@astrojs/node
π Patch Changes
-
#16002
846f27fThanks @buley! - Fixes file descriptor leaks from read streams that were not destroyed on client disconnect or read errors -
#15941
f41584aThanks @ematipico! - Fixes an infinite loop inresolveClientDir()when the server entry point is bundled with esbuild or similar tools. The function now throws a descriptive error instead of hanging indefinitely when the expected server directory segment is not found in the file path.
-
π Patch Changes
-
#15735
9685e2dThanks @fa-sharp! - Fixes an EventEmitter memory leak when serving static pages from Node.js middleware.When using the middleware handler, requests that were being passed on to Express / Fastify (e.g. static files / pre-rendered pages / etc.) werenβt cleaning up socket listeners before calling
next(), causing a memory leak warning. This fix makes sure to run the cleanup before callingnext().
-
π Patch Changes
- #15934
6f8f0bcThanks @ematipico! - Updates the AstropeerDependencies#astroto be6.0.0.
- #15934
π Patch Changes
- #15868
bb2b8f5Thanks @ematipico! - Fixes an issue where the adapter would cause a series of warnings during the build.
- #15868
π Patch Changes
- Updated dependencies [
c2cd371]:- @astrojs/internal-helpers@0.7.6
- Updated dependencies [
β¨ Major Changes
-
#15654
a32aee6Thanks @florian-lefebvre! - Removes theexperimentalErrorPageHostoptionThis option allowed fetching a prerendered error page from a different host than the server is currently running on.
However, there can be security implications with prefetching from other hosts, and often more customization was required to do this safely. This has now been removed as a built-in option so that you can implement your own secure solution as needed and appropriate for your project via middleware.
What should I do?
If you were previously using this feature, you must remove the option from your adapter configuration as it no longer exists:
astro.config.mjs import { defineConfig } from 'astro/config'import node from '@astrojs/node'export default defineConfig({adapter: node({mode: 'standalone',experimentalErrorPageHost: 'http://localhost:4321'})})You can replicate the previous behavior by checking the response status in a middleware and fetching the prerendered page yourself:
src/middleware.ts import { defineMiddleware } from 'astro:middleware';export const onRequest = defineMiddleware(async (ctx, next) => {const response = await next();if (response.status === 404 || response.status === 500) {return fetch(`http://localhost:4321/${response.status}.html`);}return response;});
πΏ Minor Changes
-
#15258
d339a18Thanks @ematipico! - Stabilizes the adapter featureexperimentalStatiHeaders. If you were using this feature in any of the supported adapters, youβll need to change the name of the flag:export default defineConfig({adapter: netlify({experimentalStaticHeaders: truestaticHeaders: true})}) -
#15759
39ff2a5Thanks @matthewp! - Adds a newbodySizeLimitoption to the@astrojs/nodeadapterYou can now configure a maximum allowed request body size for your Node.js standalone server. The default limit is 1 GB. Set the value in bytes, or pass
0to disable the limit entirely:import node from '@astrojs/node';import { defineConfig } from 'astro/config';export default defineConfig({adapter: node({mode: 'standalone',bodySizeLimit: 1024 * 1024 * 100, // 100 MB}),}); -
#15006
f361730Thanks @florian-lefebvre! - Adds new session driver object shapeFor greater flexibility and improved consistency with other Astro code, session drivers are now specified as an object:
import { defineConfig } from 'astro/config'import { defineConfig, sessionDrivers } from 'astro/config'export default defineConfig({session: {driver: 'redis',options: {url: process.env.REDIS_URL},driver: sessionDrivers.redis({url: process.env.REDIS_URL}),}})Specifying the session driver as a string has been deprecated, but will continue to work until this feature is removed completely in a future major version. The object shape is the current recommended and documented way to configure a session driver.
-
#14946
95c40f7Thanks @ematipico! - Removes theexperimental.cspflag and replaces it with a new configuration optionsecurity.csp- (v6 upgrade guidance)
π Patch Changes
-
#15473
d653b86Thanks @matthewp! - Improves error page loading to read from disk first before falling back to configured host -
#15562
e14a51dThanks @florian-lefebvre! - Updates to new Adapter API introduced in v6 -
#15585
98ea30cThanks @matthewp! - Add a default body size limit for server actions to prevent oversized requests from exhausting memory. -
#15777
02e24d9Thanks @matthewp! - Fixes CSRF origin check mismatch by passing the actual server listening port tocreateRequest, ensuring the constructed URL origin includes the correct port (e.g.,http://localhost:4321instead ofhttp://localhost). Also restrictsX-Forwarded-Prototo only be trusted whenallowedDomainsis configured. -
#15714
9a2c949Thanks @ematipico! - Fixes an issue where static headers werenβt correctly applied when the website usesbase. -
#15763
1567e8cThanks @matthewp! - Normalizes static file paths before evaluating dotfile access rules for improved consistency -
#15164
54dc11dThanks @HiDeoo! - Fixes an issue where the Node.js adapter could fail to serve a 404 page matching a pre-rendered dynamic route pattern. -
#15745
20b05c0Thanks @matthewp! - Hardens static file handler path resolution to ensure resolved paths stay within the client directory -
#15495
5b99e90Thanks @leekeh! - Refactors to usemiddlewareModeadapter feature (set toclassic) -
#15657
cb625b6Thanks @qzio! - Adds a newsecurity.actionBodySizeLimitoption to configure the maximum size of Astro Actions request bodies.This lets you increase the default 1 MB limit when your actions need to accept larger payloads. For example, actions that handle file uploads or large JSON payloads can now opt in to a higher limit.
If you do not set this option, Astro continues to enforce the 1 MB default to help prevent abuse.
astro.config.mjs export default defineConfig({security: {actionBodySizeLimit: 10 * 1024 * 1024, // set to 10 MB},}); -
Updated dependencies [
4ebc1e3,4e7f3e8,a164c77,cf6ea6b,a18d727,240c317,745e632]:- @astrojs/internal-helpers@0.8.0
-
πΏ Minor Changes
-
#15759
39ff2a5Thanks @matthewp! - Adds a newbodySizeLimitoption to the@astrojs/nodeadapterYou can now configure a maximum allowed request body size for your Node.js standalone server. The default limit is 1 GB. Set the value in bytes, or pass
0to disable the limit entirely:import node from '@astrojs/node';import { defineConfig } from 'astro/config';export default defineConfig({adapter: node({mode: 'standalone',bodySizeLimit: 1024 * 1024 * 100, // 100 MB}),});
π Patch Changes
-
#15777
02e24d9Thanks @matthewp! - Fixes CSRF origin check mismatch by passing the actual server listening port tocreateRequest, ensuring the constructed URL origin includes the correct port (e.g.,http://localhost:4321instead ofhttp://localhost). Also restrictsX-Forwarded-Prototo only be trusted whenallowedDomainsis configured. -
#15763
1567e8cThanks @matthewp! - Normalizes static file paths before evaluating dotfile access rules for improved consistency -
Updated dependencies [
4ebc1e3,4e7f3e8]:- @astrojs/internal-helpers@0.8.0-beta.3
-
π Patch Changes
- Updated dependencies [
745e632]:- @astrojs/internal-helpers@0.8.0-beta.2
- Updated dependencies [
β¨ Major Changes
-
#15654
a32aee6Thanks @florian-lefebvre! - Removes theexperimentalErrorPageHostoptionThis option allowed fetching a prerendered error page from a different host than the server is currently running on.
However, there can be security implications with prefetching from other hosts, and often more customization was required to do this safely. This has now been removed as a built-in option so that you can implement your own secure solution as needed and appropriate for your project via middleware.
What should I do?
If you were previously using this feature, you must remove the option from your adapter configuration as it no longer exists:
astro.config.mjs import { defineConfig } from 'astro/config'import node from '@astrojs/node'export default defineConfig({adapter: node({mode: 'standalone',experimentalErrorPageHost: 'http://localhost:4321'})})You can replicate the previous behavior by checking the response status in a middleware and fetching the prerendered page yourself:
src/middleware.ts import { defineMiddleware } from 'astro:middleware';export const onRequest = defineMiddleware(async (ctx, next) => {const response = await next();if (response.status === 404 || response.status === 500) {return fetch(`http://localhost:4321/${response.status}.html`);}return response;});
π Patch Changes
-
π Patch Changes
-
#15495
5b99e90Thanks @leekeh! - Refactors to usemiddlewareModeadapter feature (set toclassic) -
#15657
cb625b6Thanks @qzio! - Adds a newsecurity.actionBodySizeLimitoption to configure the maximum size of Astro Actions request bodies.This lets you increase the default 1 MB limit when your actions need to accept larger payloads. For example, actions that handle file uploads or large JSON payloads can now opt in to a higher limit.
If you do not set this option, Astro continues to enforce the 1 MB default to help prevent abuse.
astro.config.mjs export default defineConfig({security: {actionBodySizeLimit: 10 * 1024 * 1024, // set to 10 MB},});
-
π Patch Changes
-
#15564
522f880Thanks @matthewp! - Add a default body size limit for server actions to prevent oversized requests from exhausting memory. -
#15572
ef851bfThanks @matthewp! - Upgrade astro package supportastro@5.17.3 includes a fix to prevent Action payloads from exhausting memory. @astrojs/node now depends on this version of Astro as a minimum requirement.
-
πΏ Minor Changes
-
#15258
d339a18Thanks @ematipico! - Stabilizes the adapter featureexperimentalStatiHeaders. If you were using this feature in any of the supported adapters, youβll need to change the name of the flag:export default defineConfig({adapter: netlify({experimentalStaticHeaders: truestaticHeaders: true})})
-
π Patch Changes
- Updated dependencies [
240c317]:- @astrojs/internal-helpers@0.8.0-beta.0
- Updated dependencies [