Repository navigation
馃殌 v2.1.0 Enterprise Banking Security & Distributed Tracing
XYO Financial Node.js SDK v2.1.0 delivers Tier-1 institutional security hardening, full W3C distributed tracing compliance, enhanced rate limiting resilience, zero-trust fail-closed SSRF defenses, PCI-DSS PII log redaction, dynamic secret rotation, and strict OpenAPI code isolation.
馃専 Highlights
- W3C Distributed Tracing: Full end-to-end tracing support via
correlationId(UUID v4) and standardtraceparent(W3C Trace Context RFC) headers across all single and batch financial transaction enrichment operations. - Rate Limiting: Dedicated
XyoRateLimitErrorclass providing structured access toRetry-After,RateLimit-Reset,RateLimit-Limit, andRateLimit-Remainingresponse headers with automatic ISO date and epoch timestamp parsing. - PCI-DSS PII Redaction: Elimination of raw response body preview strings in error diagnostics (preventing CWE-209 log leaks) and strict CRLF header injection protection (CWE-113) on
xApiUserheaders. - Pure OpenAPI Isolation: Architectural decoupling of ergonomic wrapper logic (
src/index.ts) from auto-generated OpenAPI bindings (src/generated/), ensuring zero manual modifications to generated client code. - Fail-Closed SSRF Defense: Zero-trust domain validation restricting archive downloads strictly to configured API host endpoints or verified AWS S3 (
*.amazonaws.com) domains with scheme validation rejecting non-HTTP protocols (file://,ftp://,gopher://). - Secret Rotation: NIST SP 800-57 compliant support for dynamic API keys and OAuth tokens via async
tokenSupplier/apiKeySuppliercallbacks.
馃摑 What's Changed / Detailed Commit Log
66a930fchore(release): bump version to 2.1.0 (#28)1875e82Automated SDK Update (#27)f5debd8ci: use SDK_DISPATCH_TOKEN for automated PR creation in generate workflow (#25)f050ca9fix(docs): use absolute raw github URL for mascot in README (#23)1c4038adocs(readme): add NestJS, Express, and Serverless integration recipes (#22)a006957style(readme): standardize header structure with mascot, title, and description (#21)a047c0edocs(readme): refine headings to omit 'Enterprise' and simplify 'Executive Summary' to 'Summary' (#20)5f3a8addocs(security): add Node.js runtime LTS schedule SVG and 3-month proactive sunset policy754cae6docs: standardize section heading emojis across markdown documentation (#19)2d993b8docs: add standard Keep a Changelog CHANGELOG.md (#18)04a5f3cci: remove npm whoami from release pipeline (#17)ebe2046feat(sdk): enforce zero trust domain validation and strongly-typed async body iteration (#16)8459703feat(sdk): universal async body iteration, SSRF preview mitigation, and tar parser bounds (#15)1a297e5feat(sdk): ISO 3166-1 alpha-2 validation and xApiUser CRLF injection protection (CWE-113) (#14)b08bc62feat(sdk): enterprise banking resilience, dynamic key rotation, and tar bomb protections (#13)0258a78docs(license): align LICENSE with exact standard Apache 2.0 text for licensecheck compliance
Full Diff Statistics: 34 files changed, 2762 insertions(+), 1404 deletions(-)
Full Changelog: v2.0.0...v2.1.0
馃摝 Installation & Usage Quickstart
Installation
npm install @xyo-financial/sdk-node@2.1.0Quickstart Example
import { XYOClient, XyoRateLimitError } from '@xyo-financial/sdk-node';
// Initialize client with W3C Distributed Tracing and dynamic key rotation
const client = new XYOClient({
apiKeySupplier: async () => process.env.XYO_API_KEY!,
correlationId: '123e4567-e89b-12d3-a456-426614174000',
traceparent: '00-4bf92f3577b34da6a3ce929d0e0e4736-00f067aa0ba902b7-01',
});
try {
const enrichment = await client.enrichTransaction({
raw_transaction: '0x1234567890abcdef...',
country_code: 'US',
});
console.log('Transaction enriched successfully:', enrichment);
} catch (error) {
if (error instanceof XyoRateLimitError) {
console.error(`Rate limited! Retry after ${error.retryAfterSeconds}s (Reset: ${error.resetAt})`);
} else {
console.error('API Error:', error);
}
}