{"_id":"@aldy505/malibu","_rev":"1-9635962730e963be5c967d9509847c61","name":"@aldy505/malibu","dist-tags":{"latest":"1.0.4"},"versions":{"1.0.4":{"name":"@aldy505/malibu","version":"1.0.4","description":"Framework-agnostic CSRF middleware","keywords":["csrf","middleware","tokens","framework agnostic","express","tinyhttp","polka","http"],"author":{"name":"Reinaldy Rafli","email":"aldy505@tutanota.com"},"license":"MIT","types":"./dist/index.d.ts","main":"./dist/index.cjs","scripts":{"build":"rollup -c","test":"node --experimental-loader esbuild-node-loader node_modules/uvu/bin.js tests","test:coverage":"c8 --include=src pnpm test","test:report":"c8 report --reporter=text-lcov > coverage.lcov","lint":"eslint \"./**/*.ts\"","format":"prettier --write \"./**/*.ts\"","prepare":"husky install"},"repository":{"type":"git","url":"git+https://github.com/aldy505/malibu-cjs.git"},"bugs":{"url":"https://github.com/aldy505/malibu-cjs/issues"},"homepage":"https://github.com/aldy505/malibu-cjs#readme","directories":{"test":"./test","lib":"./src"},"engines":{"node":"^12.20.0 || ^14.13.1 || >=16.0.0"},"devDependencies":{"@commitlint/cli":"13.1.0","@commitlint/config-conventional":"13.1.0","@rollup/plugin-typescript":"8.2.5","@tinyhttp/app":"1.3.11","@tinyhttp/cookie-parser":"1.3.11","@types/express-session":"1.17.4","@types/node":"16.9.1","@typescript-eslint/eslint-plugin":"4.31.0","@typescript-eslint/parser":"4.31.0","c8":"7.9.0","esbuild-node-loader":"0.3.1","eslint":"7.32.0","eslint-config-prettier":"8.3.0","eslint-plugin-prettier":"4.0.0","express-session":"1.17.2","husky":"7.0.2","milliparsec":"2.2.0","prettier":"2.4.0","rollup":"2.56.3","supertest-fetch":"1.4.3","tslib":"2.3.1","typescript":"4.3.5","uvu":"0.5.1"},"dependencies":{"@tinyhttp/cookie":"1.3.0","@tinyhttp/cookie-signature":"1.3.0"},"gitHead":"98451a243738c38d944b765fedf5fe86206b9d94","_id":"@aldy505/malibu@1.0.4","_nodeVersion":"16.8.0","_npmVersion":"7.21.0","dist":{"integrity":"sha512-QxZ8OGVcHLAyYOJVma9275fUpTHqKa/ijo69/dcJZeoPuzjxgCkT3s/oiUTAMDC9VxsfnTVHU4m4EkD+/ul8tA==","shasum":"3025ef3c66062951c1e31c42b615daf329bb2619","tarball":"https://registry.npmjs.org/@aldy505/malibu/-/malibu-1.0.4.tgz","fileCount":7,"unpackedSize":22339,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhOuPzCRA9TVsSAnZWagAA8ggP/RQSwMhXW5BA4PWwsop2\noGs8WseTSj3o1FXEAqPkjWaiMkFHzxl9Zpl+v8add33TnmZAD3uZfIw+2USC\nrwT7jWVl7f0cVOq1SqlVTZuYZFZiKl9U6XBhTizv2ZQtrWiY3/TFF3RUrnRg\n/b+HsMOKtVnqo1TtYttRBId/snyGiJ10Z202OwCGzznDIMfNvKc5LKV7p8Ht\nAg5yg/apLeAj8FsGCGdhat58Eco3/O8fsT3lQIcKqi/Z201M6xbc2FWUpbD6\nT0/E4qr6YEYZwzm60gB0htI2j2b9An72buw5Rmes57qPfEbz36fboNlubcHJ\nRN47/ntPFh1eV3Zl/uD8PePVtrg+f5vPPqbHWiSxSzBEaNuI0hgDwiZTNjwH\nC6E7yfGZdBq/hn2l5AjC/EcVcEGdmAOQCYxWWaRFCtQ78q+ronnGqRMLxRQf\nWsrZDHgFF6YbqYmoeIwX5x5kHo/5nfZZ6T0uWHBxi+C3j0J0jdCmqprtzxCy\n176q6mnTi19KIFNGLrwTCIZUbmwRWzLfqMC5qugE8tOWp/YfUOGAyF32RJfa\nqWCBgm8S0rH5HVIkXo2ofucVTd3SxqqJOK7C48NDLB2TeGwP5Boa9PpfD42g\nN7Why4Xd9U8mhCnyUCvFDddPwOu6jC6JaKROmuG1rm9649So/5KLm4//ZRpL\nZeWV\r\n=b4W/\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCMscZAyJcNDE3+ux/l6JTNkkZ9ona8wfXtS1YTUtigZwIhANO+eF9DXuZymxxhbkZ7voUS3Bh+HAFdI+WKc9hwCwWN"}]},"_npmUser":{"name":"aldy505","email":"aldy505@tutanota.com"},"maintainers":[{"name":"aldy505","email":"aldy505@tutanota.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/malibu_1.0.4_1631249394615_0.8170749189330206"},"_hasShrinkwrap":false}},"time":{"created":"2021-09-10T04:49:54.553Z","1.0.4":"2021-09-10T04:49:55.095Z","modified":"2022-04-04T12:36:41.694Z"},"maintainers":[{"name":"aldy505","email":"aldy505@tutanota.com"}],"description":"Framework-agnostic CSRF middleware","homepage":"https://github.com/aldy505/malibu-cjs#readme","keywords":["csrf","middleware","tokens","framework agnostic","express","tinyhttp","polka","http"],"repository":{"type":"git","url":"git+https://github.com/aldy505/malibu-cjs.git"},"author":{"name":"Reinaldy Rafli","email":"aldy505@tutanota.com"},"bugs":{"url":"https://github.com/aldy505/malibu-cjs/issues"},"license":"MIT","readme":"<div align=\"center\">\n<br /><br />\n<img align=\"center\" width=\"600px\" src=\"https://raw.githubusercontent.com/tinyhttp/malibu/master/logo.svg\" alt=\"Malibu\" />\n<br /><br />\n\n[![npm](https://img.shields.io/npm/v/malibu?style=for-the-badge&logo=npm&label=&color=26B0A0)](https://npmjs.com/package/malibu) [![npm](https://img.shields.io/npm/dt/malibu?style=for-the-badge&color=26B0A0)](https://npmjs.com/package/malibu) [![GitHub Workflow Status](https://img.shields.io/github/workflow/status/tinyhttp/malibu/CI?label=&logo=github&style=for-the-badge&color=26B0A0)](https://github.com/tinyhttp/malibu/actions) [![Coveralls](https://img.shields.io/coveralls/github/tinyhttp/malibu?style=for-the-badge&color=26B0A0)](https://coveralls.io/github/tinyhttp/malibu) [![Code Quality](https://img.shields.io/codefactor/grade/github/tinyhttp/malibu?style=for-the-badge&color=26B0A0)](https://www.codefactor.io/repository/github/tinyhttp/malibu)\n\n</div>\n\n**This is a fork of my own creation, but for CommonJS. I've updated the readme so you should be on the right track while using this one.**\n\n**If your project uses ES Modules, consider using the original [Malibu library](https://github.com/tinyhttp/malibu).**\n\nThis middleware helps web developers fight [CSRF](https://en.wikipedia.org/wiki/Cross-site_request_forgery) attacks. Bear in mind, by solely using this middleware, we can't guarantee your app will be free from CSRF attacks. Refer to [CSRF Prevention Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/Cross-Site_Request_Forgery_Prevention_Cheat_Sheet.html) and [pillarjs/understanding-csrf](https://github.com/pillarjs/understanding-csrf) for more details.\n\n* ⚡ Framework agnostic (works with Express, Tinyhttp, Polka, and more!)\n* ✨ ~~Native ESM support~~ Uhh, no this one is Common JS only.\n* 🛠 Typescript typings out of the box\n* 🚀 No legacy dependencies\n\n## Install\n\n```\npnpm i @aldy505/malibu\n```\n\n## Usage\n\nLike all CSRF plugins, it depends on either Cookie Parser or Session middleware.\n\nNOTE: If you are using Tinyhttp's dependencies (cookie-parser and such), don't forget to use the Common JS version.\nIt's should be anything before v2. Otherwise, you're going to get an error.\n\n```js\nconst { App } = require('@tinyhttp/app')\nconst { cookieParser } = require('@tinyhttp/cookie-parser')\nconst { csrf } = require('malibu')\n\nconst app = new App()\n\nconst csrfProtection = csrf()\napp.use(cookieParser())\n\n// this lets you acquire CSRF token on response body\n// you also have CSRF token on your cookies as _csrf\napp.get('/', csrfProtection, (req, res) => {\n  res.status(200).json({ token: req.csrfToken() })\n})\n\n// you may only access this if you give a previously acquired CSRF token\napp.post('/', csrfProtection, (req, res) => {\n  res.status(200).json({ message: 'hello' })\n})\n```\n\nFor signed cookies:\n\n```js\nconst app = new App()\n\nconst csrfProtection = csrf({ cookie: { signed: true } })\napp.use(cookieParser('secret key'))\n\n// this lets you acquire CSRF token on the response body\n// you also have a CSRF token on your cookies as _csrf\napp.get('/', csrfProtection, (req, res) => {\n  res.status(200).json({ token: req.csrfToken() })\n})\n\n// you may only access this if you give a previously acquired CSRF token\napp.post('/', csrfProtection, (req, res) => {\n  res.status(200).json({ message: 'hello' })\n})\n```\n\nWith [express-session](https://github.com/expressjs/session):\n\n```js\nconst { App } = require('@tinyhttp/app')\nconst session = require('express-session')\nconst { csrf } = require('malibu')\n\nconst app = new App()\n\nconst csrfProtection = csrf({ middleware: 'session' })\napp.use(session({ secret: 'secret key', resave: false, saveUninitialized: false }))\n\n// this lets you acquire CSRF token on response body\napp.get('/', csrfProtection, (req, res) => {\n  res.status(200).json({ token: req.csrfToken() })\n})\n\n// you may only access this if you give a previously acquired CSRF token\napp.post('/', csrfProtection, (req, res) => {\n  res.status(200).json({ message: 'hello' })\n})\n```\n\nFor detailed example, please refer to [examples](https://github.com/tinyhttp/tinyhttp/tree/master/examples/csrf)\n\n## Options\n\n| Name         | Type                    | Default                                                                                                                                           | Description                                                                                                                                                                                                                                                                                    |\n| ------------ | ----------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |\n| middleware   | `string`                | `cookie`                                                                                                                                          | Specifies which middleware to look for. Available options are `cookie` and `session`                                                                                                                                                                                                           |\n| cookie       | `CookieOptions`         | `{ signed: false, key: '_csrf', path: '/' }`                                                                                                      | `signed` specifies whether the cookie is signed or unsigned, `key` specifies to the cookie key, `path` specifies the domain of the cookie. For other options please refer to [@tinyhttp/cookie serializer options](https://github.com/tinyhttp/tinyhttp/tree/master/packages/cookie#options-1) |\n| sessionKey   | `string`                | `session`                                                                                                                                         | Specifies session key name                                                                                                                                                                                                                                                                     |\n| value        | `(req: Request) => any` | `req.body._csrf, req.query._csrf, req.headers[\"csrf-token\"], req.headers[\"xsrf-token\"], req.headers[\"x-csrf-token\"], req.headers[\"x-xsrf-token\"]` | Specifies where to look for the CSRF token                                                                                                                                                                                                                                                     |\n| ignoreMethod | `Array<HTTPMethod>`     | `[\"GET\", \"HEAD\", \"OPTIONS\"]`                                                                                                                      | Specifies the HTTP Method in which CSRF protection will be disabled                                                                                                                                                                                                                            |\n| saltLength   | `number`                | `8`                                                                                                                                               | Specifies the salt length for CSRF token                                                                                                                                                                                                                                                       |\n| secretLength | `number`                | `18`                                                                                                                                              | Specifies the secret length for CSRF Token                                                                                                                                                                                                                                                     |\n\n## Why \"malibu\"?\n\nIt's one variation of a longboard used in surfing. It's a 60's style longboard, made with heavy glass, long parallel 50/50 rails, and a deep single fin. Made especially for trimming, (walking the board) and for noseriding. Not to mention, it looks cool.\n","readmeFilename":"README.md"}