fletch 2.2.0
fletch: ^2.2.0 copied to clipboard
A fast, Express-inspired HTTP framework for Dart. Build production-ready REST APIs with built-in sessions, CORS, rate limiting, and middleware support.
Changelog #
All notable changes to fletch will be documented in this file.
The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
2.2.0 - 2026-03-15 #
Performance #
- 44,277 RPS on Apple M-series — now the fastest Dart web framework, ~10% behind raw
dart:io. - Lazy session & request ID generation —
Random.secure()tokens are created only on first access. Routes that never touch a session or request ID pay zero entropy cost. - Session I/O gated on access — session load, save, and
Set-Cookieare skipped entirely for routes that never read or writereq.session. requestTimeout: null— disables the per-requestTimerallocation (~7k RPS gain). Recommended behind load balancers that enforce their own upstream timeout.- Static fused JSON encoder —
JsonUtf8Encoderreused across requests, eliminating aStringintermediate on everyres.json()call. - Lazy response headers map — allocated only when headers are actually set.
- Zero-middleware fast path — routes with no middleware bypass the closure chain entirely.
- Radix router — static cached
RegExp, combined method-check + regex + param extraction in a single pass, early exit after static segment match. - Lazy query param parsing — parsed on first access, not on every request construction.
Added #
session.regenerate()— invalidates the current session ID and issues a fresh one. Prevents session fixation attacks. Should be called after every successful login. Idempotent within a single request.MultipartFile.sanitizedFilename— extension getter that strips all path components from attacker-controlled upload filenames (../../etc/passwd→passwd). Use instead offile.filenamewhen writing to disk.Fletch(debug:)— whenfalse(default), error responses return only"Internal Server Error", preventing exception strings from leaking internal details. Set totrueduring local development to see full messages.MemorySessionStore(maxSessions:)— caps live session count (default 10,000). Oldest entries are evicted on insert when the limit is reached, bounding memory under sustained traffic.- CI:
.github/workflows/ci.yml— runsdart analyze --fatal-infos, full test suite, enforces ≥90% line coverage, and uploads to Codecov on every push/PR tomain. - CI:
.github/workflows/mutation.yml— weeklydart_mutantmutation testing run with HTML, JUnit, and AI reports as artifacts. Manually triggerable with configurable sample and threshold.
Security #
- Session fixation —
session.regenerate()destroys the pre-auth session ID at login. - Error redaction —
debug: false(default) prevents internal exception details from reaching clients. - Memory exhaustion —
MemorySessionStorenow evicts oldest sessions at capacity instead of growing without bound. - Cookie prefix-confusion — parser now splits on
;and does exact name matching, so a cookie likeevilapp.sid=x;fletch.sid=real(no space) correctly resolves toreal. - File upload path traversal —
sanitizedFilenamestrips directory components from filenames. - Rate limiter proxy bypass —
keyGeneratorparameter documented withX-Forwarded-Forpattern and explicit warning against trusting unvalidated forwarded headers.
Fixed #
- Race condition in server lifecycle test: replaced fixed 50 ms delay with a
startedcompleter soclose()is only called once the handler is confirmed in-flight. - All
dart analyze --fatal-infoswarnings resolved (unused imports, unused variables, duplicate field override, super-parameter style). benchmark/folder excluded from static analysis to prevent dartmark noise locally.
Tests #
- 286 tests, 94.9% line coverage.
- New test files:
cors_test,error_handler_test,fletch_features_test,rate_limiter_test,tls_test,security_test,list_router_test,response_test,coverage_gaps_test,coverage_extension_test. - TLS integration tests use runtime
opensslcert generation — no private keys in source. - Mutation testing: 96.7% kill rate on security-critical paths.
Documentation #
configuration.md—debug,requestTimeout: null, andMemorySessionStore(maxSessions:)added to options table and dedicated sections.sessions.md—session.regenerate()replaces the outdatedsession.clear()login pattern; full auth example updated;maxSessionsshown inMemorySessionStoreexample.requests-responses.md—sanitizedFilenameshown in the file upload section with path traversal warning.server-transport.md—requestTimeout: nullperformance tip added.security/cors.md— new Rate Limiting section coveringkeyGenerator,X-Forwarded-Forpattern, and proxy spoofing warning.
2.1.0 - 2026-02-26 #
Added #
listenSecure(port, SecurityContext, {...})— binds anHttpServerover TLS natively, supportingrequestClientCertificate,shared,backlog, andv6Only.serveWith(HttpServer)— attaches Fletch to a pre-createdHttpServer, enabling Unix sockets, custom TLS configurations, and external server lifecycle management (e.g. tests,server_nativeRust transport).- Low-level bind options on
listen()—backlogandv6Onlyparameters are now forwarded toHttpServer.bind(). - Parity in
IsolatedContainer.listen()—shared,backlog, andv6Onlyadded for consistency with the mainFletch.listen(). - 13 new tests covering
serveWithrouting, middleware, error handling,waitUntilClosed, multi-server scenarios, andlisten()bind options.
2.0.6 - 2026-02-22 #
Fixed #
- Publishing & Repository
- Removed internal development tools from the published package.
- Fixed a duplicate package history notice in the
README.mdand removed theswitch_readme.shpub.dev injection script.
2.0.5 - 2026-02-22 #
Changed #
- Dependencies
- Updated to latest compatible dependency versions.
- Added new examples to documentation.
2.0.4 - 2026-01-01 #
Added #
- Unified Controller Support
- Moved
useControllertoBaseContainer, enabling controllers in bothFletchapps andIsolatedContainermodules. - Added documentation example for
BaseContainer.useController.
- Moved
Changed #
- Refactoring
Controller.initializenow acceptsBaseContainerinstead ofFletch, allowing for more flexible controller reuse.- Removed duplicate
useControllerimplementation fromFletchclass (now inherited).
Documentation #
- Significant overhaul of documentation site:
- Added new "Configuration" guide.
- Added "Requests & Responses" API reference.
- Updated "Routing" and "Error Handling" guides.
- Implemented SEO basics (sitemap, meta tags).
2.0.3 - 2025-12-30 #
Added #
- Simplified Mounting API
- Added
Fletch.mount(String prefix, IsolatedContainer container)convenience method. - Allows easy mounting of isolated containers with automatic prefix handling:
app.mount('/auth', authModule).
- Added
- IsolatedContainer Extensions
- Added
withPrefix(String newPrefix)method to support easy re-mounting and configuration of containers.
- Added
- Flexible Response Encoding
- Added an optional
Encoding encodingparameter toResponsehelper methods (json,text,html,xml). - Defaults to
utf8but allows overriding for specific needs (e.g., legacy systems).
- Added an optional
Fixed #
- Unicode Response Crash
- Fixed an issue where the default encoding (Latin1) caused crashes when sending Unicode characters (like emojis 🔒, ✅) in responses.
- All response helpers (
json,html, etc.) now explicitly setcharset=utf-8in theContent-Typeheader by default.
2.0.2 - 2025-01-27 #
Added #
- Server-Sent Events (SSE) -
Response.sse()for real-time server-to-client streamingSSESinkclass withsendEvent(),sendComment(), keep-alive support- Example:
example/sse_example.dart
- Generic streaming -
Response.stream()for streaming files and data- Optional
flushEachChunkfor real-time delivery - Example:
example/stream_example.dart
- Optional
- Response utility -
Response.status()chainable status code setter - HEAD HTTP method - Added
RequestTypes.HEADconstant andhead()method- Available in
Fletch,IsolatedContainer, andBaseContainer
- Available in
- Integration tests for SSE and streaming (16 tests, all passing)
Changed #
- HTTP method refactoring - Moved HTTP method handlers to
BaseContainer- Eliminated code duplication between
FletchandIsolatedContainer - All HTTP methods (get, post, put, patch, delete, head, options) now inherited from base
IsolatedContaineroverridesaddRoute()for path normalization
- Eliminated code duplication between
Response.send()is nowFuture<void>(wasvoid) - all call sites updated toawait- Stream cleanup with try-finally blocks to prevent socket leaks
- Using
httpResponse.headers.chunkedTransferEncoding = trueinstead of manual headers - Mutual exclusion between
stream(),sse(), andbody/bytesresponses
Fixed #
- Unawaited futures in
base_container.dartandfletch.dart SSESink.sendComment()is nowFuture<void>for proper error propagation- Keep-alive errors using
unawaited()for fire-and-forget operations
2.0.1 - 2025-01-23 #
Documentation #
- Added Fletch logo to README with baseline alignment
- Improved README visual presentation
2.0.0 - 2025-01-22 #
💥 BREAKING CHANGES - Complete Package Repurposing #
This package has been completely repurposed from a jQuery-like library to an Express-inspired HTTP framework.
Package History
- Versions 0.1.0 - 0.3.0 (2014): jQuery-like library by Rob Kellett
- Version 2.0.0 (2025): Express-inspired HTTP framework by Kartikey Mahawar
Thank you to Rob Kellett for graciously transferring the package name to enable this new project!
For Users of the Original Library (v0.3.0)
If you were using the jQuery-like library:
- Version 0.3.0 remains available: https://pub.dev/packages/fletch/versions/0.3.0
- Original repository: https://github.com/RobKellett/Fletch
- Pin your version in
pubspec.yaml:dependencies: fletch: 0.3.0
What's New in 2.0.0
This is a completely new HTTP framework with:
- Express-like API: Familiar
app.get(),app.post(), middleware patterns - Production-ready: HMAC-signed sessions, CORS, rate limiting
- Fast routing: Radix-tree router with path parameters
- Dependency injection: GetIt-powered DI container
- Modular design: Controllers, isolated containers
- Comprehensive docs: https://docs.fletch.mahawarkartikey.in/
Features #
- ✅ Express-inspired routing and middleware
- ✅ Built-in session management with HMAC signing
- ✅ CORS and rate limiting middleware
- ✅ Request/response helpers (
req.params,res.json()) - ✅ Error handling with custom error types
- ✅ Graceful shutdown support
- ✅ 98 passing tests
- ✅ Full TypeScript-like type safety
Documentation #
- Homepage: https://docs.fletch.mahawarkartikey.in/
- GitHub: https://github.com/kartikey321/fletch
- Examples: See
/exampledirectory
0.3.0 - 2014-07-26 (Original Package by Rob Kellett) #
jQuery-like library for Dart. See original repository for details.
1.0.0 - 2024-12-13 (Internal Development Version) #
🔒 Security Enhancements #
- Added HMAC-SHA256 session signing: Session cookies are now cryptographically signed to prevent tampering
- Changed session cookie defaults: Now use
secure: true,httpOnly: true,SameSite: Laxby default - Added constant-time signature comparison: Protection against timing attacks
- Fixed rate limiter memory leak: Cleanup timers now properly disposed on shutdown
✨ New Features #
- Pluggable Session Stores: Abstract
SessionStoreinterface for custom persistence backends - MemorySessionStore: Built-in in-memory store with automatic TTL expiration
- Session lifecycle hooks: Automatic load/save with error handling
sessionSecretparameter: Configure HMAC secret for productionsecureCookiesparameter: Control HTTPS enforcement (default:true)sessionStoreparameter: Use Redis, PostgreSQL, or custom backends
🔧 Bug Fixes #
- Fixed cookie parser discarding empty cookie values (e.g.,
logout=) - Fixed rate limiter cleanup timer memory leak
- Removed broken
Session.regenerate()method (session ID is immutable) - Added proper resource cleanup on server shutdown
💥 BREAKING CHANGES #
- Session cookies now require HTTPS in production (default
secure: true)- Set
secureCookies: falsefor local HTTP development - Ensure HTTPS is configured for production deployments
- Set
Dependencies #
- Added:
crypto: ^3.0.3