What middleapi/orpc shipped
Written by FoxPlug from public releases; not affiliated with Orpc. An automatic summary of the public release, pull request and commit data of github.com/middleapi/orpc. Orpc did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- Redis Pub/Sub now delivers events in stream order when resume is enabled, fixing cases where concurrent publishers could skip or duplicate events. Pull request #2073
- Batched procedures and subscriptions now stop when the client disconnects instead of running to completion. Pull request #2092
- BatchLinkPlugin and DedupeLinkPlugin gain a wait option to collect requests for milliseconds before sending, reducing request count. Pull request #2090
- Procedures served through toORPCRouter now receive only schema-declared fields, closing a mass-assignment risk. Pull request #2106
- RetryLinkPlugin no longer loops forever when retryDelay throws or rejects. Pull request #2105
- Publisher resume with lastEventId no longer silently drops the oldest missed events when backlog exceeds maxBufferedEvents. Pull request #2104
- Nest Express adapter now cancels streamed response bodies when the client disconnects, preventing subscription leaks. Pull request #2101
- PrototypePollutionProtectionHandlerPlugin now protects against __proto__ keys on arrays in MessagePort messages. Pull request #2107
- CloudflareTracer now renames request spans to procedure paths and records exceptions following OpenTelemetry semantics. Pull request #2095
- Routers implemented with .lazy() now follow the contract's error map and meta. Pull request #2070
Why it matters
This week addresses critical reliability issues in streaming, batching, and event delivery, plus mass-assignment and security gaps. Connection lifecycle handling across multiple transports is now correct, and procedures respect schema boundaries properly. These fixes prevent data loss, resource leaks, and vulnerability exposure.
Changelog entry
- fix(publisher, bun)!: keep Redis Pub/Sub delivery in stream order Pull request #2073
- fix(server): abort batch sub-requests when the client disconnects Pull request #2092
- feat(client): add wait option to batch and dedupe link plugins Pull request #2090
- fix(trpc): stop toORPCRouter from passing input keys the schema strips Pull request #2106
- fix(client): stop retrying forever when retryDelay throws Pull request #2105
- fix(publisher): stop truncating the resume backlog to maxBufferedEvents Pull request #2104
- fix(nest): cancel streamed response bodies when the client disconnects Pull request #2101
- fix(server): stop MessagePort arrays from bypassing prototype pollution protection Pull request #2107
- feat(cloudflare): rename spans and follow OTel exception semantics in CloudflareTracer Pull request #2095
- fix(server): apply the contract to routers implemented with .lazy() Pull request #2070
- fix(client): send FormData uploads outside the batch Pull request #2102
- fix(json-schema): prevent unhandled rejections when converting async schemas Pull request #2103
- fix(server,contract,ai-sdk): stop loose stacked input schemas from reverting earlier transforms Pull request #2099
- fix(shared): close the source iterator when consumeAsyncIterator onEvent throws Pull request #2093
- fix(client): let the WebSocket link reconnect after giving up Pull request #2084
- fix(client): reject WebSocket link calls when connect returns a closed socket Pull request #2083
- fix(client): reject message port link calls after the port closes Pull request #2082
- fix(client): reject WebSocket link calls after the socket closes Pull request #2081
- fix(client): reject batched calls when a batch option throws Pull request #2079
This week: Redis events now stay in order, batches and subscriptions stop on disconnect, retry loops don't freeze, and procedures respect their schemas. 40 fixes across transport, validation, and streaming.
Orpc shipped 40 fixes this week focusing on reliability and correctness. Redis Pub/Sub now guarantees event ordering during resume, client disconnects properly cancel streamed responses and batched work, and procedures no longer receive undeclared fields. RetryLinkPlugin no longer hangs on errors, and batching gains a configurable wait option to optimize request grouping. These changes address streaming leaks, mass-assignment risks, and connection lifecycle issues across WebSocket, MessagePort, and HTTP transports.
Week of September 14, 2026
What shipped
- v2.0.0-beta.37 removes adapter interceptors and adapter plugins, removes built-in RegExp support from serializers and JSON Schema coercer, and fixes plugin registration order. Release
- RPC JSON serializer now checks wire types before restoring serialized values and compiles RegExp values lazily to prevent type confusion attacks from untrusted clients. Pull request #2048
- Server handler options now accept context as a function resolved after the prefix check, avoiding context setup costs on requests that don't match. Pull request #2029
- v2.0.0-beta.36 adds distributed locking helpers with multiple adapters, NestJS support for HTTP QUERY method, and Redis cluster support for rate limiting. Release
- Documentation now lists Cloudflare Workers Traces alongside OpenTelemetry as a first-party tracing option. Pull request #2051
- NestJS integration now supports HTTP QUERY method on NestJS v11.2+ through QueryMethod decorator. Pull request #2031
- Performance comparison page updated with benchmarks from oRPC 2.0.0-beta.37, tRPC 11.19.0, and Hono 4.13.8. Pull request #2050
- Zod integration now preserves JSON Schema constraints on zod >= 4.6 by reading checks from the definition directly. Pull request #2028
- Bracket notation serializer now prevents prototype pollution by reading and writing own properties only. Pull request #2024
- Lock package adds distributed locking helpers with multiple adapter implementations. Pull request #2016
Why it matters
Beta.37 hardens security with type checking during deserialization and removes deprecated adapter-level hooks, while beta.36 expanded platform support with distributed locks and NestJS QUERY method. These releases improve both safety and flexibility for developers building production systems.
Changelog entry
- Breaking: Remove adapter interceptors and adapter plugins Release
- Breaking: Remove built-in RegExp support from serializers and JSON Schema coercer Release
- Fix: Keep registration order when sorting plugins Release
- Fix: Check serialized value types and compile regexps lazily during RPC deserialization Release
- Upgrade: @standard-server/* to 0.9.2 Pull request #2049
- Docs: Warn that Fastify bodyLimit does not cover catch-all parser in oRPC Pull request #2046
- Docs: Add Redirect Response section to OpenAPI Input and Output Mapping page Pull request #2043
- Upgrade: @standard-server/* to 0.9.1 Pull request #2035
- Feature: Add distributed locking helpers with multiple adapters Release
- Feature: NestJS support for HTTP QUERY method Release
- Feature: Rate limiter accepts Redis cluster clients Release
- Fix: Keep request span open until streamed response body finishes Pull request #2032
- Feature: Handler options accept context as function resolved after prefix check Pull request #2029
- Fix: Reject form action calls with non-FormData input Release
- Fix: Keep JSON Schema constraints on zod >= 4.6 Release
- Fix: Prevent prototype pollution through object values in bracket notation Pull request #2024
v2.0.0-beta.37 and beta.36 shipped this week. Beta.37 removes adapter interceptors, hardens RPC deserialization against type confusion, and fixes plugin ordering. Beta.36 adds distributed locking, NestJS QUERY support, and Redis cluster adapters.
Two oRPC beta releases landed this week with significant improvements: v2.0.0-beta.37 removes deprecated adapter-level interceptors and plugins, hardens the RPC serializer to validate wire types before restoring built-in values, fixes plugin registration order, and lets handlers accept context functions resolved after prefix checks. v2.0.0-beta.36 introduces distributed locking helpers with multiple adapters, adds NestJS support for HTTP QUERY method on v11.2+, and extends rate limiting to accept Redis cluster clients. Documentation now clarifies that any Standard Schema library works with oRPC, not just the three highlighted packages.