{"_id":"@aahoughton/oav-express4","_rev":"19-6a15184a81166e632ba799c3d884269a","name":"@aahoughton/oav-express4","dist-tags":{"latest":"3.8.0"},"versions":{"1.0.0":{"name":"@aahoughton/oav-express4","version":"1.0.0","keywords":["express","express4","middleware","openapi","openapi-3.0","openapi-3.1","openapi-3.2","validation","validator"],"author":{"name":"Andrew Houghton","email":"aah@roarmouse.org"},"license":"MIT","_id":"@aahoughton/oav-express4@1.0.0","maintainers":[{"name":"aahoughton","email":"aah@roarmouse.org"}],"homepage":"https://github.com/aahoughton/oav#readme","bugs":{"url":"https://github.com/aahoughton/oav/issues"},"dist":{"shasum":"c9d65951a3782f9e3b8892eba7b057860c29f8e5","tarball":"https://registry.npmjs.org/@aahoughton/oav-express4/-/oav-express4-1.0.0.tgz","fileCount":9,"integrity":"sha512-AZY55hvmAxkLZdToWy/qQzEbqSo4IR9Z1HGPS8ZvpgrLJhzhwW2kW60I/AqWmRdEm14Av5lXaZamOZdXVQ8rdg==","signatures":[{"sig":"MEUCIGrpIJal0h06FSOMYPPdElyvvs3YgpdxTlYbpEpn5FI1AiEA7seQA1jtgrbdNognCuRlporLxt5lrKFd+irz0Eu9SSw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aahoughton%2foav-express4@1.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":92407},"main":"./dist/index.cjs","type":"module","_from":"file:aahoughton-oav-express4-1.0.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=22"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}},"./package.json":"./package.json"},"scripts":{"test":"vitest run","build":"tsup","typecheck":"tsc -b"},"_npmUser":{"name":"aahoughton","email":"aah@roarmouse.org"},"_resolved":"/tmp/efa2e8e34d73dc74ee36f2bf5f6ec2b4/aahoughton-oav-express4-1.0.0.tgz","_integrity":"sha512-AZY55hvmAxkLZdToWy/qQzEbqSo4IR9Z1HGPS8ZvpgrLJhzhwW2kW60I/AqWmRdEm14Av5lXaZamOZdXVQ8rdg==","repository":{"url":"git+https://github.com/aahoughton/oav.git","type":"git","directory":"packages/oav-express4"},"_npmVersion":"10.9.7","description":"Express 4 adapter for @aahoughton/oav-core. Ships a request-validator middleware factory plus standalone helpers (httpRequestFromExpress, renderProblemDetails) for callers that want to compose their own.","directories":{},"sideEffects":false,"_nodeVersion":"22.22.2","dependencies":{"@aahoughton/oav-core":"1.0.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"tsup":"8.5.1","vitest":"4.1.5","express":"4.21.2","@oav/core":"0.0.0","typescript":"5.9.3","@oav/validator":"0.0.0","@types/express":"4.17.21"},"peerDependencies":{"express":"^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/oav-express4_1.0.0_1777179369040_0.4448328484033861","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed to @oaverify/express4."},"1.1.0":{"name":"@aahoughton/oav-express4","version":"1.1.0","keywords":["express","express4","middleware","openapi","openapi-3.0","openapi-3.1","openapi-3.2","validation","validator"],"author":{"name":"Andrew Houghton","email":"aah@roarmouse.org"},"license":"MIT","_id":"@aahoughton/oav-express4@1.1.0","maintainers":[{"name":"aahoughton","email":"aah@roarmouse.org"}],"homepage":"https://github.com/aahoughton/oav#readme","bugs":{"url":"https://github.com/aahoughton/oav/issues"},"//":"No prepublishOnly: release.yml runs `pnpm test` from root before `pnpm -r publish`. Per-package publish (`cd packages/<x> && pnpm publish`) is not the supported path; it would skip the test gate.","dist":{"shasum":"f303f663a9c4c93657c4a14411ba4a8a84b8ebb8","tarball":"https://registry.npmjs.org/@aahoughton/oav-express4/-/oav-express4-1.1.0.tgz","fileCount":9,"integrity":"sha512-w7F62sNhrbIgY54eHVtr0LAOmD36wzFI4+GlH0uoTqGcmwkvla39WuAX5e0q+Gjxn3Ws9IsfmcLFtnlyFQLSqA==","signatures":[{"sig":"MEYCIQDIOGFbTrSbMcKbo7uiTk8QeY0IcMhHyHGue9QbkoPYbgIhANGZjwV8napYd1xrMDWzAghbtL8etjxZ/9uY1hFBnCsO","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aahoughton%2foav-express4@1.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":92682},"main":"./dist/index.cjs","type":"module","_from":"file:aahoughton-oav-express4-1.1.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=22"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}},"./package.json":"./package.json"},"scripts":{"test":"vitest run","build":"tsup","typecheck":"tsc -b"},"_npmUser":{"name":"aahoughton","email":"aah@roarmouse.org"},"_resolved":"/tmp/34004c9620c0c97bc5ddaa00bf511ee0/aahoughton-oav-express4-1.1.0.tgz","_integrity":"sha512-w7F62sNhrbIgY54eHVtr0LAOmD36wzFI4+GlH0uoTqGcmwkvla39WuAX5e0q+Gjxn3Ws9IsfmcLFtnlyFQLSqA==","repository":{"url":"git+https://github.com/aahoughton/oav.git","type":"git","directory":"packages/oav-express4"},"_npmVersion":"10.9.7","description":"Express 4 adapter for @aahoughton/oav-core. Ships a request-validator middleware factory plus standalone helpers (httpRequestFromExpress, renderProblemDetails) for callers that want to compose their own.","directories":{},"sideEffects":false,"_nodeVersion":"22.22.2","dependencies":{"@aahoughton/oav-core":"1.1.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"tsup":"8.5.1","vitest":"4.1.5","express":"4.22.1","@oav/core":"0.0.0","typescript":"5.9.3","@oav/validator":"0.0.0","@types/express":"4.17.21"},"peerDependencies":{"express":"^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/oav-express4_1.1.0_1777240338644_0.8073870471016322","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed to @oaverify/express4."},"1.1.1":{"name":"@aahoughton/oav-express4","version":"1.1.1","keywords":["express","express4","middleware","openapi","openapi-3.0","openapi-3.1","openapi-3.2","validation","validator"],"author":{"name":"Andrew Houghton","email":"aah@roarmouse.org"},"license":"MIT","_id":"@aahoughton/oav-express4@1.1.1","maintainers":[{"name":"aahoughton","email":"aah@roarmouse.org"}],"homepage":"https://github.com/aahoughton/oav#readme","bugs":{"url":"https://github.com/aahoughton/oav/issues"},"//":"No prepublishOnly: release.yml runs `pnpm test` from root before `pnpm -r publish`. Per-package publish (`cd packages/<x> && pnpm publish`) is not the supported path; it would skip the test gate.","dist":{"shasum":"775f182f8ac40e18ca1f2be3caeffd4ebbd852ec","tarball":"https://registry.npmjs.org/@aahoughton/oav-express4/-/oav-express4-1.1.1.tgz","fileCount":9,"integrity":"sha512-wvJ8gtwex92yXd/Kz+JzmKexRT/kvUnlLnYIpFnNhy/gNla0Wib4q88Jl+j0MXS4F+8/2xo0Hwf5r1TDBU8p+w==","signatures":[{"sig":"MEQCIDiBnuuXZhyNQlr1fUgVIlXPJGSQ9vBUiwhsjyeiPsjWAiApmDBE4v5poIpIhsaWvHhHvjEg6fuwPRBJHygn3DDO8Q==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aahoughton%2foav-express4@1.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":92975},"main":"./dist/index.cjs","type":"module","_from":"file:aahoughton-oav-express4-1.1.1.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=22"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}},"./package.json":"./package.json"},"scripts":{"test":"vitest run","build":"tsup","typecheck":"tsc -b"},"_npmUser":{"name":"aahoughton","email":"aah@roarmouse.org"},"_resolved":"/tmp/c4825e8dfca7a4de4bd4c8129acced87/aahoughton-oav-express4-1.1.1.tgz","_integrity":"sha512-wvJ8gtwex92yXd/Kz+JzmKexRT/kvUnlLnYIpFnNhy/gNla0Wib4q88Jl+j0MXS4F+8/2xo0Hwf5r1TDBU8p+w==","repository":{"url":"git+https://github.com/aahoughton/oav.git","type":"git","directory":"packages/oav-express4"},"_npmVersion":"10.9.7","description":"Express 4 adapter for @aahoughton/oav-core. Ships a request-validator middleware factory plus standalone helpers (httpRequestFromExpress, renderProblemDetails) for callers that want to compose their own.","directories":{},"sideEffects":false,"_nodeVersion":"22.22.2","dependencies":{"@aahoughton/oav-core":"1.1.2"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"tsup":"8.5.1","vitest":"4.1.5","express":"4.22.1","@oav/core":"0.0.0","typescript":"5.9.3","@oav/validator":"0.0.0","@types/express":"4.17.21"},"peerDependencies":{"express":"^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/oav-express4_1.1.1_1777265599060_0.4386435255191772","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed to @oaverify/express4."},"2.0.0":{"name":"@aahoughton/oav-express4","version":"2.0.0","keywords":["express","express4","middleware","openapi","openapi-3.0","openapi-3.1","openapi-3.2","validation","validator"],"author":{"name":"Andrew Houghton","email":"aah@roarmouse.org"},"license":"MIT","_id":"@aahoughton/oav-express4@2.0.0","maintainers":[{"name":"aahoughton","email":"aah@roarmouse.org"}],"homepage":"https://github.com/aahoughton/oav#readme","bugs":{"url":"https://github.com/aahoughton/oav/issues"},"//":"No prepublishOnly: release.yml runs `pnpm test` from root before `pnpm -r publish`. Per-package publish (`cd packages/<x> && pnpm publish`) is not the supported path; it would skip the test gate.","dist":{"shasum":"39f9799fa394213399187244990701b87a4e8364","tarball":"https://registry.npmjs.org/@aahoughton/oav-express4/-/oav-express4-2.0.0.tgz","fileCount":9,"integrity":"sha512-K6oWMATd7aqgN0QqxfDxmwCN9UETp2kG3dHV9bYbU8lmPu7X0MYJcCwxi5wtuHbxtGY49KghaB2Zt6AoQI+2zg==","signatures":[{"sig":"MEUCIQDQl8LbxQEzKdvijgsl4ea/yXuIdncJfgE/SbokZRfVCgIgRtdCELjGLaTKe4lH5+ndYJ/hNDZBGC6Ijwux7cLbeyY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aahoughton%2foav-express4@2.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":98794},"main":"./dist/index.cjs","type":"module","_from":"file:aahoughton-oav-express4-2.0.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=22"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}},"./package.json":"./package.json"},"scripts":{"test":"vitest run","build":"tsup","typecheck":"tsc -b"},"_npmUser":{"name":"aahoughton","email":"aah@roarmouse.org"},"_resolved":"/tmp/e3d2cbc2b717b113077e09be2ef14c36/aahoughton-oav-express4-2.0.0.tgz","_integrity":"sha512-K6oWMATd7aqgN0QqxfDxmwCN9UETp2kG3dHV9bYbU8lmPu7X0MYJcCwxi5wtuHbxtGY49KghaB2Zt6AoQI+2zg==","repository":{"url":"git+https://github.com/aahoughton/oav.git","type":"git","directory":"packages/oav-express4"},"_npmVersion":"10.9.7","description":"Express 4 adapter for @aahoughton/oav-core. Ships a request-validator middleware factory plus standalone helpers (httpRequestFromExpress, renderProblemDetails) for callers that want to compose their own.","directories":{},"sideEffects":false,"_nodeVersion":"22.22.2","dependencies":{"@aahoughton/oav-core":"2.0.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"tsup":"8.5.1","vitest":"4.1.5","express":"4.22.1","@oav/core":"0.0.0","typescript":"5.9.3","@oav/validator":"0.0.0","@types/express":"4.17.21"},"peerDependencies":{"express":"^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/oav-express4_2.0.0_1777746020912_0.07067551295653152","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed to @oaverify/express4."},"2.1.0":{"name":"@aahoughton/oav-express4","version":"2.1.0","keywords":["express","express4","middleware","openapi","openapi-3.0","openapi-3.1","openapi-3.2","validation","validator"],"author":{"name":"Andrew Houghton","email":"aah@roarmouse.org"},"license":"MIT","_id":"@aahoughton/oav-express4@2.1.0","maintainers":[{"name":"aahoughton","email":"aah@roarmouse.org"}],"homepage":"https://github.com/aahoughton/oav#readme","bugs":{"url":"https://github.com/aahoughton/oav/issues"},"//":"No prepublishOnly: release.yml runs `pnpm test` from root before `pnpm -r publish`. Per-package publish (`cd packages/<x> && pnpm publish`) is not the supported path; it would skip the test gate.","dist":{"shasum":"e6927173c9a5872e91fef922a15d892697e56e08","tarball":"https://registry.npmjs.org/@aahoughton/oav-express4/-/oav-express4-2.1.0.tgz","fileCount":9,"integrity":"sha512-sEwc/vxLDA8uHacrViYGbKc0pjuttTs0cDqQGERuo50Ryb/QaGT+BLaqmPo9EvEVAM10ruX42yipxSmoodW/jw==","signatures":[{"sig":"MEUCIQCViWwo0Bks55xrr//kcCJMG6aasOLPc1/ybwVtk/ydlwIgC77tuW2COA/RWkUQroQ98fBT39+aRLlJO6kmwlv3UHc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aahoughton%2foav-express4@2.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":104923},"main":"./dist/index.cjs","type":"module","_from":"file:aahoughton-oav-express4-2.1.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=22"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}},"./package.json":"./package.json"},"scripts":{"test":"vitest run","build":"tsup","typecheck":"tsc -b"},"_npmUser":{"name":"aahoughton","email":"aah@roarmouse.org"},"_resolved":"/tmp/bcbb7a709206ac6b263cfb80c1c50ecc/aahoughton-oav-express4-2.1.0.tgz","_integrity":"sha512-sEwc/vxLDA8uHacrViYGbKc0pjuttTs0cDqQGERuo50Ryb/QaGT+BLaqmPo9EvEVAM10ruX42yipxSmoodW/jw==","repository":{"url":"git+https://github.com/aahoughton/oav.git","type":"git","directory":"packages/oav-express4"},"_npmVersion":"10.9.7","description":"Express 4 adapter for @aahoughton/oav-core. Ships a request-validator middleware factory plus standalone helpers (httpRequestFromExpress, renderProblemDetails) for callers that want to compose their own.","directories":{},"sideEffects":false,"_nodeVersion":"22.22.2","dependencies":{"@aahoughton/oav-core":"2.1.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"tsup":"8.5.1","vitest":"4.1.5","express":"4.22.1","@oav/core":"0.0.0","typescript":"5.9.3","@oav/validator":"0.0.0","@types/express":"4.17.21"},"peerDependencies":{"express":"^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/oav-express4_2.1.0_1777873101333_0.3031993241175488","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed to @oaverify/express4."},"2.2.0":{"name":"@aahoughton/oav-express4","version":"2.2.0","keywords":["express","express4","middleware","openapi","openapi-3.0","openapi-3.1","openapi-3.2","validation","validator"],"author":{"name":"Andrew Houghton","email":"aah@roarmouse.org"},"license":"MIT","_id":"@aahoughton/oav-express4@2.2.0","maintainers":[{"name":"aahoughton","email":"aah@roarmouse.org"}],"homepage":"https://github.com/aahoughton/oav#readme","bugs":{"url":"https://github.com/aahoughton/oav/issues"},"//":"No prepublishOnly: release.yml runs `pnpm test` from root before `pnpm -r publish`. Per-package publish (`cd packages/<x> && pnpm publish`) is not the supported path; it would skip the test gate.","dist":{"shasum":"6f333dd18f219495ccd8d2b4c6f094b19dc3794b","tarball":"https://registry.npmjs.org/@aahoughton/oav-express4/-/oav-express4-2.2.0.tgz","fileCount":9,"integrity":"sha512-vBXlY51U2aRq1AgKyTB9Jdr2cwkJmv4E2KXqEmquQsD3wmw2g3IpO2xk9Q6nV9viet/+ECoCdClbWlU4DxSoQw==","signatures":[{"sig":"MEUCIQDUBsyekfxZNSsDoh35LViv6vGcrSGCYAuoqDxx4IrbmgIgBh51oCi6gD06n9mwdSmco2/zV94w/m8E23JhBhRPxIk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aahoughton%2foav-express4@2.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":106761},"main":"./dist/index.cjs","type":"module","_from":"file:aahoughton-oav-express4-2.2.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=22"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}},"./package.json":"./package.json"},"scripts":{"test":"vitest run","build":"tsup","typecheck":"tsc -b"},"_npmUser":{"name":"aahoughton","email":"aah@roarmouse.org"},"_resolved":"/tmp/2f4062003b25393fed7d937ac6dce528/aahoughton-oav-express4-2.2.0.tgz","_integrity":"sha512-vBXlY51U2aRq1AgKyTB9Jdr2cwkJmv4E2KXqEmquQsD3wmw2g3IpO2xk9Q6nV9viet/+ECoCdClbWlU4DxSoQw==","repository":{"url":"git+https://github.com/aahoughton/oav.git","type":"git","directory":"packages/oav-express4"},"_npmVersion":"10.9.7","description":"Express 4 adapter for @aahoughton/oav-core. Ships a request-validator middleware factory plus standalone helpers (httpRequestFromExpress, renderProblemDetails) for callers that want to compose their own.","directories":{},"sideEffects":false,"_nodeVersion":"22.22.2","dependencies":{"@aahoughton/oav-core":"2.2.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"tsup":"8.5.1","vitest":"4.1.6","express":"4.22.2","@oav/core":"0.0.0","typescript":"5.9.3","@oav/validator":"0.0.0","@types/express":"4.17.21"},"peerDependencies":{"express":"^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/oav-express4_2.2.0_1779217715568_0.8131191600190943","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed to @oaverify/express4."},"2.2.1":{"name":"@aahoughton/oav-express4","version":"2.2.1","keywords":["express","express4","middleware","openapi","openapi-3.0","openapi-3.1","openapi-3.2","validation","validator"],"author":{"name":"Andrew Houghton","email":"aah@roarmouse.org"},"license":"MIT","_id":"@aahoughton/oav-express4@2.2.1","maintainers":[{"name":"aahoughton","email":"aah@roarmouse.org"}],"homepage":"https://github.com/aahoughton/oav#readme","bugs":{"url":"https://github.com/aahoughton/oav/issues"},"//":"No prepublishOnly: release.yml runs `pnpm test` from root before `pnpm -r publish`. Per-package publish (`cd packages/<x> && pnpm publish`) is not the supported path; it would skip the test gate.","dist":{"shasum":"e0bfb1a7d915017a4593827497d2694b113281f1","tarball":"https://registry.npmjs.org/@aahoughton/oav-express4/-/oav-express4-2.2.1.tgz","fileCount":9,"integrity":"sha512-P6JWWIYKvx5jD+XaXn+t4RKYHraEDFxcdzCf3iOT5FqzzE2eUlT4AFDZZSFYx0dFH6AEP2o/zplCJz6unAtzRw==","signatures":[{"sig":"MEUCIFGtKGppD+rQh4cl+vPuM7M76E08HCRwpx/x32aPib9hAiEA+EwBVknqGYuhhT0Xujw/TeL7EJ3/kroh46+tHvToeTs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aahoughton%2foav-express4@2.2.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":106736},"main":"./dist/index.cjs","type":"module","_from":"file:pkgs/aahoughton-oav-express4-2.2.1.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=22"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}},"./package.json":"./package.json"},"scripts":{"test":"vitest run","build":"tsup","typecheck":"tsc -b"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:bac0b0d1-f1d3-465a-ae7f-b7e2741f8dbb"}},"_resolved":"/home/runner/work/oav/oav/pkgs/aahoughton-oav-express4-2.2.1.tgz","_integrity":"sha512-P6JWWIYKvx5jD+XaXn+t4RKYHraEDFxcdzCf3iOT5FqzzE2eUlT4AFDZZSFYx0dFH6AEP2o/zplCJz6unAtzRw==","repository":{"url":"git+https://github.com/aahoughton/oav.git","type":"git","directory":"packages/oav-express4"},"_npmVersion":"11.13.0","description":"Express 4 adapter for @aahoughton/oav-core. Ships a request-validator middleware factory plus standalone helpers (httpRequestFromExpress, renderProblemDetails) for callers that want to compose their own.","directories":{},"sideEffects":false,"_nodeVersion":"24.16.0","dependencies":{"@aahoughton/oav-core":"2.2.1"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"tsup":"8.5.1","vitest":"4.1.8","@oav/core":"0.0.0","typescript":"5.9.3","@oav/validator":"0.0.0","@types/express":"4.17.21"},"peerDependencies":{"express":"^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/oav-express4_2.2.1_1780700001715_0.41796400383489973","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed to @oaverify/express4."},"2.3.0":{"name":"@aahoughton/oav-express4","version":"2.3.0","keywords":["express","express4","middleware","openapi","openapi-3.0","openapi-3.1","openapi-3.2","validation","validator"],"author":{"name":"Andrew Houghton","email":"aah@roarmouse.org"},"license":"MIT","_id":"@aahoughton/oav-express4@2.3.0","maintainers":[{"name":"aahoughton","email":"aah@roarmouse.org"}],"homepage":"https://github.com/aahoughton/oav#readme","bugs":{"url":"https://github.com/aahoughton/oav/issues"},"//":"No prepublishOnly: release.yml runs `pnpm test` from root before `pnpm -r publish`. Per-package publish (`cd packages/<x> && pnpm publish`) is not the supported path; it would skip the test gate.","dist":{"shasum":"0e2e8859e0a06de3a6ac4083ff96826550d9a4b8","tarball":"https://registry.npmjs.org/@aahoughton/oav-express4/-/oav-express4-2.3.0.tgz","fileCount":9,"integrity":"sha512-UDRVFv2NLFg0XDN+C2lWAU3upLvIfeTq3EuLnkef1s0OHVVId2R8XaVtamoOvZsxl3xBSKPY/C63SQWWlVAQHA==","signatures":[{"sig":"MEUCIQCj1g0gPWBf0Kp09laudq3nPfO//cE1QqWzCxO67ogbwAIgXF4Qk9o4/HFZieJSOqNSUx0orHf4aSW8w4odJnBW7pI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aahoughton%2foav-express4@2.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":106563},"main":"./dist/index.cjs","type":"module","_from":"file:pkgs/aahoughton-oav-express4-2.3.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=22"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}},"./package.json":"./package.json"},"scripts":{"test":"vitest run","build":"tsup","typecheck":"tsc -b"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:bac0b0d1-f1d3-465a-ae7f-b7e2741f8dbb"}},"_resolved":"/home/runner/work/oav/oav/pkgs/aahoughton-oav-express4-2.3.0.tgz","_integrity":"sha512-UDRVFv2NLFg0XDN+C2lWAU3upLvIfeTq3EuLnkef1s0OHVVId2R8XaVtamoOvZsxl3xBSKPY/C63SQWWlVAQHA==","repository":{"url":"git+https://github.com/aahoughton/oav.git","type":"git","directory":"packages/oav-express4"},"_npmVersion":"11.13.0","description":"Express 4 adapter for @aahoughton/oav-core. Ships a request-validator middleware factory plus standalone helpers (httpRequestFromExpress, renderProblemDetails) for callers that want to compose their own.","directories":{},"sideEffects":false,"_nodeVersion":"24.16.0","dependencies":{"@aahoughton/oav-core":"2.3.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"peerDependencies":{"express":"^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/oav-express4_2.3.0_1780762503312_0.12442691166142628","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed to @oaverify/express4."},"2.4.0":{"name":"@aahoughton/oav-express4","version":"2.4.0","keywords":["express","express4","middleware","openapi","openapi-3.0","openapi-3.1","openapi-3.2","validation","validator"],"author":{"name":"Andrew Houghton","email":"aah@roarmouse.org"},"license":"MIT","_id":"@aahoughton/oav-express4@2.4.0","maintainers":[{"name":"aahoughton","email":"aah@roarmouse.org"}],"homepage":"https://github.com/aahoughton/oav#readme","bugs":{"url":"https://github.com/aahoughton/oav/issues"},"//":"No prepublishOnly: release.yml runs `pnpm test` from root before `pnpm -r publish`. Per-package publish (`cd packages/<x> && pnpm publish`) is not the supported path; it would skip the test gate.","dist":{"shasum":"b120cdb805c84ee4fe789bb0b073cf224b7d1dbb","tarball":"https://registry.npmjs.org/@aahoughton/oav-express4/-/oav-express4-2.4.0.tgz","fileCount":9,"integrity":"sha512-2KF974UDgPD3c+fylquMxKSDHCrCWWLVAmbnvNbwbnGwwmbvnPaIdHh6p+V/8UFcf3R1UGXfsr4KlcEoeUjUzg==","signatures":[{"sig":"MEUCIALoHzcYPqQOXKi87HSRKWnfKvuMgl5Y32w4Exv3y1qdAiEAn9IJ8yRK+9FV6kfSmPB6NbwQEQx+ky3jz+gDCztfQ8w=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aahoughton%2foav-express4@2.4.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":108165},"main":"./dist/index.cjs","type":"module","_from":"file:pkgs/aahoughton-oav-express4-2.4.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=22"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}},"./package.json":"./package.json"},"scripts":{"test":"vitest run","build":"tsup","typecheck":"tsc -b"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:bac0b0d1-f1d3-465a-ae7f-b7e2741f8dbb"}},"_resolved":"/home/runner/work/oav/oav/pkgs/aahoughton-oav-express4-2.4.0.tgz","_integrity":"sha512-2KF974UDgPD3c+fylquMxKSDHCrCWWLVAmbnvNbwbnGwwmbvnPaIdHh6p+V/8UFcf3R1UGXfsr4KlcEoeUjUzg==","repository":{"url":"git+https://github.com/aahoughton/oav.git","type":"git","directory":"packages/oav-express4"},"_npmVersion":"11.13.0","description":"Express 4 adapter for @aahoughton/oav-core. Ships a request-validator middleware factory plus standalone helpers (httpRequestFromExpress, renderProblemDetails) for callers that want to compose their own.","directories":{},"sideEffects":false,"_nodeVersion":"24.16.0","dependencies":{"@aahoughton/oav-core":"2.4.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"peerDependencies":{"express":"^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/oav-express4_2.4.0_1780776945029_0.7022627856795871","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed to @oaverify/express4."},"3.0.0":{"name":"@aahoughton/oav-express4","version":"3.0.0","keywords":["express","express4","middleware","openapi","openapi-3.0","openapi-3.1","openapi-3.2","validation","validator"],"author":{"name":"Andrew Houghton","email":"aah@roarmouse.org"},"license":"MIT","_id":"@aahoughton/oav-express4@3.0.0","maintainers":[{"name":"aahoughton","email":"aah@roarmouse.org"}],"homepage":"https://github.com/aahoughton/oav#readme","bugs":{"url":"https://github.com/aahoughton/oav/issues"},"//":"No prepublishOnly: release.yml runs `pnpm test` from root before `pnpm -r publish`. Per-package publish (`cd packages/<x> && pnpm publish`) is not the supported path; it would skip the test gate.","dist":{"shasum":"dce28a174f866014bc3605faff13c6f6354cb285","tarball":"https://registry.npmjs.org/@aahoughton/oav-express4/-/oav-express4-3.0.0.tgz","fileCount":9,"integrity":"sha512-lW5uTfMjHQXIXScZyW2+c/ojOX+Zj7gU4C6nDUTDPYboTOJ7aJNlGRx24wCNbKn0Oe1F8nfyNWlvji9z+LkBbw==","signatures":[{"sig":"MEUCIQDR7bY9gRDLKRbm/vR41y08nPMKv9LU+G8JeGCV5lwElgIgUPCbZeIavwEyUaUCQSEKYz/Y1hKOkD+uMiYg/zS2WT4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aahoughton%2foav-express4@3.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":120239},"main":"./dist/index.cjs","type":"module","_from":"file:pkgs/aahoughton-oav-express4-3.0.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=22"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}},"./package.json":"./package.json"},"scripts":{"test":"vitest run","build":"tsup","typecheck":"tsc -b"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:bac0b0d1-f1d3-465a-ae7f-b7e2741f8dbb"}},"_resolved":"/home/runner/work/oav/oav/pkgs/aahoughton-oav-express4-3.0.0.tgz","_integrity":"sha512-lW5uTfMjHQXIXScZyW2+c/ojOX+Zj7gU4C6nDUTDPYboTOJ7aJNlGRx24wCNbKn0Oe1F8nfyNWlvji9z+LkBbw==","repository":{"url":"git+https://github.com/aahoughton/oav.git","type":"git","directory":"packages/oav-express4"},"_npmVersion":"11.13.0","description":"Express 4 adapter for @aahoughton/oav-core. Ships a request-validator middleware factory plus standalone helpers (httpRequestFromExpress, renderProblemDetails) for callers that want to compose their own.","directories":{},"sideEffects":false,"_nodeVersion":"24.16.0","dependencies":{"@aahoughton/oav-core":"3.0.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"peerDependencies":{"express":"^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/oav-express4_3.0.0_1780892131210_0.2527963417226615","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed to @oaverify/express4."},"3.1.0":{"name":"@aahoughton/oav-express4","version":"3.1.0","keywords":["express","express4","middleware","openapi","openapi-3.0","openapi-3.1","openapi-3.2","validation","validator"],"author":{"name":"Andrew Houghton","email":"aah@roarmouse.org"},"license":"MIT","_id":"@aahoughton/oav-express4@3.1.0","maintainers":[{"name":"aahoughton","email":"aah@roarmouse.org"}],"homepage":"https://github.com/aahoughton/oav#readme","bugs":{"url":"https://github.com/aahoughton/oav/issues"},"//":"No prepublishOnly: release.yml runs `pnpm test` from root before `pnpm -r publish`. Per-package publish (`cd packages/<x> && pnpm publish`) is not the supported path; it would skip the test gate.","dist":{"shasum":"152b61d1dacd999884272ba8dabc41ec47fcfba3","tarball":"https://registry.npmjs.org/@aahoughton/oav-express4/-/oav-express4-3.1.0.tgz","fileCount":9,"integrity":"sha512-ziuvc4ZLHIyUI/r+46st6ui7+uqTsfcy/j6N7i8khqqNI4piJjRdudMa3ZGkyiDiRVjdPy9OIQUwEbGvvQT4Xw==","signatures":[{"sig":"MEYCIQCL7gYO2Kusx8Mszp+Kt0MvBNCDvcomGnLxYB31Fxmd4QIhAN6+Er8fApGhON//Sw951qGIXZIvAy7J3ItYpJwW3P1q","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aahoughton%2foav-express4@3.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":120566},"main":"./dist/index.cjs","type":"module","_from":"file:pkgs/aahoughton-oav-express4-3.1.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=22"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}},"./package.json":"./package.json"},"scripts":{"test":"vitest run","build":"tsup","typecheck":"tsc -b"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:bac0b0d1-f1d3-465a-ae7f-b7e2741f8dbb"}},"_resolved":"/home/runner/work/oav/oav/pkgs/aahoughton-oav-express4-3.1.0.tgz","_integrity":"sha512-ziuvc4ZLHIyUI/r+46st6ui7+uqTsfcy/j6N7i8khqqNI4piJjRdudMa3ZGkyiDiRVjdPy9OIQUwEbGvvQT4Xw==","repository":{"url":"git+https://github.com/aahoughton/oav.git","type":"git","directory":"packages/oav-express4"},"_npmVersion":"11.13.0","description":"Express 4 adapter for @aahoughton/oav-core. Ships a request-validator middleware factory plus standalone helpers (httpRequestFromExpress, renderProblemDetails) for callers that want to compose their own.","directories":{},"sideEffects":false,"_nodeVersion":"24.16.0","dependencies":{"@aahoughton/oav-core":"3.1.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"peerDependencies":{"express":"^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/oav-express4_3.1.0_1781036857795_0.1114718614908119","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed to @oaverify/express4."},"3.2.0":{"name":"@aahoughton/oav-express4","version":"3.2.0","keywords":["express","express4","middleware","openapi","openapi-3.0","openapi-3.1","openapi-3.2","validation","validator"],"author":{"name":"Andrew Houghton","email":"aah@roarmouse.org"},"license":"MIT","_id":"@aahoughton/oav-express4@3.2.0","maintainers":[{"name":"aahoughton","email":"aah@roarmouse.org"}],"homepage":"https://github.com/aahoughton/oav#readme","bugs":{"url":"https://github.com/aahoughton/oav/issues"},"//":"No prepublishOnly: release.yml runs `pnpm test` from root before `pnpm -r publish`. Per-package publish (`cd packages/<x> && pnpm publish`) is not the supported path; it would skip the test gate.","dist":{"shasum":"1624a5d6c916de5e3451678504e3a7e7f0f6043d","tarball":"https://registry.npmjs.org/@aahoughton/oav-express4/-/oav-express4-3.2.0.tgz","fileCount":9,"integrity":"sha512-Gy9nyKX5hVLcakWFjLvwJfnzOus+qdplaqUPWf+0cgNmmxgfkcRaSFhySs6dKfIbfelKlSBa0AC9goxXnmFnYg==","signatures":[{"sig":"MEUCIB8EHDm38VuzD43d0R4OxugpEI83aTZJe1H6qpGE5CIAAiEAq1D/Y7jz73NWq0XCwEiLt/He13l+A23Qt/QUR4Huabg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aahoughton%2foav-express4@3.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":172903},"main":"./dist/index.cjs","type":"module","_from":"file:pkgs/aahoughton-oav-express4-3.2.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=22"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}},"./package.json":"./package.json"},"scripts":{"test":"vitest run","build":"tsup","typecheck":"tsc -b"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:bac0b0d1-f1d3-465a-ae7f-b7e2741f8dbb"}},"_resolved":"/home/runner/work/oav/oav/pkgs/aahoughton-oav-express4-3.2.0.tgz","_integrity":"sha512-Gy9nyKX5hVLcakWFjLvwJfnzOus+qdplaqUPWf+0cgNmmxgfkcRaSFhySs6dKfIbfelKlSBa0AC9goxXnmFnYg==","repository":{"url":"git+https://github.com/aahoughton/oav.git","type":"git","directory":"packages/oav-express4"},"_npmVersion":"11.13.0","description":"Express 4 adapter for @aahoughton/oav-core. Ships a request-validator middleware factory plus standalone helpers (httpRequestFromExpress, renderProblemDetails) for callers that want to compose their own.","directories":{},"sideEffects":false,"_nodeVersion":"24.16.0","dependencies":{"@aahoughton/oav-core":"3.2.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"peerDependencies":{"express":"^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/oav-express4_3.2.0_1781211636887_0.8304753347624001","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed to @oaverify/express4."},"3.3.0":{"name":"@aahoughton/oav-express4","version":"3.3.0","keywords":["express","express4","middleware","openapi","openapi-3.0","openapi-3.1","openapi-3.2","validation","validator"],"author":{"name":"Andrew Houghton","email":"aah@roarmouse.org"},"license":"MIT","_id":"@aahoughton/oav-express4@3.3.0","maintainers":[{"name":"aahoughton","email":"aah@roarmouse.org"}],"homepage":"https://github.com/aahoughton/oav#readme","bugs":{"url":"https://github.com/aahoughton/oav/issues"},"//":"No prepublishOnly: release.yml runs `pnpm test` from root before `pnpm -r publish`. Per-package publish (`cd packages/<x> && pnpm publish`) is not the supported path; it would skip the test gate.","dist":{"shasum":"993c4a08ebcfcbc089a12088af83e3d8a0607965","tarball":"https://registry.npmjs.org/@aahoughton/oav-express4/-/oav-express4-3.3.0.tgz","fileCount":9,"integrity":"sha512-a3+3DTD7gwebUICy2PdFEcMSMq66iVq+6mZJsGzs9YFmpDY664nUItgu2E4a/Zm/LKuLlsvYW8x9w8GHN0Gm+w==","signatures":[{"sig":"MEYCIQCseq1eEeVtn6r7/Xr4eyAAbmiMnRs8lxA9YpXLZ1FFCQIhAIHmMYKE4WfKP0Kfqh9FDMhT42HdWS+OyAIcbpV9W8BQ","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aahoughton%2foav-express4@3.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":174431},"main":"./dist/index.cjs","type":"module","_from":"file:pkgs/aahoughton-oav-express4-3.3.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=22"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}},"./package.json":"./package.json"},"scripts":{"test":"vitest run","build":"tsup","typecheck":"tsc -b"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:bac0b0d1-f1d3-465a-ae7f-b7e2741f8dbb"}},"_resolved":"/home/runner/work/oav/oav/pkgs/aahoughton-oav-express4-3.3.0.tgz","_integrity":"sha512-a3+3DTD7gwebUICy2PdFEcMSMq66iVq+6mZJsGzs9YFmpDY664nUItgu2E4a/Zm/LKuLlsvYW8x9w8GHN0Gm+w==","repository":{"url":"git+https://github.com/aahoughton/oav.git","type":"git","directory":"packages/oav-express4"},"_npmVersion":"11.13.0","description":"Express 4 adapter for @aahoughton/oav-core. Ships a request-validator middleware factory plus standalone helpers (httpRequestFromExpress, renderProblemDetails) for callers that want to compose their own.","directories":{},"sideEffects":false,"_nodeVersion":"24.16.0","dependencies":{"@aahoughton/oav-core":"3.3.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"peerDependencies":{"express":"^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/oav-express4_3.3.0_1781710959372_0.9940855011210024","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed to @oaverify/express4."},"3.4.0":{"name":"@aahoughton/oav-express4","version":"3.4.0","keywords":["express","express4","middleware","openapi","openapi-3.0","openapi-3.1","openapi-3.2","validation","validator"],"author":{"name":"Andrew Houghton","email":"aah@roarmouse.org"},"license":"MIT","_id":"@aahoughton/oav-express4@3.4.0","maintainers":[{"name":"aahoughton","email":"aah@roarmouse.org"}],"homepage":"https://github.com/aahoughton/oav#readme","bugs":{"url":"https://github.com/aahoughton/oav/issues"},"//":"No prepublishOnly: release.yml runs `pnpm test` from root before `pnpm -r publish`. Per-package publish (`cd packages/<x> && pnpm publish`) is not the supported path; it would skip the test gate.","dist":{"shasum":"e10ee9cddc35aca8ea77026719ee05d4adc63420","tarball":"https://registry.npmjs.org/@aahoughton/oav-express4/-/oav-express4-3.4.0.tgz","fileCount":9,"integrity":"sha512-CDCDlDyFObyhh+DBS/fgrFZ8zqkMcm0hwVCA4liHKWx/6LuxEMFGnJPBV7nxIPaw1VwZKhNVqAiubddR7juY2w==","signatures":[{"sig":"MEQCIFik7zLC3nS+w7loPzU4mxJV4XoMxDLRbm+l1y3XcTZPAiAtpxNcp9K+X7nckE4LIOPFg10X9m03WjBzPI9ISd3pGw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aahoughton%2foav-express4@3.4.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":173861},"main":"./dist/index.cjs","type":"module","_from":"file:pkgs/aahoughton-oav-express4-3.4.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=22"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}},"./package.json":"./package.json"},"scripts":{"test":"vitest run","build":"tsup","typecheck":"tsc -b"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:bac0b0d1-f1d3-465a-ae7f-b7e2741f8dbb"}},"_resolved":"/home/runner/work/oav/oav/pkgs/aahoughton-oav-express4-3.4.0.tgz","_integrity":"sha512-CDCDlDyFObyhh+DBS/fgrFZ8zqkMcm0hwVCA4liHKWx/6LuxEMFGnJPBV7nxIPaw1VwZKhNVqAiubddR7juY2w==","repository":{"url":"git+https://github.com/aahoughton/oav.git","type":"git","directory":"packages/oav-express4"},"_npmVersion":"11.13.0","description":"Express 4 adapter for @aahoughton/oav-core. Ships a request-validator middleware factory plus standalone helpers (httpRequestFromExpress, renderProblemDetails) for callers that want to compose their own.","directories":{},"sideEffects":false,"_nodeVersion":"24.16.0","dependencies":{"@aahoughton/oav-core":"3.4.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"peerDependencies":{"express":"^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/oav-express4_3.4.0_1781997904864_0.8601005636421635","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed to @oaverify/express4."},"3.5.0":{"name":"@aahoughton/oav-express4","version":"3.5.0","keywords":["api-validation","express","express-openapi","express4","middleware","oas","openapi","openapi-3.0","openapi-3.1","openapi-3.2","openapi-middleware","openapi-request-validator","openapi-validator","request-validator","swagger","validation","validator"],"author":{"name":"Andrew Houghton","email":"aah@roarmouse.org"},"license":"MIT","_id":"@aahoughton/oav-express4@3.5.0","maintainers":[{"name":"aahoughton","email":"aah@roarmouse.org"}],"homepage":"https://github.com/aahoughton/oav#readme","bugs":{"url":"https://github.com/aahoughton/oav/issues"},"//":"No prepublishOnly: release.yml runs `pnpm test` from root before `pnpm -r publish`. Per-package publish (`cd packages/<x> && pnpm publish`) is not the supported path; it would skip the test gate.","dist":{"shasum":"a3ff385d7f8c151e391dbc10753df7be154ba3c7","tarball":"https://registry.npmjs.org/@aahoughton/oav-express4/-/oav-express4-3.5.0.tgz","fileCount":9,"integrity":"sha512-9qde08FQwouxjy5ruUAGHwCo3NWQjyapDQvlzpxz1iQ0ebVrlqZwhTUxiTHALO8W9lB9mwDzhzpcd6Bq5O7a5Q==","signatures":[{"sig":"MEUCIA/ES1B+pNAOk6Bj8Xpeciu1R7AIntaiFTb9s6L6jRMdAiEAhsVoR7WOPrFpNsDEPmZiadSibHjl5NGPEALPvy4U0Fw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aahoughton%2foav-express4@3.5.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":174033},"main":"./dist/index.cjs","type":"module","_from":"file:pkgs/aahoughton-oav-express4-3.5.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=22"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}},"./package.json":"./package.json"},"scripts":{"test":"vitest run","build":"tsup","typecheck":"tsc -b"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:bac0b0d1-f1d3-465a-ae7f-b7e2741f8dbb"}},"_resolved":"/home/runner/work/oav/oav/pkgs/aahoughton-oav-express4-3.5.0.tgz","_integrity":"sha512-9qde08FQwouxjy5ruUAGHwCo3NWQjyapDQvlzpxz1iQ0ebVrlqZwhTUxiTHALO8W9lB9mwDzhzpcd6Bq5O7a5Q==","repository":{"url":"git+https://github.com/aahoughton/oav.git","type":"git","directory":"packages/oav-express4"},"_npmVersion":"11.13.0","description":"Express 4 middleware for OpenAPI request validation (3.0/3.1/3.2). Checks method, path, params, body, and headers against your spec and returns problem+json errors. Built on @aahoughton/oav-core.","directories":{},"sideEffects":false,"_nodeVersion":"24.16.0","dependencies":{"@aahoughton/oav-core":"3.5.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"peerDependencies":{"express":"^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/oav-express4_3.5.0_1782139838410_0.2680656112547348","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed to @oaverify/express4."},"3.6.0":{"name":"@aahoughton/oav-express4","version":"3.6.0","keywords":["api-validation","express","express-openapi","express4","middleware","oas","openapi","openapi-3.0","openapi-3.1","openapi-3.2","openapi-middleware","openapi-request-validator","openapi-validator","request-validator","swagger","validation","validator"],"author":{"name":"Andrew Houghton","email":"aah@roarmouse.org"},"license":"MIT","_id":"@aahoughton/oav-express4@3.6.0","maintainers":[{"name":"aahoughton","email":"aah@roarmouse.org"}],"homepage":"https://github.com/aahoughton/oav#readme","bugs":{"url":"https://github.com/aahoughton/oav/issues"},"//":"No prepublishOnly: release.yml runs `pnpm test` from root before `pnpm -r publish`. Per-package publish (`cd packages/<x> && pnpm publish`) is not the supported path; it would skip the test gate.","dist":{"shasum":"f20c43474ffc2d6ec78b949c99b39ed3876cb0da","tarball":"https://registry.npmjs.org/@aahoughton/oav-express4/-/oav-express4-3.6.0.tgz","fileCount":7,"integrity":"sha512-uMPqZk8+FThLmTm0DcIfPHs4BgFx/W1Ndw54CQhMnitbW9nr6m784SCreE9YuY2ySBud6j9kpmedLXd3M+R2mQ==","signatures":[{"sig":"MEUCIDDPwC9i4AR0n0idgPIOzuIIwZBWkeqRrMgcf0vpp54KAiEAlOnb6VLW9OWB1SRLb/5dUSzPUhmzSq95BZHCDUx82ts=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aahoughton%2foav-express4@3.6.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":129777},"main":"./dist/index.cjs","type":"module","_from":"file:pkgs/aahoughton-oav-express4-3.6.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=22"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}},"./package.json":"./package.json"},"scripts":{"test":"vitest run","build":"tsup","typecheck":"tsc -b"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:bac0b0d1-f1d3-465a-ae7f-b7e2741f8dbb"}},"_resolved":"/home/runner/work/oav/oav/pkgs/aahoughton-oav-express4-3.6.0.tgz","_integrity":"sha512-uMPqZk8+FThLmTm0DcIfPHs4BgFx/W1Ndw54CQhMnitbW9nr6m784SCreE9YuY2ySBud6j9kpmedLXd3M+R2mQ==","repository":{"url":"git+https://github.com/aahoughton/oav.git","type":"git","directory":"packages/oav-express4"},"_npmVersion":"11.13.0","description":"Express 4 middleware for OpenAPI request validation (3.0/3.1/3.2). Checks method, path, params, body, and headers against your spec and returns problem+json errors. Built on @aahoughton/oav-core.","directories":{},"sideEffects":false,"_nodeVersion":"24.16.0","dependencies":{"@aahoughton/oav-core":"3.6.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"peerDependencies":{"express":"^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/oav-express4_3.6.0_1782314703675_0.37136694099703726","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed to @oaverify/express4."},"3.7.0":{"name":"@aahoughton/oav-express4","version":"3.7.0","keywords":["api-validation","express","express-openapi","express4","middleware","oas","openapi","openapi-3.0","openapi-3.1","openapi-3.2","openapi-middleware","openapi-request-validator","openapi-validator","request-validator","swagger","validation","validator"],"author":{"name":"Andrew Houghton","email":"aah@roarmouse.org"},"license":"MIT","_id":"@aahoughton/oav-express4@3.7.0","maintainers":[{"name":"aahoughton","email":"aah@roarmouse.org"}],"homepage":"https://github.com/aahoughton/oav#readme","bugs":{"url":"https://github.com/aahoughton/oav/issues"},"//":"No prepublishOnly: release.yml runs `pnpm test` from root before `pnpm -r publish`. Per-package publish (`cd packages/<x> && pnpm publish`) is not the supported path; it would skip the test gate.","dist":{"shasum":"bf6976d717051718a6d0b911ac01d70190ade3d1","tarball":"https://registry.npmjs.org/@aahoughton/oav-express4/-/oav-express4-3.7.0.tgz","fileCount":7,"integrity":"sha512-TrKsZ0Hw7sztvDYVLxbBbjyaoCjwiLrKcf+dB13ksQIYLPn/imEtaoMU38BGh/lRoCfgaqQFcgCyuzcUZhlUXQ==","signatures":[{"sig":"MEQCIGczwY1B/yl+UHjp8p9TXWHjMCG1WGmnqipNG2cZ7mMiAiB1G2cr6g4ltco72tZyebIiFKHBlLA8McvZxvnLHClDqA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aahoughton%2foav-express4@3.7.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":129777},"main":"./dist/index.cjs","type":"module","_from":"file:pkgs/aahoughton-oav-express4-3.7.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=22"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}},"./package.json":"./package.json"},"scripts":{"test":"vitest run","build":"tsup","typecheck":"tsc -b"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:bac0b0d1-f1d3-465a-ae7f-b7e2741f8dbb"}},"_resolved":"/home/runner/work/oav/oav/pkgs/aahoughton-oav-express4-3.7.0.tgz","_integrity":"sha512-TrKsZ0Hw7sztvDYVLxbBbjyaoCjwiLrKcf+dB13ksQIYLPn/imEtaoMU38BGh/lRoCfgaqQFcgCyuzcUZhlUXQ==","repository":{"url":"git+https://github.com/aahoughton/oav.git","type":"git","directory":"packages/oav-express4"},"_npmVersion":"11.13.0","description":"Express 4 middleware for OpenAPI request validation (3.0/3.1/3.2). Checks method, path, params, body, and headers against your spec and returns problem+json errors. Built on @aahoughton/oav-core.","directories":{},"sideEffects":false,"_nodeVersion":"24.17.0","dependencies":{"@aahoughton/oav-core":"3.7.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"peerDependencies":{"express":"^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/oav-express4_3.7.0_1782425644643_0.8418486079542591","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed to @oaverify/express4."},"3.8.0":{"name":"@aahoughton/oav-express4","version":"3.8.0","keywords":["api-validation","express","express-openapi","express4","middleware","oas","openapi","openapi-3.0","openapi-3.1","openapi-3.2","openapi-middleware","openapi-request-validator","openapi-validator","request-validator","swagger","validation","validator"],"author":{"name":"Andrew Houghton","email":"aah@roarmouse.org"},"license":"MIT","_id":"@aahoughton/oav-express4@3.8.0","maintainers":[{"name":"aahoughton","email":"aah@roarmouse.org"}],"homepage":"https://github.com/aahoughton/oav#readme","bugs":{"url":"https://github.com/aahoughton/oav/issues"},"//":"No prepublishOnly: release.yml runs `pnpm test` from root before `pnpm -r publish`. Per-package publish (`cd packages/<x> && pnpm publish`) is not the supported path; it would skip the test gate.","dist":{"shasum":"4ab6fc4850bbca4867f40705f4245fa1ddb86255","tarball":"https://registry.npmjs.org/@aahoughton/oav-express4/-/oav-express4-3.8.0.tgz","fileCount":7,"integrity":"sha512-9Kfiqf2avNbPHB5rVU7tUvjdLpRjrC/UGRGxZo9XBUa7hB7es2BVPlI+4aq/WpW/BIqHyMGbEi3vvQ6bP9XdMw==","signatures":[{"sig":"MEUCIGq5osl9FgKcjyvuQrZwc/PJgadL3YBUIsib4FAumGVfAiEAlLK1SkejnK/DJTm3U1Ogfh7gsnPu5lfA35bSoeoys0g=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aahoughton%2foav-express4@3.8.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":130031},"main":"./dist/index.cjs","type":"module","_from":"file:pkgs/aahoughton-oav-express4-3.8.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=22"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}},"./package.json":"./package.json"},"scripts":{"test":"vitest run","build":"tsup","typecheck":"tsc -b"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:bac0b0d1-f1d3-465a-ae7f-b7e2741f8dbb"}},"_resolved":"/home/runner/work/oav/oav/pkgs/aahoughton-oav-express4-3.8.0.tgz","_integrity":"sha512-9Kfiqf2avNbPHB5rVU7tUvjdLpRjrC/UGRGxZo9XBUa7hB7es2BVPlI+4aq/WpW/BIqHyMGbEi3vvQ6bP9XdMw==","repository":{"url":"git+https://github.com/aahoughton/oav.git","type":"git","directory":"packages/oav-express4"},"_npmVersion":"11.16.0","description":"Express 4 middleware for OpenAPI request validation (3.0/3.1/3.2). Checks method, path, params, body, and headers against your spec and returns problem+json errors. Built on @aahoughton/oav-core.","directories":{},"sideEffects":false,"_nodeVersion":"24.18.0","dependencies":{"@aahoughton/oav-core":"3.8.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"peerDependencies":{"express":"^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/oav-express4_3.8.0_1783306966329_0.7115540150467576","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed to @oaverify/express4."}},"time":{"created":"2026-04-26T04:56:08.917Z","modified":"2026-07-28T04:30:16.859Z","1.0.0":"2026-04-26T04:56:09.174Z","1.1.0":"2026-04-26T21:52:18.779Z","1.1.1":"2026-04-27T04:53:19.193Z","2.0.0":"2026-05-02T18:20:21.057Z","2.1.0":"2026-05-04T05:38:21.465Z","2.2.0":"2026-05-19T19:08:35.714Z","2.2.1":"2026-06-05T22:53:21.861Z","2.3.0":"2026-06-06T16:15:03.453Z","2.4.0":"2026-06-06T20:15:45.174Z","3.0.0":"2026-06-08T04:15:31.334Z","3.1.0":"2026-06-09T20:27:37.979Z","3.2.0":"2026-06-11T21:00:37.091Z","3.3.0":"2026-06-17T15:42:39.493Z","3.4.0":"2026-06-20T23:25:05.029Z","3.5.0":"2026-06-22T14:50:38.548Z","3.6.0":"2026-06-24T15:25:03.824Z","3.7.0":"2026-06-25T22:14:04.766Z","3.8.0":"2026-07-06T03:02:46.498Z"},"bugs":{"url":"https://github.com/aahoughton/oav/issues"},"author":{"name":"Andrew Houghton","email":"aah@roarmouse.org"},"license":"MIT","homepage":"https://github.com/aahoughton/oav#readme","keywords":["api-validation","express","express-openapi","express4","middleware","oas","openapi","openapi-3.0","openapi-3.1","openapi-3.2","openapi-middleware","openapi-request-validator","openapi-validator","request-validator","swagger","validation","validator"],"repository":{"url":"git+https://github.com/aahoughton/oav.git","type":"git","directory":"packages/oav-express4"},"description":"Express 4 middleware for OpenAPI request validation (3.0/3.1/3.2). Checks method, path, params, body, and headers against your spec and returns problem+json errors. Built on @aahoughton/oav-core.","maintainers":[{"name":"aahoughton","email":"aah@roarmouse.org"}],"readme":"# oav-express4\n\nExpress 4 adapter for [`oav-core`](https://www.npmjs.com/package/@aahoughton/oav-core): a request-validator middleware factory plus standalone helpers (`httpRequestFromExpress`, `renderProblemDetails`) for callers composing their own middleware.\n\nThin: this package re-exports nothing from oav-core. You install both. The adapter declares oav-core as a regular dependency, so a single `npm install @aahoughton/oav-express4` pulls oav-core along; or install [`oav`](https://www.npmjs.com/package/@aahoughton/oav) instead if you want YAML readers and the CLI.\n\nSibling packages: [`oav-express5`](https://github.com/aahoughton/oav/blob/main/packages/oav-express5/README.md), [`oav-fastify`](https://github.com/aahoughton/oav/blob/main/packages/oav-fastify/README.md). Identical option shapes and defaults; `validateRequests` and `renderProblemDetails` share names across the family, while the `httpRequestFrom*` extractor and `*Context` type carry framework-native names.\n\n> **Migrating from `express-openapi-validator`?** See [docs/migration-from-eov.md](https://github.com/aahoughton/oav/blob/main/docs/migration-from-eov.md) for behavior differences (path-label `/params/` → `/path/`, `errorCode` namespacing, status mapping) and a worked porting walkthrough.\n\n## Install\n\n```bash\n# JSON specs only\nnpm install @aahoughton/oav-core @aahoughton/oav-express4 express\n\n# YAML specs + CLI (oav transitively provides oav-core)\nnpm install @aahoughton/oav @aahoughton/oav-express4 express\n```\n\n`express` is a peer dep; your app's existing install satisfies it.\n\n> **YAML specs.** `oav-core` is JSON-only by design (zero runtime deps). If your spec is YAML, either install [`oav`](https://www.npmjs.com/package/@aahoughton/oav) instead (it bundles the YAML readers and the CLI), or install `yaml` separately and parse the spec yourself before passing the parsed object to `createValidator`.\n\n## Quick start\n\n```ts\nimport express from \"express\";\nimport { createValidator } from \"@aahoughton/oav-core\";\nimport { validateRequests } from \"@aahoughton/oav-express4\";\n\nconst validator = createValidator(spec); // see \"Hardening for untrusted input\" below\n\nconst app = express();\napp.use(express.json()); // ← MUST run before validateRequests\napp.use(validateRequests(validator));\n\napp.post(\"/pets\", (req, res) => res.json({ ok: true }));\n```\n\nInvalid requests receive a `400 application/problem+json` response (status from `httpStatusFor`, body from `toProblemDetails`, `Allow` header on 405). Valid requests reach the route handlers.\n\n> **Body parser ordering matters.** `express.json()` (or your equivalent) must run **before** `validateRequests(...)`, otherwise `req.body` is `undefined` and the validator emits `body required` for every request: a misleading error that points at the schema, not at the missing parser. Same for `cookie-parser` if your spec validates cookies. Any middleware that populates `req.body` with a parsed object satisfies oav: `express.json()`, custom streaming parsers, `body-parser`, fastify's bridge, app-specific middleware all work the same way.\n>\n> **Empty-body normalization.** Some parsers (streaming variants, custom multi-format setups) leave `req.body === undefined` even after they run, for empty `{}`-equivalent payloads. When that happens, `required`-field checks short-circuit on the missing body, so empty submissions pass validation. Normalize via `toHttpRequest`:\n>\n> ```ts\n> import { httpRequestFromExpress, validateRequests } from \"@aahoughton/oav-express4\";\n>\n> app.use(\n>   validateRequests(validator, {\n>     toHttpRequest: (req) => ({ ...httpRequestFromExpress(req), body: req.body ?? {} }),\n>   }),\n> );\n> ```\n>\n> Stock `express.json()` populates an empty body to `{}` and doesn't hit this, but migrators inheriting alternative parsers (e.g. `body-parser` streaming mode) often do.\n\n## Hardening for untrusted input\n\nThe quick start is the minimal wiring. Before exposing the validator to untrusted callers, cap two things so a small, cheap payload can't burn CPU or exhaust the stack. Both are `createValidator` options, and both default to uncapped, so the quick start above sets neither.\n\n```ts\nconst validator = createValidator(spec, {\n  maxDepth: 64, // recursion cap: a body nesting past 64 levels fails as 400\n  maxErrors: 10, // stop after 10 errors instead of walking a huge invalid body\n});\n```\n\n- **`maxDepth`** bounds recursion through self-referential (`$ref`) schemas. Without it, a few KB of deeply nested JSON can exhaust the call stack and surface as a 500. Past the cap, validation emits a `depth` error (mapped to 400) instead of descending. Legitimate payloads rarely recurse beyond ten or fifteen levels, so 32 to 64 is generous.\n- **`maxErrors`** caps how many errors one request can produce, in compute and in response size: a large array whose every element fails the same way otherwise yields one error per element. Results carry `truncated: true` when the cap was hit. Leave it unset in development if you want every error at once.\n\nA byte-size limit (`express.json({ limit })`) and a parse-boundary depth cap, applied before the request reaches the validator, are backstops for nesting the validator never traverses (fields the schema doesn't descend into); see [Guarding against deeply nested payloads](https://github.com/aahoughton/oav/blob/main/docs/configuration.md#guarding-against-deeply-nested-payloads).\n\n## API\n\n### `validateRequests(validator, options?)`\n\nReturns an Express 4 `RequestHandler`.\n\n| option          | type                                                        | default                  |\n| --------------- | ----------------------------------------------------------- | ------------------------ |\n| `toHttpRequest` | `(req: Request) => HttpRequest`                             | `httpRequestFromExpress` |\n| `onError`       | `(errors: ValidationError[], ctx) => void \\| Promise<void>` | `renderProblemDetails`   |\n\n`onError` may be async; the middleware awaits it. If it throws or rejects, the error is forwarded via `next(err)` so the host's error middleware sees it. The middleware does **not** call `next()` after `onError` returns; your callback owns the response (write to `ctx.res`, or call `ctx.next(err)` to delegate).\n\n> **Validation failures don't traverse Express's error chain by default.** The default `onError` (`renderProblemDetails`) writes the response directly. If you're migrating from `express-openapi-validator` (which emits validation failures as `HttpError` through `next(err)`), your existing error middleware won't see oav's failures unless you forward them; see [Forward to Express's error middleware](#forward-to-expresss-error-middleware) below. Same goes for observability: see [Add observability without changing the response](#add-observability-without-changing-the-response).\n\n### `validateResponses(validator, options?)`\n\nOpt-in middleware that validates outgoing responses (`res.json`, `res.send`) against the spec. Mount it where you want response checking, conventionally on in development and off in production:\n\n```ts\nimport { validateResponses } from \"@aahoughton/oav-express4\";\n\nif (process.env.NODE_ENV !== \"production\") {\n  app.use(validateResponses(validator));\n}\n```\n\nMount it after `validateRequests`. Mounted before, it also validates the 400 problem-details bodies the request validator renders; unless the spec declares those responses, every request-validation 400 becomes a 500 finding.\n\n| option          | type                                                        | default                         |\n| --------------- | ----------------------------------------------------------- | ------------------------------- |\n| `toHttpRequest` | `(req: Request) => HttpRequest`                             | `httpRequestFromExpress`        |\n| `statuses`      | `(status: number) => boolean`                               | validate every status           |\n| `onError`       | `(errors: ValidationError[], ctx) => void \\| Promise<void>` | throw `ResponseValidationError` |\n\nThe default `onError` throws a `ResponseValidationError` (forwarded via `next(err)` to your error middleware, since a non-conforming response is a server bug). Return normally from a custom `onError` to log-and-continue: the original body is sent unchanged. Every declared status is checked by default (4xx / 5xx too); an undeclared status is itself a finding. Only the core `validateResponse` stays pure; this is the one place the adapter wraps `res`, and only where you mount it.\n\n**Split-phase: status and headers always, body when it's JSON.** Status and declared headers are checked for every response that flows through `res.send`, regardless of media type, so an undeclared status or a missing required header on a 204, a text error page, or `res.sendStatus` is a finding. The body is validated only when it is a parseable JSON string: the middleware wraps `res.send`, the one point every JSON response passes through serialized (`res.json` stringifies and re-dispatches through it), parses that string, and validates the result. Serialization runs first, so `toJSON` methods (ORM documents, `Date` fields), the app's `json replacer` / `json spaces` settings, and dropped `undefined` keys are all reflected in what is checked: validation sees exactly what the client receives. Cost is one `JSON.parse` per JSON response while mounted; mount it dev-only and that cost never reaches production.\n\nBody validated: `res.json(obj)`, `res.send(obj)`, `res.send(jsonString)` with a JSON content type, `res.jsonp` without a callback parameter, and the bodies Express computes for HEAD requests (a HEAD request validates against the GET operation when the spec declares no HEAD). Status and headers validated, body not: non-JSON string sends (text error pages, `res.sendStatus`, `res.jsonp` with a callback), malformed JSON strings, and an empty body (`res.json()` with no argument). A missing body is not itself a finding by default, since OpenAPI declares response content without a required flag; build the validator with `requireResponseBody: true` (see `ValidatorOptions`) to make it one, catching the empty-200 bug where `res.json(user)` ran with an `undefined` lookup result (HEAD and 204 / 205 / 304 stay exempt). With that flag on, every body-not-validated case in this list counts as absent, since the middleware hands the validator a body only when it parsed as JSON. Not covered at all (these bypass `res.send`): Buffers, streamed bodies (`res.write` / `res.end`), `res.sendFile`, redirects (`res.redirect` uses `res.end`), and apps that override `res.json` with a custom serializer that writes to the socket itself (stock `res.json` re-dispatches through `res.send`; an override that pipes directly never does). For a response path the middleware can't see, call `validator.validateResponse` directly at the layer you own; it stays a pure function for exactly this reason. Express 4's deprecated two-argument forms (`res.json(status, obj)` and friends) are forwarded to Express untouched; once Express disambiguates them, the body comes back through `send` and is validated against the actual status.\n\n**Error-middleware responses are responses too.** A body your error middleware renders for an ordinary thrown error is validated like any other, so declare your error statuses in the spec or scope them out with `statuses`. The exception is the reply to a response-validation failure itself, which is never re-validated (no loop). Mounting the middleware twice on one chain fails every request with a clear error instead of validating twice.\n\n### `httpRequestFromExpress(req)`\n\nConvert an Express 4 `Request` to oav's framework-agnostic `HttpRequest` shape. Read what's already on `req`; body parsing is the host app's responsibility.\n\nHeader keys lowercased, path stripped of query string, cookies read from `req.cookies` if present.\n\n**Returns a fresh `HttpRequest`.** Top-level fields can be reassigned freely without affecting the original Express `req`; safe to spread (`{ ...httpRequestFromExpress(req), body: {} }`) or mutate in place. The values it references (`req.body`, `req.headers`) are still the originals; deep mutation would still leak, but reassignment doesn't.\n\nUse this when you want to compose your own middleware (e.g. validate inside an existing custom wrapper) without re-implementing the extraction.\n\n### `renderProblemDetails(errors, ctx)`\n\nThe default `onError`. Takes the flat list of failing leaves and writes\nan RFC 9457 `application/problem+json` body (via `toProblemDetails`),\nstatus from `httpStatusFor`, `Allow` header from `allowHeaderFor` on 405.\n`onError` receives the same leaf list whatever `output` the validator\nuses (a tree validator's result is flattened first).\n\nExported standalone so a custom `onError` can call it as the fallback path:\n\n```ts\nvalidateRequests(validator, {\n  onError: (errors, ctx) => {\n    if (errors.some((e) => e.code === \"security\")) return ctx.res.status(401).end();\n    renderProblemDetails(errors, ctx);\n  },\n});\n```\n\n## Common patterns\n\n### Enable shape-only security checks (no auth middleware yet)\n\n`ValidatorOptions.validateSecurity` is off by default; real apps run auth middleware upstream of the validator, so by the time `validateRequests` runs the credential has already been verified. During early dev (no auth wired yet) or with decorator-only auth that just attaches `req.user`, opt in:\n\n```ts\nconst validator = createValidator(spec, { validateSecurity: \"shape\" });\napp.use(validateRequests(validator));\n```\n\nThe check is shape-only: it confirms the declared credential is _present_, not that it's _valid_. Don't treat it as a substitute for auth middleware.\n\n### Per-scheme auth dispatch (the eov `securityHandlers` shape)\n\neov's `securityHandlers` is a per-scheme dispatch table: you supply an auth function per declared scheme and eov calls it. `oav-express4` doesn't ship this as a helper, but the recipe is small. Mount it as middleware _before_ `validateRequests`:\n\n```ts\nimport type { Request } from \"express\";\nimport { createValidator } from \"@aahoughton/oav-core\";\n\ntype SchemeHandler = (req: Request, scopes: string[]) => Promise<boolean>;\n\nconst handlers: Record<string, SchemeHandler> = {\n  bearerAuth: async (req, scopes) => {\n    const token = req.headers.authorization?.replace(/^Bearer /, \"\");\n    return verifyJwt(token, scopes);\n  },\n  apiKeyAuth: async (req) => {\n    const key = req.header(\"x-api-key\");\n    return Boolean(key) && (await verifyApiKey(key));\n  },\n};\n\napp.use(async (req, res, next) => {\n  const op = validator.getOperation({ method: req.method, path: req.path });\n  const requirements = op?.operation.security ?? spec.security ?? [];\n  if (requirements.length === 0) return next();\n  for (const requirement of requirements) {\n    let allPass = true;\n    for (const [scheme, scopes] of Object.entries(requirement)) {\n      const handler = handlers[scheme];\n      if (!handler || !(await handler(req, scopes))) {\n        allPass = false;\n        break;\n      }\n    }\n    if (allPass) return next();\n  }\n  res.status(401).type(\"application/problem+json\").json({\n    type: \"about:blank\",\n    title: \"Unauthorized\",\n    status: 401,\n    detail: \"no security requirement satisfied\",\n  });\n});\n\napp.use(validateRequests(validator)); // shape check off by default; redundant given the dispatcher above\n```\n\nOpenAPI semantics: each requirement object is AND across its scheme keys; the outer array is OR across requirements. The recipe walks them accordingly.\n\nIf multiple projects end up copying this recipe, that's the signal to harvest into a `dispatchSecurity(...)` helper export. Not yet.\n\n### Skip validation for paths the spec doesn't declare\n\nThe validator owns this: pass it `ignorePaths` or `ignoreUndocumented` at construction. See `ValidatorOptions` in `oav-core` for the contract.\n\n```ts\nconst validator = createValidator(spec, {\n  ignorePaths: (p) => p.startsWith(\"/internal/\"),\n});\napp.use(validateRequests(validator));\n```\n\n### Custom error envelope\n\n```ts\napp.use(\n  validateRequests(validator, {\n    onError: (errors, ctx) => {\n      ctx.res.status(httpStatusFor(errors)).json({\n        message: `${errors.length} validation error(s)`,\n        errors: collectIssues(errors),\n      });\n    },\n  }),\n);\n```\n\n### Forward to Express's error middleware\n\n```ts\napp.use(\n  validateRequests(validator, {\n    onError: (errors, ctx) => ctx.next(new ValidationFailure(errors)),\n  }),\n);\n\napp.use((err, _req, res, _next) => {\n  if (err instanceof ValidationFailure) {\n    res.status(422).json({ ... });\n    return;\n  }\n  // ... your existing error handler\n});\n```\n\n### Add observability without changing the response\n\nValidation failures don't reach your registered Express error middleware by default (the middleware terminates the request itself). To log every failure while keeping the default problem-details response, compose `renderProblemDetails` after your log call:\n\n```ts\napp.use(\n  validateRequests(validator, {\n    onError: (errors, ctx) => {\n      log.warn(\"validation failed\", { path: ctx.req.path, codes: errors.map((e) => e.code) });\n      renderProblemDetails(errors, ctx);\n    },\n  }),\n);\n```\n\nUse this whenever your existing error pipeline (Sentry, structured logger, request-id correlation) needs to see validation failures without changing the response shape.\n\n### Async `onError` (remote logging, dynamic config)\n\n```ts\napp.use(\n  validateRequests(validator, {\n    onError: async (errors, ctx) => {\n      await sentry.captureException(errors);\n      renderProblemDetails(errors, ctx);\n    },\n  }),\n);\n```\n\nThe middleware awaits the returned promise; rejections route to `next(err)`.\n\n### Per-route mounting\n\n`validateRequests(...)` is route-aware (it derives the operation from method+path). Mount it once at the app level; per-route mounting is redundant and may cause double-validation under nested routers.\n\n### Global validator + per-route multer (file uploads)\n\nWhen the validator is mounted globally and one or a few routes accept file uploads via multer, mount multer at the route prefix that needs it (upstream of the global validator) and use `toHttpRequest` to synthesize the spec-shaped body from `req.files`:\n\n```ts\nimport multer from \"multer\";\nimport { httpRequestFromExpress, validateRequests } from \"@aahoughton/oav-express4\";\n\nconst upload = multer({ storage: multer.memoryStorage() });\napp.use(\"/uploads\", upload.any());\n\napp.use(\n  validateRequests(validator, {\n    toHttpRequest: (req) => {\n      const httpReq = httpRequestFromExpress(req);\n      const files = req.files as Express.Multer.File[] | undefined;\n      if (files && files.length > 0) {\n        httpReq.body = files.length === 1 ? files[0]?.buffer : files.map((f) => f.buffer);\n      }\n      return httpReq;\n    },\n  }),\n);\n```\n\n`toHttpRequest` is the general \"reshape what oav sees\" seam: synthesizing body from files, normalizing empty bodies, merging headers from an upstream proxy, anything that lives above the extraction layer. The empty-body normalization recipe higher in this README and this multer recipe are two examples of the same pattern.\n\nFor per-route inline multer (validator called from inside the route handler) and the full multer recipe with text-field reassembly, see the [integration.md file uploads section](https://github.com/aahoughton/oav/blob/main/docs/integration.md#file-uploads-with-multer).\n\n## See also\n\n- [`oav-core`](https://www.npmjs.com/package/@aahoughton/oav-core): `createValidator`, `ValidatorOptions`, `formatSummary`, `collectIssues`, `httpStatusFor`, `toProblemDetails`.\n- [`oav`](https://www.npmjs.com/package/@aahoughton/oav): oav-core plus YAML readers and the `oav` CLI.\n- The repo-root [`docs/integration.md`](https://github.com/aahoughton/oav/blob/main/docs/integration.md): broader recipes (security, file uploads, response validation, status mapping, type coercion, ignoring paths).\n- The repo-root [`docs/migration-from-eov.md`](https://github.com/aahoughton/oav/blob/main/docs/migration-from-eov.md): porting from `express-openapi-validator`.\n","readmeFilename":"README.md"}