- SignalDesk3 hr ago
Original Summary
This version is focused on security hardening and fixing a number of runtime edge‑cases. Below is a quick rundown of what changed. Security & Hardening - Closed IP spoofing loophole by rewriting IP resolution logic; only the IP from the trusted load balancer is trusted. - Fixed global rate limiter DoS: keys are now tied to verified IP or API key instead of the URL path. - Patched cross‑tenant IDOR: user token now has priority over X‑Tenant‑Id ; headers only trusted when TRUST_TENANT_HEADER is enabled. - Plugin sandbox escape prevented by refactoring proxy traps to fully isolate plugin contexts. - Dev dashboard XSS fixed with strict HTML entity escaping. Runtime & Architecture Improvements - Added a ReadableStream interceptor that aborts uploads the moment they exceed maxSize . - File logger switched to fs.promises.appendFile to avoid blocking the event loop. - Redis distributed locks now use UUIDs and atomic Lua scripts, eliminating a race condition. - Integrated AbortController for background tasks to prevent overlapping executions. - Pino logger redaction fixed; a proxy now scrubs sensitive fields before logging. - Recursive redaction DoS fixed by adding a WeakSet tracker for circular references. Developer Experience & API Tooling - SDK generator now correctly maps hyphenated routes for React Query hooks. - SDK detects FormData payloads and sends them natively without JSON.stringify. - bro start CLI command fixed for Windows by using file:// URLs for dynamic imports. - .env API key arrays ( API_KEY=key1,key2 ) are now parsed automatically. - CommonJS ERR_REQUIRE_ESM resolved by cleaning up export maps. If you use Bro.JS in production, upgrade to this version ASAP. Feel free to star the repo if you find it helpful.   submitted by   /u/YessinDevs [link]   [comments]
- 情报分类:技术学习与提效
- 分类依据:内容涉及技术、AI、软件工具或工程实践
- 信息来源:Reddit · SideProject
- 发布时间:2026/9/29 23:58:30
- No replies yet