🚀 v1.0.2 - Production Hardening & Performance Update
This release focuses on internal robustness, performance optimization for high-traffic environments, and expanded security traps to prevent library tampering.
🛠️ What’s New in v1.0.2?
⚡ O(1) Performance Optimization
The core policy engine has been rewritten to use Sets instead of Arrays.
-
The Benefit: Whether your
allowlistcontains 5 methods or 5,000, the lookup time is now constant ($O(1)$). This ensures LITM adds virtually zero latency to your legacy method calls.
🛡️ Expanded Proxy Traps (Advanced Hardening)
We have moved beyond simple get interception. LITM now guards the entire lifecycle of the library object:
- SET Trap: Prevents "Prototype Pollution" or malicious overwriting of library methods at runtime.
- HAS Trap: Intercepts
inoperator checks (e.g.,'riskyMethod' in lib). In enforcement mode, blocked methods will now appear as non-existent to the calling code. - DELETE Trap: Blocks attempts to delete security-critical functions from the library.
🔗 Context-Aware Execution
Improved handling of the this context using .apply(obj, args). This ensures that legacy libraries relying on internal state or private variables continue to function perfectly even when wrapped.
📝 Developer Experience (IntelliSense)
Added full JSDoc Typedefs for all configuration options and callbacks. Developers using VS Code or other modern IDEs will now see full auto-completion and documentation for allowlist, denylist, and validate hooks.
📦 Updated Implementation Example
const LibraryInTheMiddle = require('./litm');
const legacyLib = require('vulnerable-package');
const secured = new LibraryInTheMiddle(legacyLib, {
name: "Legacy-Vault",
transparent: false, // Set to false for active blocking
allowlist: ['read', 'write'],
denylist: ['eval', 'adminCmd'],
onTelemetry: (data) => {
// New structured telemetry includes 'action' (blocked/executed/threw)
sendToSIEM(data);
}
});
🛡️ Security Posture Reminder
- Prevent: Use
transparent: falseto kill unauthorized calls. - Detect: Use
onTelemetryto watch fordetected-riskyevents. - Correct: Audit the
threwevents to see if the legacy library is failing under specific payloads.
Full Changelog: v1.0.1...v1.0.2