{"_id":"@adhix11/endpoint-guard","name":"@adhix11/endpoint-guard","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@adhix11/endpoint-guard","version":"1.0.0","description":"Full API contract and security audit CLI for frontend + backend projects","type":"module","main":"./dist/index.cjs","module":"./dist/index.js","types":"./dist/index.d.ts","bin":{"endpoint-guard":"dist/bin/index.js"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"scripts":{"build":"tsup","dev":"tsup --watch","test":"vitest run","test:watch":"vitest","lint":"tsc --noEmit","prepublishOnly":"npm run build"},"keywords":["api","openapi","swagger","security","audit","contract","endpoint","owasp","cli","typescript","loopback","nestjs","express","frontend","backend"],"author":{"name":"adhix11"},"license":"MIT","publishConfig":{"access":"public"},"engines":{"node":">=18.0.0"},"dependencies":{"@apidevtools/swagger-parser":"^10.1.1","chalk":"^5.4.1","commander":"^13.1.0","glob":"^11.0.2","ora":"^8.2.0","typescript":"^5.8.3"},"devDependencies":{"@types/node":"^22.15.0","tsup":"^8.4.0","vitest":"^3.1.0"},"_id":"@adhix11/endpoint-guard@1.0.0","_nodeVersion":"22.19.0","_npmVersion":"11.6.2","dist":{"integrity":"sha512-fGDEphphFhpmvfQ+thpTyAaDSXG2oVt5QvTLYdXElzpP4NzBH1zLpvYol3VKv12zgdkcSKRdj6dOB7hjp/LZOg==","shasum":"91ee7fd84d3b87f9768016753b7ca742561b154c","tarball":"https://registry.npmjs.org/@adhix11/endpoint-guard/-/endpoint-guard-1.0.0.tgz","fileCount":18,"unpackedSize":729974,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIALDV7ae9Nr4Ec1d2AcROe/PNmwADImnXf+SBpCKz6OZAiBl7K1DtBxH74bG3wzrf2Ie87g88t4QdpHwTyi/GewfKw=="}]},"_npmUser":{"name":"adhix11","email":"adhix11@gmail.com"},"directories":{},"maintainers":[{"name":"adhix11","email":"adhix11@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/endpoint-guard_1.0.0_1782444423433_0.5277416512933308"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-26T03:27:03.256Z","1.0.0":"2026-06-26T03:27:03.570Z","modified":"2026-06-26T03:27:03.816Z"},"maintainers":[{"name":"adhix11","email":"adhix11@gmail.com"}],"description":"Full API contract and security audit CLI for frontend + backend projects","keywords":["api","openapi","swagger","security","audit","contract","endpoint","owasp","cli","typescript","loopback","nestjs","express","frontend","backend"],"author":{"name":"adhix11"},"license":"MIT","readme":"# ⛨ @adhix11/endpoint-guard\n\n**Full API contract and security audit CLI for frontend + backend projects.**\n\n[![npm version](https://img.shields.io/npm/v/@adhix11/endpoint-guard.svg)](https://www.npmjs.com/package/@adhix11/endpoint-guard)\n[![Node.js](https://img.shields.io/badge/node-%3E%3D18.0.0-brightgreen)](https://nodejs.org)\n[![License: MIT](https://img.shields.io/badge/License-MIT-blue.svg)](https://opensource.org/licenses/MIT)\n\nendpoint-guard compares frontend API usage with backend OpenAPI specs, validates paths, methods, headers, request bodies, query parameters, responses, authentication, authorization, sensitive data exposure, public write endpoints, BOLA/IDOR risks, tenant isolation risks, CORS, security headers, rate-limit risks, file upload risks, webhook safety, and generates detailed Markdown, JSON, and HTML audit reports.\n\n---\n\n## Quick Start\n\n```bash\n# Run against an OpenAPI spec and frontend source\nnpx @adhix11/endpoint-guard audit \\\n  --spec ./openapi.json \\\n  --src ./src\n\n# Full audit with all report formats\nnpx @adhix11/endpoint-guard audit \\\n  --spec ./openapi.json \\\n  --src ./src \\\n  --backend-src ./server/src \\\n  --framework loopback4 \\\n  --report console,markdown,json,html\n\n# Runtime verification mode\nnpx @adhix11/endpoint-guard audit \\\n  --spec ./openapi.json \\\n  --base-url https://api.example.com \\\n  --runtime \\\n  --token \"Bearer your-jwt-token\"\n\n# CI/CD mode — fail on critical or high issues\nnpx @adhix11/endpoint-guard audit \\\n  --spec ./openapi.json \\\n  --src ./src \\\n  --ci \\\n  --fail-on critical,high\n```\n\n---\n\n## Features\n\n### 24 Audit Categories\n\n| # | Feature | Category | Description |\n|:-:|:--|:--|:--|\n| 1 | **Endpoint Contract** | Contract | Missing endpoints, method mismatches, unused endpoints, deprecated usage |\n| 2 | **Request Headers** | Security | Missing auth headers, hardcoded tokens, wrong auth scheme |\n| 3 | **Response Audit** | Contract | Missing success/error responses, sensitive response fields |\n| 4 | **Request Body** | Contract | Missing required fields, unknown fields, type mismatches |\n| 5 | **Query Parameters** | Contract | Unknown params, sensitive data in query, no pagination |\n| 6 | **Auth & Authorization** | Security | Public endpoints, weak auth, inconsistent security |\n| 7 | **BOLA / IDOR** | Security | Object ID endpoints without ownership verification |\n| 8 | **Tenant Isolation** | Security | Cross-tenant data access risks |\n| 9 | **CORS** | Security | Wildcard origins, credentials with broad CORS |\n| 10 | **Security Headers** | Security | Missing HSTS, CSP, X-Content-Type-Options |\n| 11 | **Rate Limiting** | Reliability | No pagination, missing 429, heavy operations |\n| 12 | **File Upload** | Security | Public uploads, no size/MIME restrictions |\n| 13 | **Error Leakage** | Data | Stack traces, SQL errors, file paths in responses |\n| 14 | **Frontend Quality** | Quality | Missing try/catch, no timeout, hardcoded URLs |\n| 15 | **Backend Source** | Security | Missing auth decorators, exposed filters |\n| 16 | **Data Exposure** | Data | Sensitive fields in response schemas |\n| 17 | **Mass Assignment** | Security | Privileged fields in request bodies |\n| 18 | **Admin Endpoints** | Security | Admin paths without role protection |\n| 19 | **Webhooks** | Security | Missing signature, timestamp, idempotency |\n| 20 | **Idempotency** | Reliability | Payment/order POST without idempotency key |\n| 21 | **Cache Control** | Security | Sensitive endpoints without no-store |\n| 22 | **OpenAPI Quality** | Quality | Missing operationId, tags, schemas, descriptions |\n| 23 | **Runtime Tests** | Security | Live auth, CORS, headers, error leakage tests |\n| 24 | **Risk Scoring** | All | Aggregate score 0-100 with OWASP mapping |\n\n---\n\n## CLI Options\n\n```\nOptions:\n  -s, --src <path>          Frontend source directory (default: \"./src\")\n  -b, --backend-src <path>  Backend source directory\n      --spec <path>         OpenAPI spec file path or URL\n  -f, --framework <name>    Backend framework: loopback4, nestjs, express, fastify\n      --base-url <url>      Base URL for runtime testing\n      --runtime             Enable runtime verification mode\n  -t, --token <token>       Bearer token for runtime testing\n  -r, --report <formats>    Report formats: console,markdown,json,html (default: \"console\")\n  -o, --output <dir>        Output directory for reports (default: \".\")\n      --ci                  CI mode — exit with code 1 on failure\n      --fail-on <levels>    Severity levels that cause CI failure (default: \"critical,high\")\n  -c, --config <path>       Config file path\n```\n\n---\n\n## Configuration File\n\nCreate `.endpointguardrc.json` or `endpoint-guard.config.json`:\n\n```json\n{\n  \"src\": \"./src\",\n  \"backendSrc\": \"./server/src\",\n  \"spec\": \"./openapi.json\",\n  \"framework\": \"loopback4\",\n  \"baseUrl\": \"http://localhost:3000\",\n  \"reports\": [\"console\", \"markdown\", \"json\", \"html\"],\n\n  \"auth\": {\n    \"tokenEnv\": \"ENDPOINT_GUARD_TOKEN\",\n    \"requiredHeaders\": [\"Authorization\"],\n    \"tenantHeaders\": [\"X-Tenant-Id\", \"X-Enterprise-Id\"]\n  },\n\n  \"allowPublic\": [\n    \"POST /login\",\n    \"POST /signup\",\n    \"GET /health\",\n    \"GET /openapi.json\",\n    \"POST /webhook/*\"\n  ],\n\n  \"ignoreUnused\": [\n    \"GET /health\",\n    \"GET /openapi.json\"\n  ],\n\n  \"sensitiveFields\": [\n    \"password\", \"token\", \"secret\", \"otp\",\n    \"apiKey\", \"refreshToken\", \"privateKey\",\n    \"isAdmin\", \"role\", \"permissions\"\n  ],\n\n  \"tenantFields\": [\n    \"enterpriseId\", \"tenantId\", \"companyId\",\n    \"locationOneId\", \"locationTwoId\"\n  ],\n\n  \"failOn\": {\n    \"critical\": true,\n    \"high\": true,\n    \"medium\": false,\n    \"low\": false\n  }\n}\n```\n\n---\n\n## Report Formats\n\n### Console\nRich terminal output with colored severity indicators and structured issue details.\n\n### Markdown (`endpoint-guard-report.md`)\nFull audit report with executive summary, risk score, issue details, endpoint inventories, and CI gate result.\n\n### JSON (`endpoint-guard-report.json`)\nMachine-readable format for CI/CD integration and custom tooling.\n\n### HTML (`endpoint-guard-report.html`)\nPremium dark-mode visual report with risk score card, collapsible sections, and responsive design.\n\n---\n\n## Risk Scoring\n\nEach issue is scored by severity:\n\n| Severity | Points | Example |\n|:--|--:|:--|\n| Critical | 10 | Public write endpoint, hardcoded token |\n| High | 7 | Missing auth, BOLA risk, tenant isolation |\n| Medium | 4 | Missing pagination, unknown fields |\n| Low | 1 | Missing timeout, no try/catch |\n| Info | 0 | Unused endpoint, missing description |\n\nFinal risk score ranges:\n- **80-100**: Critical Risk\n- **60-79**: High Risk\n- **30-59**: Medium Risk\n- **1-29**: Low Risk\n- **0**: Clean\n\n---\n\n## OWASP API Top 10 (2023) Mapping\n\n| OWASP ID | Name | Auditors |\n|:--|:--|:--|\n| API1:2023 | Broken Object Level Authorization | BOLA/IDOR, Tenant Isolation |\n| API2:2023 | Broken Authentication | Auth, Request Headers, Webhooks |\n| API3:2023 | Broken Object Property Level Authorization | Data Exposure, Mass Assignment, Request Body |\n| API4:2023 | Unrestricted Resource Consumption | Rate Limit, File Upload |\n| API5:2023 | Broken Function Level Authorization | Auth, Admin Endpoints |\n| API8:2023 | Security Misconfiguration | CORS, Security Headers, Cache Control |\n| API9:2023 | Improper Inventory Management | Endpoint Contract, Backend Source |\n\n---\n\n## Supported Frameworks\n\n### Frontend\n- **React** (axios, fetch)\n- **Next.js** (API routes, fetch)\n- **Angular** (HttpClient)\n- **Vue** (axios, fetch)\n- Any JS/TS project using axios or fetch\n\n### Backend\n- **LoopBack 4** — decorators: `@authenticate`, `@authorize`, `@get/@post`, `@requestBody`\n- **NestJS** — decorators: `@UseGuards`, `@Roles`, `@Get/@Post`, `@Body`\n- **Express** — `app.get()`, `router.post()`, middleware detection\n- **Fastify** — `fastify.get()`, schema definitions\n\n---\n\n## Programmatic API\n\n```typescript\nimport { runAudit, loadConfig, parseOpenAPISpec } from '@adhix11/endpoint-guard';\n\n// Run a full audit programmatically\nconst config = loadConfig({ spec: './openapi.json', src: './src' });\nconst report = await runAudit(config);\n\nconsole.log(`Risk Score: ${report.riskScore.score}/100`);\nconsole.log(`Issues: ${report.summary.totalIssues}`);\n```\n\n---\n\n## CI/CD Integration\n\n### GitHub Actions\n\n```yaml\n- name: API Security Audit\n  run: |\n    npx @adhix11/endpoint-guard audit \\\n      --spec ./openapi.json \\\n      --src ./src \\\n      --ci \\\n      --fail-on critical,high \\\n      --report json\n```\n\n### GitLab CI\n\n```yaml\napi-audit:\n  script:\n    - npx @adhix11/endpoint-guard audit --spec ./openapi.json --src ./src --ci --fail-on critical,high\n  artifacts:\n    paths:\n      - endpoint-guard-report.*\n```\n\n---\n\n## License\n\nMIT © adhix11\n","readmeFilename":"README.md","_rev":"1-06cdb743bd4e0d8967aeb5304ee9cff6"}