Dynoxide 1.3.0: security fixes and fussier pagination
Dynoxide 1.3.0 ended up a bit bigger than I'd planned. Working through the compatibility fixes turned up some DynamoDB behaviour I hadn't expected, and I also fixed two security issues that needed advisories. There's a lot in the release notes, so I've picked out a few highlights below, including a contribution that makes test runs quieter and a few things to check before upgrading. Two security…
Dynoxide 1.3.0 introduces several security fixes and improvements. Two significant security issues were addressed: one related to DynamoDB behaviour and another involving tokens in help output. The high-severity issue in expression parsing, which occurred when certain non-ASCII characters were present, now results in a syntax error instead of a panic.
Additionally, subcommand help no longer reveals the value of DYNOXIDE_MCP_AUTH_TOKEN, mitigating a low-severity security concern. The release also includes an update to the aws-smithy-json dependency and includes several noticeable changes to pagination rules. DynamoDB's behaviour regarding pagination tokens has become stricter, with rules requiring exact matches on statement text, whitespace, keyword case, and key order.
As a result, changes to statements between pages will now be detected, and failure to comply will lead to request refusal. Other changes include making ORDER BY statements mandatory, handling malformed conditions, and properly managing vector capacity for writes. The release also brings more accurate information on table and index sizes and better error reporting.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.