Skip to content

v1.0.2

Latest

Choose a tag to compare

@SecuriLee SecuriLee released this 12 Apr 09:57
e7eca22

🚀 v1.0.2 - Production Hardening & Performance Update

This release focuses on internal robustness, performance optimization for high-traffic environments, and expanded security traps to prevent library tampering.

🛠️ What’s New in v1.0.2?

⚡ O(1) Performance Optimization

The core policy engine has been rewritten to use Sets instead of Arrays.

  • The Benefit: Whether your allowlist contains 5 methods or 5,000, the lookup time is now constant ($O(1)$). This ensures LITM adds virtually zero latency to your legacy method calls.

🛡️ Expanded Proxy Traps (Advanced Hardening)

We have moved beyond simple get interception. LITM now guards the entire lifecycle of the library object:

  • SET Trap: Prevents "Prototype Pollution" or malicious overwriting of library methods at runtime.
  • HAS Trap: Intercepts in operator checks (e.g., 'riskyMethod' in lib). In enforcement mode, blocked methods will now appear as non-existent to the calling code.
  • DELETE Trap: Blocks attempts to delete security-critical functions from the library.

🔗 Context-Aware Execution

Improved handling of the this context using .apply(obj, args). This ensures that legacy libraries relying on internal state or private variables continue to function perfectly even when wrapped.

📝 Developer Experience (IntelliSense)

Added full JSDoc Typedefs for all configuration options and callbacks. Developers using VS Code or other modern IDEs will now see full auto-completion and documentation for allowlist, denylist, and validate hooks.


📦 Updated Implementation Example

const LibraryInTheMiddle = require('./litm');
const legacyLib = require('vulnerable-package');

const secured = new LibraryInTheMiddle(legacyLib, {
    name: "Legacy-Vault",
    transparent: false, // Set to false for active blocking
    allowlist: ['read', 'write'], 
    denylist: ['eval', 'adminCmd'],
    onTelemetry: (data) => {
        // New structured telemetry includes 'action' (blocked/executed/threw)
        sendToSIEM(data);
    }
});

🛡️ Security Posture Reminder

  • Prevent: Use transparent: false to kill unauthorized calls.
  • Detect: Use onTelemetry to watch for detected-risky events.
  • Correct: Audit the threw events to see if the legacy library is failing under specific payloads.

Full Changelog: v1.0.1...v1.0.2