github DuendeSoftware/products bff-3.1.1
Duende.BFF 3.1.1

latest releases: bff-4.3.1, bff-4.2.1, bff-4.1.3...
5 hours ago

Duende.BFF 3.1.1

This is a security patch release. It fixes a vulnerability in Duende.BFF.Yarp. We recommend that all users of the YARP integration upgrade.

The fix changes default behavior. Read Breaking changes below before you upgrade.

The same fix is released in 3.1.1, 3.0.1, 2.3.1 and 2.2.1, and for 4.x in 4.3.1, 4.2.1, 4.1.3 and 4.0.4.

Security fixes

  • The YARP integration no longer forwards the Cookie header (GHSA-vvg7-p7jw-8qr3). Routes proxied through the BFF's YARP integration (AddReverseProxy().AddBffExtensions()) forwarded the incoming Cookie header to the remote API. That header includes the BFF session cookie, which was sent along with the access token. The BFF now removes the Cookie header from requests on all YARP routes, as MapRemoteBffApiEndpoint already did.

Breaking changes

  • YARP routes no longer forward cookies to remote APIs. If an upstream API needs cookies from the browser, you can turn this off for the whole application with the new BffOptions.RemoveCookieHeaderFromYarpRequests option:

    builder.Services.AddBff(options =>
    {
        options.RemoveCookieHeaderFromYarpRequests = false;
    });

    With the option set to false, YARP forwards cookies as before. You can then control cookie forwarding per route with standard YARP transforms, for example RequestHeaderRemove: Cookie. Only do this for upstream APIs you trust with the BFF session cookie.

Don't miss a new products release

NewReleases is sending notifications on new releases.