Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 19 additions & 3 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,16 +7,32 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0

## [Unreleased]

### Added

- **OpenTelemetry spans** around `protect()` and rule evaluation. Pass a tracer: `new WebDecoy({ tracer: trace.getTracer('webdecoy') })`. Injected rather than imported, so the package stays dependency-free and edge-safe — the `Tracer` type is a structural subset of OpenTelemetry's, so `trace.getTracer()` works with no adapter, and omitting it means no spans, no dependency and no behaviour change. Attributes cover the decision id (which joins a span to its dashboard row), the conclusion, the deciding rule, and whether the request cost a round trip to ingest. A tracer that throws cannot fail a request.
## [0.15.1] - 2026-09-16

### Changed

- **`ClearanceOptions.scope` is documented as reserved.** It was described as a route-group scope that limits where a token is valid. No validator enforces that: a clearance token is bound to the organization, and each protected path's verification level is the way to require stronger proof. Passing `scope` (or `data-scope` on the script tag) still works and still has no effect.

## [0.15.0] - 2026-08-28

### Fixed

- **A datacenter or VPN IP alone no longer forwards a request for server verification.** Local analysis scored a datacenter/VPN address high enough on its own to forward the request, so a real visitor on a VPN, with a normal browser and full headers, was sent for server-side scoring exactly like a bot. The SDK now forwards on a genuine local bot signal (a bot or automation user agent, or missing headers every real browser sends) or when TLS details are available to fingerprint. A datacenter IP and an absent `Sec-CH-UA` no longer force a forward, alone or together; both still travel with a request that is forwarded for another reason. Trade-off: a bot that perfectly imitates a browser from a datacenter IP, with no TLS details, is no longer forwarded on the IP alone.

## [0.14.0] - 2026-08-28

### Changed

- **Breaking: server-to-server traffic defaults to `https://in.webdecoy.com`.** The default `apiUrl` moved from `https://ingest.webdecoy.com`. Server-to-server calls carry no browser fingerprint, so the fronted hostname costs nothing and adds DDoS absorption and rate limiting in front of ingest. If you set `apiUrl` explicitly, nothing changes. `@webdecoy/client` keeps the direct hostname, because a browser's own TLS handshake is part of what it reports.

- **One adapter core.** Express, Fastify, Next.js (middleware and Pages wrapper) and the fetch guard each carried their own copy of skip-path matching, the 429 and 403 payloads, and honeytoken arming — five copies of one set of decisions, and five places the next correction can fail to land. They now share `adapter-core.ts`; the framework-specific response mechanics are untouched, and every honeytoken-injection test passes unchanged. Fastify keeps its awaited arming, which has no window where early requests are served without the link.

### Added

- **OpenTelemetry spans** around `protect()` and rule evaluation. Pass a tracer: `new WebDecoy({ tracer: trace.getTracer('webdecoy') })`. Injected rather than imported, so the package stays dependency-free and edge-safe — the `Tracer` type is a structural subset of OpenTelemetry's, so `trace.getTracer()` works with no adapter, and omitting it means no spans, no dependency and no behaviour change. Attributes cover the decision id (which joins a span to its dashboard row), the conclusion, the deciding rule, and whether the request cost a round trip to ingest. A tracer that throws cannot fail a request.

- **Six more crawlers are recognised:** DuckAssistBot, SofyaBot, Reflectionbot, xAI-SearchBot, LinkupBot, and IbouBot (classified as a search crawler).

## [0.13.0] - 2026-08-22

### Added
Expand Down
20 changes: 10 additions & 10 deletions package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion packages/client/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@webdecoy/client",
"version": "0.15.0",
"version": "0.15.1",
"description": "Web Decoy browser widget - signal collection, proof-of-work, and captcha UI",
"main": "./dist/index.js",
"module": "./dist/index.mjs",
Expand Down
4 changes: 2 additions & 2 deletions packages/client/src/clearance.ts
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
/**
* wd_clearance minting (WAF Enforcement PRD FR6 / closes the #124 loop).
* wd_clearance minting.
*
* Real browsers earn a signed clearance token from WebDecoy's ingest service and
* carry it in a first-party cookie. The edge validator (FR7) lets tokened
* carry it in a first-party cookie. The edge validator lets tokened
* sessions through; a decoy hit denies the token's fp (deny-at-mint + live-token
* revocation). This is the *allow-and-observe* path — it mints silently during
* normal browsing so the loop covers monitor mode, not just the enforce-mode
Expand Down
4 changes: 2 additions & 2 deletions packages/express/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@webdecoy/express",
"version": "0.15.0",
"version": "0.15.1",
"description": "Web Decoy middleware for Express.js",
"main": "./dist/index.js",
"types": "./dist/index.d.ts",
Expand Down Expand Up @@ -40,7 +40,7 @@
"url": "https://github.com/WebDecoy/node/issues"
},
"dependencies": {
"@webdecoy/node": "^0.15.0"
"@webdecoy/node": "^0.15.1"
},
"peerDependencies": {
"express": "^4.18.0 || ^5.0.0"
Expand Down
4 changes: 2 additions & 2 deletions packages/fastify/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@webdecoy/fastify",
"version": "0.15.0",
"version": "0.15.1",
"description": "Web Decoy plugin for Fastify",
"main": "./dist/index.js",
"types": "./dist/index.d.ts",
Expand Down Expand Up @@ -40,7 +40,7 @@
"url": "https://github.com/WebDecoy/node/issues"
},
"dependencies": {
"@webdecoy/node": "^0.15.0",
"@webdecoy/node": "^0.15.1",
"fastify-plugin": "^4.5.1"
},
"peerDependencies": {
Expand Down
4 changes: 2 additions & 2 deletions packages/hono/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@webdecoy/hono",
"version": "0.15.0",
"version": "0.15.1",
"description": "Web Decoy middleware for Hono — Cloudflare Workers, Bun, Deno, Node",
"main": "./dist/index.js",
"types": "./dist/index.d.ts",
Expand Down Expand Up @@ -44,7 +44,7 @@
"url": "https://github.com/WebDecoy/node/issues"
},
"dependencies": {
"@webdecoy/node": "^0.15.0"
"@webdecoy/node": "^0.15.1"
},
"peerDependencies": {
"hono": "^4.0.0"
Expand Down
4 changes: 2 additions & 2 deletions packages/nextjs/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@webdecoy/nextjs",
"version": "0.15.0",
"version": "0.15.1",
"description": "Web Decoy middleware for Next.js",
"main": "./dist/index.js",
"types": "./dist/index.d.ts",
Expand Down Expand Up @@ -42,7 +42,7 @@
"url": "https://github.com/WebDecoy/node/issues"
},
"dependencies": {
"@webdecoy/node": "^0.15.0"
"@webdecoy/node": "^0.15.1"
},
"peerDependencies": {
"next": ">=13.0.0"
Expand Down
2 changes: 1 addition & 1 deletion packages/webdecoy/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@webdecoy/node",
"version": "0.15.0",
"version": "0.15.1",
"description": "Web Decoy SDK for Node.js - Bot detection with TLS fingerprinting",
"main": "./dist/index.js",
"types": "./dist/index.d.ts",
Expand Down
Loading