gointo the generatedroutespackage; the notes store lives in the route's<server>section- Fix:
dreego docsworks without ago.mod(resolves first-party docs from the module cache);--listno longer exits when nogo.modexists- Docs: update
getting-started,cli,deployment, and the template decision for the removedinit, the port constant, and theweb-approute store- Docs: add
_todo/plugins/websocket-hub-broadcast.1.mdfor the plugin's missing hub registration and README drift
... (truncated)
Commits
40a16b3docs: apply pending release notesb140351Merge pull request #115 from dreego-stack/integration/v010940b9d9efix: move shared fixture types into an importable package and update the scop...3095fbbtest: cover profile pattern validation, CSRF cookie path and /vN import namesf0bb890fix: validate ApplyProfile patterns, scope CSRF cookie path, resolve /vN impo...37bb0c7fix: adapt fixtures, demo and package-split tests to generated markers and pe...69c77fbdocs: add release change file for v0.10.9d92ab50test: adapt route-profile and route-package tests to per-folder packages and ...e465a5fMerge branch 'fix/v0109-p9-docs' into integration/v0109c8d88b7Merge branch 'fix/v0109-p6-lint' into integration/v0109- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Technical Details
| ID: | 16632070 |
| UUID: | 5651843529 |
| Node ID: | PR_kwDOUS5UOc8AAAABF9hZHQ |
| Host: | GitHub |
| Repository: | dreego-stack/plugin-auth |