Skip to content

v2.1.0

Latest

Choose a tag to compare

@syniol syniol released this 22 Aug 23:50
· 10 commits to main since this release
66a930f

馃殌 v2.1.0 Enterprise Banking Security & Distributed Tracing

XYO Financial Node.js SDK v2.1.0 delivers Tier-1 institutional security hardening, full W3C distributed tracing compliance, enhanced rate limiting resilience, zero-trust fail-closed SSRF defenses, PCI-DSS PII log redaction, dynamic secret rotation, and strict OpenAPI code isolation.

馃専 Highlights

  • W3C Distributed Tracing: Full end-to-end tracing support via correlationId (UUID v4) and standard traceparent (W3C Trace Context RFC) headers across all single and batch financial transaction enrichment operations.
  • Rate Limiting: Dedicated XyoRateLimitError class providing structured access to Retry-After, RateLimit-Reset, RateLimit-Limit, and RateLimit-Remaining response headers with automatic ISO date and epoch timestamp parsing.
  • PCI-DSS PII Redaction: Elimination of raw response body preview strings in error diagnostics (preventing CWE-209 log leaks) and strict CRLF header injection protection (CWE-113) on xApiUser headers.
  • Pure OpenAPI Isolation: Architectural decoupling of ergonomic wrapper logic (src/index.ts) from auto-generated OpenAPI bindings (src/generated/), ensuring zero manual modifications to generated client code.
  • Fail-Closed SSRF Defense: Zero-trust domain validation restricting archive downloads strictly to configured API host endpoints or verified AWS S3 (*.amazonaws.com) domains with scheme validation rejecting non-HTTP protocols (file://, ftp://, gopher://).
  • Secret Rotation: NIST SP 800-57 compliant support for dynamic API keys and OAuth tokens via async tokenSupplier / apiKeySupplier callbacks.

馃摑 What's Changed / Detailed Commit Log

  • 66a930f chore(release): bump version to 2.1.0 (#28)
  • 1875e82 Automated SDK Update (#27)
  • f5debd8 ci: use SDK_DISPATCH_TOKEN for automated PR creation in generate workflow (#25)
  • f050ca9 fix(docs): use absolute raw github URL for mascot in README (#23)
  • 1c4038a docs(readme): add NestJS, Express, and Serverless integration recipes (#22)
  • a006957 style(readme): standardize header structure with mascot, title, and description (#21)
  • a047c0e docs(readme): refine headings to omit 'Enterprise' and simplify 'Executive Summary' to 'Summary' (#20)
  • 5f3a8ad docs(security): add Node.js runtime LTS schedule SVG and 3-month proactive sunset policy
  • 754cae6 docs: standardize section heading emojis across markdown documentation (#19)
  • 2d993b8 docs: add standard Keep a Changelog CHANGELOG.md (#18)
  • 04a5f3c ci: remove npm whoami from release pipeline (#17)
  • ebe2046 feat(sdk): enforce zero trust domain validation and strongly-typed async body iteration (#16)
  • 8459703 feat(sdk): universal async body iteration, SSRF preview mitigation, and tar parser bounds (#15)
  • 1a297e5 feat(sdk): ISO 3166-1 alpha-2 validation and xApiUser CRLF injection protection (CWE-113) (#14)
  • b08bc62 feat(sdk): enterprise banking resilience, dynamic key rotation, and tar bomb protections (#13)
  • 0258a78 docs(license): align LICENSE with exact standard Apache 2.0 text for licensecheck compliance

Full Diff Statistics: 34 files changed, 2762 insertions(+), 1404 deletions(-)
Full Changelog: v2.0.0...v2.1.0


馃摝 Installation & Usage Quickstart

Installation

npm install @xyo-financial/sdk-node@2.1.0

Quickstart Example

import { XYOClient, XyoRateLimitError } from '@xyo-financial/sdk-node';

// Initialize client with W3C Distributed Tracing and dynamic key rotation
const client = new XYOClient({
  apiKeySupplier: async () => process.env.XYO_API_KEY!,
  correlationId: '123e4567-e89b-12d3-a456-426614174000',
  traceparent: '00-4bf92f3577b34da6a3ce929d0e0e4736-00f067aa0ba902b7-01',
});

try {
  const enrichment = await client.enrichTransaction({
    raw_transaction: '0x1234567890abcdef...',
    country_code: 'US',
  });
  console.log('Transaction enriched successfully:', enrichment);
} catch (error) {
  if (error instanceof XyoRateLimitError) {
    console.error(`Rate limited! Retry after ${error.retryAfterSeconds}s (Reset: ${error.resetAt})`);
  } else {
    console.error('API Error:', error);
  }
}