Skip to content

v0.3.2 - Security & Resilience Hardening

Latest

Choose a tag to compare

@GustavoBaranda GustavoBaranda released this 29 Sep 23:43
c06ffc0

Security & Resilience Fixes

This release consolidates nine security and reliability fixes across
the WhatsApp, Telegram, and LLM engine layers.

Security

  • SEC-02 (#3): Tool execution errors are now sanitized before being returned to the LLM — generic messages with a trace ID are surfaced to the model, while full tracebacks stay in server logs.
  • SEC-03 (#5): Phone numbers are now masked in WhatsApp exception and fallback delivery logs.
  • SEC-04 (#7): The Telegram /reset command is now restricted to group creators and administrators in group/supergroup chats.
  • SEC-05 (#9): FastAPI's /docs, /redoc, and /openapi.json are disabled by default on the WhatsApp webhook server; opt back in with enable_docs=True for local development.
  • SEC-07 (#11): OpenAIEngine no longer forwards the server's global API key to a custom, unofficial base_url unless an API key is provided explicitly — preventing accidental credential leakage to untrusted endpoints.

Reliability

  • SEC-08 (#12): Long Telegram responses are now split into sequential chunks respecting Telegram's 4,096-character limit.
  • SEC-09 (#13): Calling Tool.execute() on an async tool from within a running event loop now raises a clear, actionable error instead of a confusing nested RuntimeError. Documented when to use execute_async() instead.
  • SEC-10 (#14): AnthropicEngine now retries transient errors (429, 500-504, 529 Overloaded) and connection failures with exponential backoff and jitter, matching OpenAIEngine's resilience.

Documentation

  • SEC-06 (#10): Added production deployment guidance recommending reverse-proxy rate limiting (Nginx limit_req_zone / Cloudflare) in front of Uvicorn, rather than in-app rate limiting that could drop legitimate bursts of WhatsApp webhook traffic.

Full Changelog: https://github.com/GustavoBaranda/chatflow-agent/blob/main/CHANGELOG.md