Skip to content

Update the BFF docs based on the latest BFF Releases - #1250

Merged
maartenba merged 4 commits into
mainfrom
ev/bff-security-patch-docs
Oct 8, 2026
Merged

maartenba merged 4 commits into
mainfrom
ev/bff-security-patch-docs

Conversation

@Erwinvandervalk

@Erwinvandervalk Erwinvandervalk commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the documentation to the latest versions of BFF.

Starting with Duende.BFF 2.2.1, 2.3.1, 3.0.1, 3.1.1, 4.0.4, 4.1.3, 4.2.1,
and 4.3.1, the YARP integration removes the inbound Cookie header on all
routes by default. Document the new BffOptions.RemoveCookieHeaderFromYarpRequests
option, the global opt-out, per-route control with YARP transforms, and the
transform-ordering caveat.

* options.md: add RemoveCookieHeaderFromYarpRequests to the API options
* yarp.md: add "Cookie Header Removal" section (opt-out, per-route, ordering)
* remote.mdx: note that the direct forwarder never forwards Cookie
* troubleshooting.mdx: add entry for APIs that no longer receive cookies
* upgrading/index.mdx: add "Behavior Changes In Patch Releases" section

TODO (release day, once GHSA-vvg7-p7jw-8qr3 is published): add an advisory
link to
* upgrading/index.mdx, "YARP Routes No Longer Forward The Cookie Header"
* fundamentals/apis/yarp.md, the "Changed in ..." note under
  "Cookie Header Removal"
Starting with Duende.BFF 4.0.4, 4.1.3, 4.2.1, and 4.3.1, remote APIs
defined on a frontend (WithRemoteApis or Frontends:<name>:RemoteApis in
configuration) require the anti-forgery header. Requests without it get
401 and a warning is logged. The check respects
BffOptions.DisableAntiForgeryCheck and has no per-API opt-out.

* multi-frontend/index.mdx: add "Anti-forgery Protection For Remote APIs"
* multi-frontend/configuration.md: note the header requirement on remoteApis
* getting-started/multi-frontend.mdx: note the header next to WithRemoteApis
* options.md: DisableAntiForgeryCheck now covers frontend remote APIs
* remote.mdx: point to the frontend remote API anti-forgery section
* troubleshooting.mdx: mention frontend remote APIs under anti-forgery failures
* upgrading/index.mdx: add the behavior change to the patch release section

TODO (release day, once GHSA-4j63-5v5f-xcc4 is published): add an advisory
link to
* upgrading/index.mdx, "Frontend Remote APIs Require The Anti-Forgery Header"
* fundamentals/multi-frontend/index.mdx, the "Changed in ..." note under
  "Anti-forgery Protection For Remote APIs"
@Erwinvandervalk Erwinvandervalk changed the title BFF: document security patch behavior changes (Cookie header, frontend remote API anti-forgery) BFF: bump the samples to the latest versions Oct 7, 2026
@Erwinvandervalk Erwinvandervalk changed the title BFF: bump the samples to the latest versions Update the BFF docs based on the latest BFF Releases Oct 7, 2026
@Erwinvandervalk
Erwinvandervalk requested review from khalidabuhakmeh and maartenba and removed request for maartenba October 7, 2026 14:00
@Erwinvandervalk
Erwinvandervalk marked this pull request as ready for review October 7, 2026 14:01

@maartenba maartenba left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Couple of small suggestions

Comment thread astro/src/content/docs/bff/fundamentals/apis/yarp.md Outdated
Comment thread astro/src/content/docs/bff/fundamentals/multi-frontend/index.mdx Outdated
@maartenba maartenba added this to the 2026-Q4 milestone Oct 7, 2026
@maartenba maartenba added the documentation Improvements or additions to documentation label Oct 7, 2026
Erwinvandervalk and others added 2 commits October 7, 2026 16:38
Co-authored-by: Maarten Balliauw <maarten.balliauw@duendesoftware.com>
Co-authored-by: Maarten Balliauw <maarten.balliauw@duendesoftware.com>
@maartenba

Copy link
Copy Markdown
Member

Approved, feel free to merge @Erwinvandervalk

@maartenba
maartenba merged commit 6cf66d6 into main Oct 8, 2026
6 checks passed
@maartenba
maartenba deleted the ev/bff-security-patch-docs branch October 8, 2026 09:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants