Skip to content

Release 1.4.0: universal middleware and scoped tool boundaries - #10

Merged
umudhasanli merged 1 commit into
mainfrom
feat/universal-boundaries-1.4
Aug 4, 2026
Merged

umudhasanli merged 1 commit into
mainfrom
feat/universal-boundaries-1.4

Conversation

@umudhasanli

Copy link
Copy Markdown
Collaborator

Summary

  • add flare-redact/middleware, a policy-first integration boundary for any SDK or framework with redact, observe, and block modes
  • add createScopedToolBoundary() so each trusted tool scope can restore only its own placeholders, closing cross-tool placeholder transplantation
  • document safe integrations, migration guidance, a runnable universal example, and the 1.4.0 release notes
  • extend CI and benchmarks for the new integration surface

Security model

The authorization scope is resolved by trusted application routing, never from a model-supplied tool name. Legacy createToolBoundary() remains compatible and is explicitly documented for a single tool or trust domain.

Verification

  • npm test — 194 tests passed
  • npm audit — 0 vulnerabilities
  • npm pack --dry-run — middleware JavaScript and declarations included
  • fresh tarball consumer smoke test passed
  • OpenAI privacy, Express/Pino, and universal-boundaries examples passed
  • performance and adversarial benchmark suites passed

@umudhasanli
umudhasanli merged commit 3e0065d into main Aug 4, 2026
5 checks passed
@umudhasanli
umudhasanli deleted the feat/universal-boundaries-1.4 branch August 4, 2026 08:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant