Hey folks! 🎉
If you’ve been using Bro.JS for anything beyond a quick prototype, you’ll want to grab v3.1.0 right away. The last few weeks were spent on a deep‑dive security and stability audit, and 14 critical issues have been patched.
What’s fixed?
- IP spoofing – The framework now only trusts the real client IP from your load balancer.
- Rate‑limiter DoS – Keys are tied to verified IPs or API keys, stopping key‑bloat attacks.
-
Cross‑tenant IDOR – User tokens win over any
X‑Tenant‑Idheader unless you explicitly enableTRUST_TENANT_HEADER. - Plugin sandbox escape – Proxy traps fully isolate plugin contexts again.
- Dev dashboard XSS – All HTML output is now safely escaped.
Runtime improvements
- Edge upload limits are enforced with a
ReadableStreaminterceptor. - File logger is now async (
fs.promises.appendFile). - Redis distributed locks use UUIDs and atomic Lua scripts.
- Background tasks get an
AbortControllersignal to avoid overlap. - Pino logger redaction and circular‑reference crashes have been fixed.
Developer experience tweaks
- SDK generator now correctly maps hyphenated routes for React Query hooks.
- Native
FormDatauploads work out‑of‑the‑box. - Windows path resolution for
bro startis fixed viafile://URLs. -
.envAPI key arrays (API_KEY=key1,key2) are parsed automatically. - CommonJS
ERR_REQUIRE_ESMissues are resolved.
Give it a spin and let me know what you think. If it saves you time, a ⭐ on the repo would be awesome! Happy coding!
Top comments (0)