| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| README.md | 2026-05-14 | 6.2 kB | |
| v0.13.1 -- Performance _ Security Hardening source code.tar.gz | 2026-05-14 | 5.6 MB | |
| v0.13.1 -- Performance _ Security Hardening source code.zip | 2026-05-14 | 5.7 MB | |
| Totals: 3 Items | 11.3 MB | 0 | |
Changelog
v0.13.1 — Performance & Security Hardening (2026-05-14)
High
- H-1: Converted
LocalBlobDriverfrom syncfs.*to asyncfs/promises— file uploads, downloads, and deletes no longer block the event loop - H-2: Replaced synchronous
scryptSyncwith asynccrypto.scrypt+ in-memory derived-key cache (5-min TTL) — settings encryption/decryption no longer blocks the event loop
Medium
- M-1: Replaced flat secret-key scrubbing with recursive
deepScrub()in agent workflow definitions and execution input storage — secrets at any nesting depth are now sanitized
Low
- L-1: Covered by H-2 async scrypt migration and key cache
Verified Clean
This audit round confirmed the following areas are free of findings: SQL injection (all identifier paths validated, all values parameterized), XSS (no HTML rendering), CSRF (Bearer token auth), mass assignment (field whitelists on all write paths), auth (all sensitive endpoints gated), rate limiting (enabled by default, applied to all auth flows), error leakage (all errors logged server-side only), command injection (zero child_process usage), crypto (bcrypt, AES-256-CBC, per-encryption salt, timing-safe OTP comparison, no Math.random).
v0.13.0 — Security Patch (2026-05-14)
Critical
- C-1: Added
validateIdentifiertoFieldconstructor andbuildExpectedColumns— closes SQL injection via field names in DDL (CREATE TABLE, ALTER TABLE) - C-2: Added semicolon guard with string-literal stripping before EXPLAIN view-query validation — prevents multi-statement injection bypass
High
- H-1: Re-validate collection name and field names after
Object.assignon PATCH — prevents path traversal and SQL injection from bypassed constructor validation - H-2: Converted all backup endpoints (list, create, upload, restore, delete) from sync
fs.*to asyncfs/promises— prevents event-loop blocking during backup operations
Medium
- M-1: Covered by C-1 Field constructor fix —
validateIdentifierrejects invalid field names at construction time
Low
- L-1: Covered by H-1 —
validateIdentifieron PATCH prevents invalid collection names from reaching DB and crashing bootstrap - L-2: Added per-field name validation in collection import endpoint — rejects invalid field names before collection creation
v0.12.1 — Security Patch (2026-05-14)
High
- H-1: Replaced
err.messagewith generic'Internal server error'in all API catch blocks (71 instances across 16 files) — full errors logged server-side only - H-2: Added rate limiters to all 6 user-facing auth flow endpoints (password reset, verification, email change — 5 req/hr request, 10 req/15min confirm)
- H-3: Added rate limiters to OAuth2 authentication callback and admin token refresh
- H-4: Replaced blocklist-based view query validation with EXPLAIN-based opcode analysis — blocks write operations (DDL, DML, PRAGMA, ATTACH)
Medium
- M-1: Added SELECT-only guard to
findRecordsByRawQuery - M-2: Clamped
setBcryptRoundsto [10, 12] to prevent DoS via excessive work factor - M-3: Replaced predictable
superuser_${Date.now()}IDs withcrypto.randomBytes - M-4: CLI superuser password input now masked with
*characters
Low
- L-1: Added
Referrer-Policy: no-referrerheader to password reset email responses - L-2: Replaced inline regex with shared
validateIdentifierin vector search - L-3: Replaced sync
fscalls withfs/promisesin automated backup cron
v0.12.0 — Security Patch (2025-05-14)
Critical
- C-1: Replaced
...createDataspread in OAuth2 flow with explicit field allowlist to prevent mass assignment ofpasswordHash - C-2: Added rate limiter to
auth-with-otpendpoint (5 req/min per IP+otpId) - C-3: Replaced
Math.random()withcrypto.randomIntfor OTP code generation - C-4: Replaced
Math.random()withcrypto.randomIntfor MFA backup codes; codes now hashed before storage
High
- H-1: Added
requireSuperuserAuthtoGET /api/collectionsandGET /api/collections/:idendpoints - H-2: Added
requireSuperuserAuthtoGET /api/cronsendpoint - H-3: Fixed SQL column/placeholder count mismatch in OTP INSERT statement
- H-4: Fixed
+/-field modifier bypass of protected-field stripping in record upsert - H-5: Replaced all
Math.random().toString(36)ID generation withcrypto.randomBytesacross 5 files - H-6: Enabled rate limiting by default (60 req/min per IP)
Medium
- M-1: Enabled SMTP TLS certificate validation by default
- M-2: Replaced hardcoded KDF salt with random per-encryption salt; added backward-compatible decryption
- M-3: Lowered JSON/URL-encoded body limit from 50MB to 10MB
- M-4: Sanitized morgan request logging to omit query strings
- M-5: Added field type validation for file upload
fieldquery parameter - M-6: Implemented per-account lockout after 10 consecutive failed auth attempts within 15 minutes
Low
- L-1: Replaced string comparison with
crypto.timingSafeEqualfor OTP hash verification - L-2: Capped workflow stream input size to 64KB before
JSON.parse - L-3: Applied rejection sampling to eliminate modulo bias in
generateRandomString - L-4: Loaded version from
package.jsonat runtime; enabledhelmet.hidePoweredBy() - L-5: Added structural validation for collection objects in the import endpoint
- L-6: Removed hardcoded localhost entries from OAuth2 redirect URL allowlist
v0.11.0 — Security Remediation (2025-05-13)
Security
- Fixed 32 security findings including critical SQL injection vulnerabilities, unauthenticated endpoints, weak encryption key fallback, and missing WebSocket authentication
- Added shared
validateIdentifierutility for consistent SQL injection prevention - Applied principle of least privilege with auth middleware additions
- See previous audit report for full details
v0.10.0 — Torque Integration
- Torque agent and workflow engine
- AI-assisted collection and rule generation