Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,13 +7,15 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0

## [Unreleased]

## [0.18.0] - 2026-09-27

### Added

- **`trustProxy: 'railway'`.** Railway's edge replaces any `X-Forwarded-For` the client sent with exactly `<client>, <edge>`, so the visitor is two entries from the right. A depth of `1`, and the Next.js and Hono default, names Railway's edge for every visitor instead. `'railway'` is the same answer as a depth of `2`, under a name you do not have to work out. Works in every adapter.

### Changed

- **Fastify: pass the hop count to the plugin, not to Fastify.** Since Fastify 5.12 a numeric server `trustProxy` trusts no hop at all, so `request.ip` stays the socket address. The plugin's own `trustProxy` is unaffected; its documentation now says so.
- **Fastify: pass the hop count to the plugin, not to Fastify.** Since Fastify 5.12.1 a numeric server `trustProxy` trusts no hop at all, so `request.ip` stays the socket address. The plugin's own `trustProxy` is unaffected; its documentation now says so.

## [0.17.0] - 2026-09-24

Expand Down
20 changes: 10 additions & 10 deletions package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion packages/client/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@webdecoy/client",
"version": "0.17.0",
"version": "0.18.0",
"description": "Web Decoy browser widget - signal collection, proof-of-work, and captcha UI",
"main": "./dist/index.js",
"module": "./dist/index.mjs",
Expand Down
4 changes: 2 additions & 2 deletions packages/express/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@webdecoy/express",
"version": "0.17.0",
"version": "0.18.0",
"description": "Web Decoy middleware for Express.js",
"main": "./dist/index.js",
"types": "./dist/index.d.ts",
Expand Down Expand Up @@ -40,7 +40,7 @@
"url": "https://github.com/WebDecoy/node/issues"
},
"dependencies": {
"@webdecoy/node": "^0.17.0"
"@webdecoy/node": "^0.18.0"
},
"peerDependencies": {
"express": "^4.18.0 || ^5.0.0"
Expand Down
4 changes: 2 additions & 2 deletions packages/fastify/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@webdecoy/fastify",
"version": "0.17.0",
"version": "0.18.0",
"description": "Web Decoy plugin for Fastify",
"main": "./dist/index.js",
"types": "./dist/index.d.ts",
Expand Down Expand Up @@ -40,7 +40,7 @@
"url": "https://github.com/WebDecoy/node/issues"
},
"dependencies": {
"@webdecoy/node": "^0.17.0",
"@webdecoy/node": "^0.18.0",
"fastify-plugin": "^4.5.1"
},
"peerDependencies": {
Expand Down
2 changes: 1 addition & 1 deletion packages/fastify/src/plugin.ts
Original file line number Diff line number Diff line change
Expand Up @@ -65,7 +65,7 @@ export interface WebDecoyPluginOptions extends ProtectOptions {
* it to override that for WebDecoy alone — a number of trusted hops,
* `'cloudflare'`, `'railway'`, or CIDRs of your proxies.
*
* Prefer this over Fastify's own option for a hop count: since Fastify 5.12 a
* Prefer this over Fastify's own option for a hop count: since Fastify 5.12.1 a
* numeric server `trustProxy` trusts no hop at all (a count cannot tell a
* proxy from a direct client), so `request.ip` stays the socket address.
*
Expand Down
4 changes: 2 additions & 2 deletions packages/hono/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@webdecoy/hono",
"version": "0.17.0",
"version": "0.18.0",
"description": "Web Decoy middleware for Hono — Cloudflare Workers, Bun, Deno, Node",
"main": "./dist/index.js",
"types": "./dist/index.d.ts",
Expand Down Expand Up @@ -44,7 +44,7 @@
"url": "https://github.com/WebDecoy/node/issues"
},
"dependencies": {
"@webdecoy/node": "^0.17.0"
"@webdecoy/node": "^0.18.0"
},
"peerDependencies": {
"hono": "^4.0.0"
Expand Down
4 changes: 2 additions & 2 deletions packages/nextjs/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@webdecoy/nextjs",
"version": "0.17.0",
"version": "0.18.0",
"description": "Web Decoy middleware for Next.js",
"main": "./dist/index.js",
"types": "./dist/index.d.ts",
Expand Down Expand Up @@ -42,7 +42,7 @@
"url": "https://github.com/WebDecoy/node/issues"
},
"dependencies": {
"@webdecoy/node": "^0.17.0"
"@webdecoy/node": "^0.18.0"
},
"peerDependencies": {
"next": ">=13.0.0"
Expand Down
2 changes: 1 addition & 1 deletion packages/webdecoy/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@webdecoy/node",
"version": "0.17.0",
"version": "0.18.0",
"description": "Web Decoy SDK for Node.js - Bot detection with TLS fingerprinting",
"main": "./dist/index.js",
"types": "./dist/index.d.ts",
Expand Down
Loading