What Framework 0.13.8
What Framework 0.13.8
Published September 7, 2026 (UTC). All 13 maintained packages have npm
provenance and passed the registry-install and published-app checks in
release run 34076453796.
This release combines synchronous middleware enforcement and better benchmark
diagnostics with the declaration corrections prepared in the unpublished
0.13.7 candidate.
Protected routes fail closed
Route middleware remains synchronous: return true or nothing to continue,
false to deny access, or a string to redirect. A synchronous redirect()
signal still works.
Previously, JavaScript callers could return a promise and the route would mount
without waiting for its result. This release throws ERR_ASYNC_MIDDLEWARE
before the protected component mounts when middleware returns a promise or
thenable. Rejections are observed, including native promises returned by async
then() methods. Results are never awaited or used to authorize navigation.
This is runtime enforcement, beyond the declaration correction in 0.13.7.
Move asynchronous checks from middleware[] to a component wrapper:
import { asyncGuard } from 'what-router';
const ProtectedPage = asyncGuard(
async () => await checkAccess(),
{ fallback: '/login', loading: Spinner },
)(AccountPage);
const routes = [{ path: '/account', component: ProtectedPage }];
// Without custom options: component: asyncGuard(check)(AccountPage)Client-side guards control rendering and navigation; enforce authorization
separately on the server for private data and mutations.
Benchmark evidence, not a performance claim
DOM reports retain raw samples in round order, exact sample counts for each
operation, and machine, Node, installed toolchain and actual browser metadata.
The samplesPerRound summary changes from a scalar to an operation-name map;
consumers needing exact counts can read each result's sampleCounts array.
The pooled 25th-percentile aggregate, measured operations, noise floor,
committed baseline and comparison tolerances are unchanged. Missing command-line
metadata is explicit; expected browser versions from the installed manifest
are distinguished from the browser that actually ran. Report-generation tests
run without Chromium. These changes make future investigations more informative;
they do not demonstrate a speed improvement or make historical runs comparable.
Historical comparison labels are restored from their dated Git records:
the September 4 runtime report identifies 0.13.4, and the August 11 bundle
comparison identifies 0.12.4. Their measured values and dates are unchanged.
Scope and verification limits
The maintained fixed-version group contains 13 packages. Deprecated what-mcp
remains frozen at 0.12.4. No new dependencies or rendering capabilities are
introduced. Version badges and package metadata identify the release;
historical release notes and benchmark measurements are preserved.
Source checks covered router and report-generation regressions,
version-sensitive tests, declarations/source types, lint, production builds,
bundle-size budgets and package/type/error-document consistency. The hosted
release workflow passed its correctness, performance-signal, registry-install
and published-app checks. Historical local DOM timing drift remains a separate
investigation; publication is not a claim that those older timing baselines
passed locally or that this release improves performance.