Skip to content

v1.3.1

Latest

Choose a tag to compare

@cursor cursor released this 05 Sep 12:21
7383b58

What's Changed

Follow-up hardening after the v1.3.0 security pass (#14).

Security

  • Resolve . / .. after URI decoding so routing and excludePaths share one canonical path
  • Write-once Symbol.for('0http.canonicalPath') — security middleware does not trust mutable req.path
  • Logger and Prometheus excludePaths use exact/boundary matching (/health no longer skips /healthcheck)
  • CORS: Vary: Origin on string-origin preflights; reject Origin: null for all non-wildcard configs
  • Logger: sanitize request IDs; redact Set-Cookie / Authorization / Cookie / X-Api-Key
  • MemoryStore and sliding window: maxKeys with fail-closed admission for new keys

Performance

  • Skip path decode/collapse/dot work when unnecessary; reuse frozen empty query
  • Middleware uses canonical path instead of new URL() per request
  • JSON nesting scan short-circuits; custom jsonTypes parsers are cached

Ergonomics

  • Types include req.path, req.body, req.files, logger options, errorHandler(err, req), maxKeys
  • CI runs bun run lint instead of format

Full Changelog: v1.3.0...v1.3.1

npm publish was left for the maintainer.