11Changelog for Falcon 4.3.0
22==========================
33
4+ .. falcon-release: 2026-06-15
5+
46 Summary
57-------
68
7- This is the first beta release of Falcon 4.3.
8-
9- As Falcon 4.3 is now feature-complete, we would really be thankful if you could
10- take this beta release for a spin with your apps, and
11- :ref: `let us know if you run into any issues <chat >`!
12-
13- As always, you can grab this pre-release
14- `from PyPI <https://pypi.org/project/falcon/4.3.0b1/ >`__::
9+ Falcon 4.3.0 centers on request parsing and typing. On the parsing side, this
10+ release introduces a family of new :class: `~falcon.Request ` methods for
11+ extracting structured data from the query string --
12+ :meth: `~falcon.Request.get_param_as_dict `,
13+ :meth: `~falcon.Request.get_param_as_media `, and
14+ :meth: `~falcon.Request.get_query_string_as_media ` -- together with a new
15+ ``delimiter `` argument for :meth: `~falcon.Request.get_param_as_list `. Several of
16+ these align with OpenAPI v3 (and 3.2) parameter styles, making it easier to
17+ implement spec-compliant APIs on top of Falcon.
1518
16- pip install falcon==4.3.0b1
19+ On the typing side, our internal annotations are now strict enough for the
20+ project to pass ``mypy --strict falcon/ ``, and :ref: `generic App types
21+ <generic_app_types>` are now automatically parametrized by the default
22+ request/response types on CPython 3.13+.
1723
18- Thank You!
24+ This release also brings a number of smaller improvements, including MessagePack
25+ support in the test client, an opt-in ``on_request() `` default responder, and
26+ hardening of :func: `falcon.secure_filename ` against Windows reserved device
27+ names.
1928
29+ Two features that we had hoped to land in 4.3 -- response teardown callbacks and
30+ a native OpenTelemetry integration -- did not make the cut in time. Both are now
31+ at the top of our priority list for Falcon
32+ `4.4 <https://github.com/falconry/falcon/milestone/46 >`__.
2033
21- .. Changes to Supported Platforms
22- .. ------------------------------
34+ On the security front, our GitHub Actions workflows are now audited with
35+ `zizmor <https://zizmor.sh/ >`__, and we have hardened the existing workflows to
36+ address the issues it surfaced.
2337
24- .. NOTE(vytas): No changes to the supported platforms (yet).
38+ This release also incorporates many pull requests submitted by our community.
39+ Sincere thanks to all 19 contributors who made this release possible!
2540
2641
2742New & Improved
@@ -31,13 +46,14 @@ New & Improved
3146 accepts a ``msgpack `` keyword argument, analogous to the existing ``json ``
3247 one. When provided, the value is serialized as a MessagePack document and
3348 used as the request body, and the ``Content-Type `` header is set to
34- :attr: ` ~falcon. MEDIA_MSGPACK `. (`#1026 <https://github.com/falconry/falcon/issues/1026 >`__)
49+ `` MEDIA_MSGPACK ` `. (`#1026 <https://github.com/falconry/falcon/issues/1026 >`__)
3550- A new router option,
3651 :attr: `~falcon.routing.CompiledRouterOptions.default_to_on_request `, was
3752 added to allow resources to provide a default responder via ``on_request() ``
38- (disabled by default). When enabled,
39- ``on_request() `` is used as the default responder for every unimplemented HTTP
40- verb except ``on_options() `` (and the special ``on_websocket `` handler).
53+ (disabled by default). When enabled, ``on_request() `` is used as the default
54+ responder for every HTTP method that lacks an explicit responder, except
55+ ``OPTIONS `` (served by ``on_options() ``) and the special WebSocket handler
56+ (``on_websocket() ``).
4157
4258 When the option is disabled, or the ``on_request() `` method is not implemented,
4359 the default responder for
@@ -46,10 +62,10 @@ New & Improved
4662 (``CON ``, ``NUL ``, ``COM1 ``, etc.) by prefixing the sanitized value with an
4763 underscore. (`#2422 <https://github.com/falconry/falcon/issues/2422 >`__)
4864- Internal type annotations were improved, allowing the project to pass
49- `mypy --strict falcon/ `. We have added a few `# type: ignore ` comments for
65+ `` mypy --strict falcon/ `` . We have added a few `` # type: ignore ` ` comments for
5066 known limitations, and are actively working to reduce their necessity. (`#2504 <https://github.com/falconry/falcon/issues/2504 >`__)
51- - The :meth: `req.get_param_as_list < falcon.Request.get_param_as_list> ` method now
52- supports a new argument, `delimiter `, for splitting values.
67+ - The :meth: `~ falcon.Request.get_param_as_list ` method now
68+ supports a new argument, `` delimiter ` `, for splitting values.
5369 In line with the OpenAPI v3 parameter specification, the supported delimiters
5470 currently include the ``'pipeDelimited' `` and ``'spaceDelimited' `` symbolic
5571 constants, as well as the literal ``',' ``, ``'|' ``, and ``' ' `` characters. (`#2538 <https://github.com/falconry/falcon/issues/2538 >`__)
97113
98114- Documented the US-ASCII restriction on the ``name `` and ``value `` arguments
99115 of :meth: `falcon.Response.set_cookie `. The implementation has always rejected
100- non-ASCII inputs (raising `` KeyError `` for ``name `` and `` ValueError ` ` for
116+ non-ASCII inputs (raising :class: ` KeyError ` for ``name `` and :class: ` ValueError ` for
101117 ``value ``), but the parameter and ``Raises `` entries did not call this out;
102118 the docstring now matches the runtime behaviour. (`#1445 <https://github.com/falconry/falcon/issues/1445 >`__)
103119- The :func: `falcon.testing.redirected ` context manager has been deprecated in
0 commit comments