Built-in Protection
Rule Engine JS has security features enabled by default:Prototype Protection
Blocks proto and constructor access
Function Blocking
Functions cannot be accessed via paths
Depth Limits
Prevents infinite recursion attacks
Type Validation
Validates operator arguments
Prototype Pollution
What It Is
Malicious path access that modifies object prototypes.How We Block It
Configuration
Input Validation
Always validate user input before using in rules.Bad vs Good
- ❌ Bad - No Validation
- ✅ Good - Validated
Whitelist Operators
Only allow specific operators in user-defined rules.Whitelist Paths
Restrict which data paths can be accessed.Rate Limiting
Prevent DoS via excessive evaluations.Depth Limits
Prevent deeply nested rules (DoS).Sensitive Data
Don’t expose sensitive data in error messages.- ❌ Bad
- ✅ Good
Regex Safety
Prevent ReDoS (Regular Expression Denial of Service).Complete Security Checklist
1. Prototype Protection
1. Prototype Protection
2. Input Validation
2. Input Validation
3. Depth Limits
3. Depth Limits
4. Rate Limiting
4. Rate Limiting
5. Error Handling
5. Error Handling
6. Regex Validation
6. Regex Validation
Secure Configuration
Related
RuleEngine API
Configuration options
Performance
Performance best practices
