github DuendeSoftware/products bff-4.2.1
Duende.BFF 4.2.1

latest release: bff-4.3.1
5 hours ago

Duende.BFF 4.2.1

This is a security patch release for the 4.x line. It fixes two vulnerabilities in Duende.BFF.Yarp. We recommend that all users of 4.x upgrade.

Both fixes change default behavior. Read Breaking changes below before you upgrade.

The same fixes are released in 4.3.1, 4.2.1, 4.1.3 and 4.0.4.

Security fixes

  • Remote APIs on dynamic frontends now enforce the anti-forgery header (GHSA-4j63-5v5f-xcc4). Remote APIs configured on a dynamic frontend (with WithRemoteApis or with Frontends:<name>:RemoteApis in configuration) were proxied with the user's access token, but the BFF didn't check for the anti-forgery header (X-CSRF: 1). A cross-site page could therefore make state-changing calls to the backend on behalf of a logged-in user. The BFF now checks the header on these routes before it attaches the access token. Requests without the header get 401 Unauthorized, and the BFF logs a warning. The check respects BffOptions.DisableAntiForgeryCheck. MapRemoteBffApiEndpoint, local BFF APIs and YARP routes were already protected and aren't affected.
  • The YARP integration no longer forwards the Cookie header (GHSA-vvg7-p7jw-8qr3). Routes proxied through the BFF's YARP integration (AddYarpConfig, or AddReverseProxy().AddBffExtensions()) forwarded the incoming Cookie header to the remote API. That header includes the BFF session cookie, which was sent along with the access token. The BFF now removes the Cookie header from requests on all YARP routes, as MapRemoteBffApiEndpoint already did.

Breaking changes

  • Remote API calls on dynamic frontends need the X-CSRF: 1 header. Make sure your frontend sends it on every call to a remote API configured on a dynamic frontend. Calls without it now return 401.

  • YARP routes no longer forward cookies to remote APIs. If an upstream API needs cookies from the browser, you can turn this off for the whole application with the new BffOptions.RemoveCookieHeaderFromYarpRequests option:

    builder.Services.AddBff(options =>
    {
        options.RemoveCookieHeaderFromYarpRequests = false;
    });

    With the option set to false, YARP forwards cookies as before. You can then control cookie forwarding per route with standard YARP transforms, for example RequestHeaderRemove: Cookie. Only do this for upstream APIs you trust with the BFF session cookie.

Don't miss a new products release

NewReleases is sending notifications on new releases.