Releases: stellar/js-stellar-sdk
Releases · stellar/js-stellar-sdk
v15.1.0
v15.1.0
Fixed
- Security:
FederationServer.createForDomainand theFederationServerconstructor now validate domains per RFC 1035, rejecting malformed domains before issuing federation orstellar.tomlrequests. Port numbers are also accepted (#1393). RpcServer.pollTransactionoff-by-one: the polling loop used<instead of<=, causing one fewer attempt than configured(#1373).requestAirdroperror path: fixed incorrect property access (error.response.detailinstead oferror.response.data.detail) when checking forcreateAccountAlreadyExist(#1373).Spec.typeRefnow properly handlesscSpecTypeResultby returning the JSON schema for theokType, instead of silently breaking out of the switch (#1373).structToJsonSchemanow placesadditionalProperties: falseon the schema object itself rather than incorrectly nesting it insideproperties(#1373).- Fixed bigint-to-U32/I32 conversion in
SpecusingNumber(val)instead ofval as number(a no-op for bigints) (#1373). - WASM custom section parser: when a section was skipped (invalid name length), the offset was not advanced, causing an infinite loop or incorrect parsing of subsequent sections (#1373).
FederationServerURL mutation:resolveAddress,resolveAccountId, andresolveTransactionIdmutated the sharedserverURLby appending query params on each call. Fixed by cloning the URL before modifying (#1373).CallBuilder.stream()URL mutation:stream()mutated the sharedthis.urlby adding query params, corrupting the builder for subsequent calls. Fixed by cloning the URL (#1373).AssembledTransactionrestore path: whenbuildWithOpwas used and automatic state restoration was needed, the rebuild incorrectly reconstructed the operation viacontract.call()instead of reusing the original operation (#1373).SERVER_TIME_MAPport collision: the Horizon time-sync cache keyed entries by hostname only, so two servers on different ports of the same host shared a cache entry. Fixed by including the port in the key (#1373).Spec.funcResToNativenow correctly returns anErrinstance when a contract function with aResultreturn type returns an error, instead of throwing while decoding it as theOktype (#1373).- SEP-10:
verifyChallengeTxSignersnow rejects challenges signed only by the server andclient_domainkey with no actual client signer, instead of returning an empty signers list (#1372). getAssetBalanceused incorrect flag bitmask constants (AuthRequiredFlag,AuthRevocableFlag,AuthClawbackEnabledFlag) which are account-level flags, not trustline-level flags. Replaced with the correct trustline flag bitmasks (0x1,0x2,0x4) (#1372).AssembledTransaction.simulatedid not clearthis.builtbefore re-simulating after a state restoration rebuild, causing it to assemble stale transaction data (#1372).AssembledTransaction.signAndSendmutated the sharedthis.options.submitflag to prevent double submission. Replaced with a wrapper aroundsignTransactionthat injectssubmit: falsewithout mutating shared state (#1372).- Fetch HTTP client: async request interceptors were not awaited — the synchronous
try/catchloop passed unresolved promise objects as the config. Replaced with a proper.then()chain matching Axios interceptor semantics (#1372). - Fetch HTTP client: cancellation now preserves custom cancel reasons and
isCancelno longer depends on exact error-message text (#1390). - Fetch HTTP client: instance default headers and params now merge correctly with per-request overrides on the no-axios / minimal builds, including requests that use bounded options (#1390).
- Fetch HTTP client:
maxRedirectsandmaxContentLengthwere silently ignored on the no-axios / minimal builds, turning SDK-set SSRF and DoS guards (StellarToml.Resolver.resolve,FederationServer) into no-ops. A new bounded adapter activates when either option is set, refusing redirects pastmaxRedirectsand streaming the response body with a running-total check so oversized responses abort mid-stream (#1390). - Fetch HTTP client: the no-axios bounded path now more closely matches Axios behavior for object request bodies,
baseURL, timeout errors, redirect method/body handling, and stripping credential-bearing headers on cross-origin redirects (#1390). src/bindings/config.tsimported../../package.jsonwith a relative path that resolved incorrectly for thelib/no-axios/andlib/minimal/build outputs, making those libs unloadable. Replaced with the__PACKAGE_VERSION__compile-time define (#1390).- Updated the production
axiosdependency from1.14.0to1.15.0(#1381).
Added
AccountResponseconstructor now uses explicit field-by-field assignment instead ofObject.entriesdynamic assignment for type safety (#1373).- Added
transactionscollection toApi.AccountRecordandAccountResponse(#1373). - Added range checks for U32/I32 values in
Spec: bigint values are now validated against min/max bounds before conversion, throwing aRangeErrorinstead of silently truncating (#1373). rpc.Server.getLatestLedger()now includescloseTime,headerXdr, andmetadataXdrin the typed response, withheaderXdr/metadataXdrparsed into XDR objects instead of raw base64 strings (#1389).
Deprecated
BalanceResponse.revocableis deprecated in favor ofauthorizedToMaintainLiabilities, which correctly reflects the trustline flag semantics (#1372).
Full Changelog: v15.0.1...v15.1.0
v15.0.1: Protocol 26
v15.0.1: Protocol 26
Breaking Changes
- XDR has been upgraded to support Protocol 26, please refer to the
@stellar/stellar-baserelease notes for details and other breaking changes.
Fixed
- Sanitize identifiers and escape string literals in generated TypeScript bindings to prevent code injection via malicious contract spec names.
sanitizeIdentifiernow strips non-identifier characters, and a newescapeStringLiteralhelper escapes quotes and newlines in string contexts (#1345). AssembledTransaction.fromXDR()andfromJSON()now validate that the deserialized transaction targets the expected contract, rejecting mismatched contract IDs and non-invokeContract operations. (#1349).- Pin exact version on axios dependency (#1365)
Contributors
Full Changelog: v14.6.1...v15.0.1
v14.6.1
v14.6.1
Fixed
- Fix
assembleTransactiondouble-counting the resource fee when the input transaction already has Soroban data attached (e.g. when re-assembling a previously simulated transaction) (#1343). - Removed adding
resourceFeeinrpc.assembleTransactionas it's now handled byTransactionBuilder.build()(#1343).
Full Changelog: v14.6.0...v14.6.1
v14.6.0
v14.6.0
Added
- Upgraded underlying
@stellar/stellar-baselibrary to include its new features and fixes (release notes).
Full Changelog: v14.5.0...v14.6.0
v14.5.0
v14.5.0
Added
- Introduced CLI functionality for generating smart contract bindings (#1287).
- Added
BindingGenerationclass for parsing contract specs into fully typed TypeScript libraries for calling contract methods (#1287). - Introduced
rpc.Server.fundAddressthat supports funding contract and account addresses via Friendbot (#1314). - Updated the
StellarTomlinterface with SEP 45 fieldsWEB_AUTH_FOR_CONTRACTS_ENDPOINTandWEB_AUTH_CONTRACT_ID(#1326).
Fixed
- X-App-Name and X-App-Version headers are now included when using
CallBuilder.stream()(#1317). CallBuildernow correctly uses the configured server URL for all requests, including pagination and linked resources. Previously, URLs returned by Horizon in_linkswould bypass reverse proxies (#1318).
Deprecated
rpc.Server.requestAirdropis deprecated in favor ofrpc.Server.fundAddress(#1314).
Contributors
@ElliotFriend, @leighmcculloch, @Ryang-21, @wpalmeri made their first contribution in #1321, and @joaquinsoza made their first contribution in #1314
Full Changelog: v14.4.3...v14.5.0
v14.4.3
v14.4.2
v14.4.1
v14.4.0
v14.4.0
Added
- Introduced an
rpc.Server.getAssetBalance()helper to fetch asset balances both for contracts and accounts (#1286). rpc.Api.BalanceResponsenow can include arevocablefield in itsbalanceEntryfor when trustlines are fetched (#1286).- Added Timepoint and Duration support to
Spec(#1288) Api.GetHealthResponseinterface now includeslatestLedger,ledgerRetentionWindow, andoldestLedgerfields (#1297).- Added
publicKey,signTransaction, andsignAuthEntryas optional fields tocontract.MethodOptions(#1293).
Fixed
Api.RawEventResponse.topicsis now optional to reflect topicless events (#1292).parseRawEventscorrectly checks ifApi.RawEventResponse.topicsis undefined (#1292).- Remove
WebAssemblyusage in favor of manual wasm parsing (#1300). - Fixed URL contamination in
Horizon.Servermethods (#1296).
Contributors
- @chadoh, @corymsmith, @Shaptic, @Ryang-2, @mootz12 made their first contribution in #1288
Full Changelog: v14.3.3...v14.4.0
v14.3.3
v14.3.3
Added
Spec.nativeToScValsupports parsing Muxed Address(#1274),
Contributors
- @alberto-crossmint made their first contribution in #1274, @jeesunikim
Full Changelog: v14.3.2...v14.3.3