DEV Community

Yass1n
Yass1n

Posted on

Bro.JS v3.1.0 – Massive Security & Stability Fixes

Hey folks! 🎉

If you’ve been using Bro.JS for anything beyond a quick prototype, you’ll want to grab v3.1.0 right away. The last few weeks were spent on a deep‑dive security and stability audit, and 14 critical issues have been patched.

What’s fixed?

  • IP spoofing – The framework now only trusts the real client IP from your load balancer.
  • Rate‑limiter DoS – Keys are tied to verified IPs or API keys, stopping key‑bloat attacks.
  • Cross‑tenant IDOR – User tokens win over any X‑Tenant‑Id header unless you explicitly enable TRUST_TENANT_HEADER.
  • Plugin sandbox escape – Proxy traps fully isolate plugin contexts again.
  • Dev dashboard XSS – All HTML output is now safely escaped.

Runtime improvements

  • Edge upload limits are enforced with a ReadableStream interceptor.
  • File logger is now async (fs.promises.appendFile).
  • Redis distributed locks use UUIDs and atomic Lua scripts.
  • Background tasks get an AbortController signal to avoid overlap.
  • Pino logger redaction and circular‑reference crashes have been fixed.

Developer experience tweaks

  • SDK generator now correctly maps hyphenated routes for React Query hooks.
  • Native FormData uploads work out‑of‑the‑box.
  • Windows path resolution for bro start is fixed via file:// URLs.
  • .env API key arrays (API_KEY=key1,key2) are parsed automatically.
  • CommonJS ERR_REQUIRE_ESM issues are resolved.

Give it a spin and let me know what you think. If it saves you time, a ⭐ on the repo would be awesome! Happy coding!

Top comments (0)