{"_id":"@best-skn/elysia-helmet","_rev":"4-9f64bbbfae4c2592448b52711590c19e","name":"@best-skn/elysia-helmet","dist-tags":{"latest":"1.0.3"},"versions":{"1.0.0":{"name":"@best-skn/elysia-helmet","version":"1.0.0","keywords":["elysia","elysia-plugin","bun","helmet","security","headers","cors","csp","xss","xss-protection","dns-prefetch","referrer-policy","permissions-policy","hsts","cross-origin-resource-policy","cross-origin-opener-policy"],"author":{"url":"https://skn.best","name":"SKN Shukhan","email":"skn437physx@gmail.com"},"license":"MIT","_id":"@best-skn/elysia-helmet@1.0.0","maintainers":[{"name":"skn437","email":"skn437physx@gmail.com"}],"homepage":"https://github.com/skn437/skn-elysia-helmet#readme","bugs":{"url":"https://github.com/skn437/skn-elysia-helmet/issues"},"dist":{"shasum":"c26c44df8e261ae7d27f7f1670f3ef2cff2c55cf","tarball":"https://registry.npmjs.org/@best-skn/elysia-helmet/-/elysia-helmet-1.0.0.tgz","fileCount":7,"integrity":"sha512-d8gzzzew7ZZBM8Tt7hL8fQwObSeMKobd4IN4Ov8MMjL6rG+iJ6nDCKMgcMH6Vfnn370q7nKOrE2SnX6Us//W7Q==","signatures":[{"sig":"MEQCIAIFjZeJ2ir43Av4R9v0I6LdTeRb4IohKN1zUSf2jsSvAiBArJs8AEMEq3ayrUc400JEXeqSiPXKJqlTA6wlC/NLYw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":30203},"main":"dist/index.js","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"7a79810eddcc8caeaf2518e571dbb1527155ddc4","scripts":{"build":"tsc"},"_npmUser":{"name":"skn437","email":"skn437physx@gmail.com"},"repository":{"url":"git+https://github.com/skn437/skn-elysia-helmet.git","type":"git"},"_npmVersion":"10.9.2","description":"A comprehensive security middleware for Elysia.js applications that helps to secure your apps by setting various HTTP headers","directories":{},"_nodeVersion":"22.14.0","_hasShrinkwrap":false,"devDependencies":{"@types/bun":"^1.2.5","typescript":"^5.8.2"},"peerDependencies":{"elysia":"^1.2.25"},"_npmOperationalInternal":{"tmp":"tmp/elysia-helmet_1.0.0_1742287065486_0.07526907066319355","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@best-skn/elysia-helmet","version":"1.0.1","keywords":["elysia","elysia-plugin","bun","helmet","security","headers","cors","csp","xss","xss-protection","dns-prefetch","referrer-policy","permissions-policy","hsts","cross-origin-resource-policy","cross-origin-opener-policy"],"author":{"url":"https://skn.best","name":"SKN Shukhan","email":"skn437physx@gmail.com"},"license":"MIT","_id":"@best-skn/elysia-helmet@1.0.1","maintainers":[{"name":"skn437","email":"skn437physx@gmail.com"}],"homepage":"https://github.com/skn437/skn-elysia-helmet#readme","bugs":{"url":"https://github.com/skn437/skn-elysia-helmet/issues"},"dist":{"shasum":"a06d653148b70653f5585f463568e286b1f025a9","tarball":"https://registry.npmjs.org/@best-skn/elysia-helmet/-/elysia-helmet-1.0.1.tgz","fileCount":7,"integrity":"sha512-A7xX2unPQEhc/0C6TkAteQiPyn3zU1LtNm6IH53MGYoVGmJxoETysb/7ywZeMerZeKdsbMUV3UvT10SzLlkemg==","signatures":[{"sig":"MEQCIA249i/kr/7DsqWhDFCQJA9fpn0rB5OgVtsYb2guJak+AiBDtJSgtatZ6+j5qs+0pP9r2xpvd5w8vze8GfELe1mrsg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":30378},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"af4e381d72c34aebbf1e27f511e82b9fce34722f","scripts":{"build":"tsc"},"_npmUser":{"name":"skn437","email":"skn437physx@gmail.com"},"repository":{"url":"git+https://github.com/skn437/skn-elysia-helmet.git","type":"git"},"_npmVersion":"10.9.2","description":"A comprehensive security middleware for Elysia.js applications that helps to secure your apps by setting various HTTP headers","directories":{},"_nodeVersion":"22.14.0","_hasShrinkwrap":false,"devDependencies":{"@types/bun":"^1.2.5","typescript":"^5.8.2"},"peerDependencies":{"elysia":"^1.2.25"},"_npmOperationalInternal":{"tmp":"tmp/elysia-helmet_1.0.1_1742541712528_0.6860557751860556","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@best-skn/elysia-helmet","version":"1.0.2","keywords":["elysia","elysia-plugin","bun","helmet","security","headers","cors","csp","xss","xss-protection","dns-prefetch","referrer-policy","permissions-policy","hsts","cross-origin-resource-policy","cross-origin-opener-policy"],"author":{"url":"https://skn.best","name":"SKN Shukhan","email":"skn437physx@gmail.com"},"license":"MIT","_id":"@best-skn/elysia-helmet@1.0.2","maintainers":[{"name":"skn437","email":"skn437physx@gmail.com"}],"homepage":"https://github.com/skn437/skn-elysia-helmet#readme","bugs":{"url":"https://github.com/skn437/skn-elysia-helmet/issues"},"dist":{"shasum":"a8130391a825519c06167eea8d146ad2ffa613bc","tarball":"https://registry.npmjs.org/@best-skn/elysia-helmet/-/elysia-helmet-1.0.2.tgz","fileCount":7,"integrity":"sha512-HwETFFXo6gfVwJ3CUJFjTOuAm4rv6Xgrt0688WZ5ipflAyKEGLGztD9ncD6jWw6xeT4xOI4+5kLpI1EDU5xB6A==","signatures":[{"sig":"MEYCIQDiAHhe2pDiMbFcX0h7NzJXIPEUWpoDhGUsuo1sSP7UoQIhAPkRsuLX2mo3QVUa0uimBBOmxFuyYyv2LeVGrpq/oNav","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":30272},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"f334b1232af59ca3afa81eb9970ed36ec65f6618","scripts":{"build":"tsc"},"_npmUser":{"name":"skn437","email":"skn437physx@gmail.com"},"repository":{"url":"git+https://github.com/skn437/skn-elysia-helmet.git","type":"git"},"_npmVersion":"10.9.3","description":"A comprehensive security middleware for Elysia.js applications that helps to secure your apps by setting various HTTP headers","directories":{},"_nodeVersion":"22.20.0","_hasShrinkwrap":false,"devDependencies":{"@types/bun":"^1.2.5","typescript":"^5.8.2"},"peerDependencies":{"elysia":"^1.2.25"},"_npmOperationalInternal":{"tmp":"tmp/elysia-helmet_1.0.2_1761190506505_0.6505734731817916","host":"s3://npm-registry-packages-npm-production"}},"1.0.3":{"name":"@best-skn/elysia-helmet","description":"A comprehensive security middleware for Elysia.js applications that helps to secure your apps by setting various HTTP headers","version":"1.0.3","main":"dist/index.js","types":"dist/index.d.ts","exports":{".":{"import":"./dist/index.js","types":"./dist/index.d.ts"}},"type":"module","repository":{"type":"git","url":"git+https://github.com/skn437/skn-elysia-helmet.git"},"keywords":["elysia","elysia-plugin","bun","helmet","security","headers","cors","csp","xss","xss-protection","dns-prefetch","referrer-policy","permissions-policy","hsts","cross-origin-resource-policy","cross-origin-opener-policy"],"author":{"name":"SKN Shukhan","email":"skn437physx@gmail.com","url":"https://skn.best"},"license":"MIT","scripts":{"build":"tsc"},"devDependencies":{"@types/bun":"^1.2.5","typescript":"^5.8.2"},"peerDependencies":{"elysia":"^1.2.25"},"_id":"@best-skn/elysia-helmet@1.0.3","gitHead":"f8b099211565bc52f3a9dcf943579041432db839","bugs":{"url":"https://github.com/skn437/skn-elysia-helmet/issues"},"homepage":"https://github.com/skn437/skn-elysia-helmet#readme","_nodeVersion":"22.20.0","_npmVersion":"10.9.3","dist":{"integrity":"sha512-a3PVD6pMDkdlOayUDMQO1IDx6TdE5Ov834HMPuxlO1ffvB0+zYgKZj3WyHoU9gJeLFiNu1vl+8YpchuKFMBi2Q==","shasum":"c11b6a9fff3d978009a2e1fc37b6f021da1bab47","tarball":"https://registry.npmjs.org/@best-skn/elysia-helmet/-/elysia-helmet-1.0.3.tgz","fileCount":7,"unpackedSize":30275,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQC0aW68yv4N9xzyESzDAHuYO+V+RU4Ht8yRXeQIhd7+BwIgZneCKRTe++XKF2RwmSpIk1odfW/2ItirG6iRPovRFqY="}]},"_npmUser":{"name":"skn437","email":"skn437physx@gmail.com"},"directories":{},"maintainers":[{"name":"skn437","email":"skn437physx@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/elysia-helmet_1.0.3_1761201616963_0.13758991577953728"},"_hasShrinkwrap":false}},"time":{"created":"2025-03-18T08:37:45.381Z","modified":"2025-10-23T06:40:17.347Z","1.0.0":"2025-03-18T08:37:45.663Z","1.0.1":"2025-03-21T07:21:52.685Z","1.0.2":"2025-10-23T03:35:06.773Z","1.0.3":"2025-10-23T06:40:17.149Z"},"bugs":{"url":"https://github.com/skn437/skn-elysia-helmet/issues"},"author":{"name":"SKN Shukhan","email":"skn437physx@gmail.com","url":"https://skn.best"},"license":"MIT","homepage":"https://github.com/skn437/skn-elysia-helmet#readme","keywords":["elysia","elysia-plugin","bun","helmet","security","headers","cors","csp","xss","xss-protection","dns-prefetch","referrer-policy","permissions-policy","hsts","cross-origin-resource-policy","cross-origin-opener-policy"],"repository":{"type":"git","url":"git+https://github.com/skn437/skn-elysia-helmet.git"},"description":"A comprehensive security middleware for Elysia.js applications that helps to secure your apps by setting various HTTP headers","maintainers":[{"name":"skn437","email":"skn437physx@gmail.com"}],"readme":"# SKN Elysia.js Helmet\n\n<p align=\"center\">\n  <a href=\"https://elysiajs.com\" target=\"_blank\">\n  <img width=\"150px\" src=\"https://firebasestorage.googleapis.com/v0/b/skn-ultimate-project-la437.appspot.com/o/GitHub%20Library%2F17-TypeScript-SEH.svg?alt=media&token=4eec4531-56a3-452d-b005-5f2725d16641\" alt=\"Elysia Helmet\" />\n  </a>\n</p>\n\n> TypeScript\n\n[![NPM Version](https://img.shields.io/npm/v/%40best-skn%2Felysia-helmet)](https://www.npmjs.com/package/@best-skn/elysia-helmet) [![MIT License](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/license/mit)\n\n&nbsp;\n\n## **_Introduction:_**\n\n### A comprehensive security middleware for Elysia.js applications that helps to secure your apps by setting various HTTP headers\n\n### This library is originally created by [aashahin](https://github.com/aashahin). Total logic has been written by him. His original repository is [Elysia Helmet](https://github.com/aashahin/elysiajs-helmet). I just exported some types so that it can be imported in separate files while using this library and also added an object holding some readonly properties related to security configurations\n\n### I created this library so that I can manage it all by myself and I don't have to rely on [aashahin](https://github.com/aashahin)\n\n&nbsp;\n\n## **_Features:_**\n\n- 🛡️ Content Security Policy (CSP)\n- 🔒 X-Frame-Options protection\n- 🚫 XSS Protection\n- 🌐 DNS Prefetch Control\n- 📜 Referrer Policy\n- 🔑 Permissions Policy\n- 🔐 HTTP Strict Transport Security (HSTS)\n- 🌍 Cross-Origin Resource Policy (CORP)\n- 🚪 Cross-Origin Opener Policy (COOP)\n- 📝 Report-To header configuration\n- ✨ Custom headers support\n\n&nbsp;\n\n## **_Details:_**\n\n### **`ReportToConfig` Interface**\n\n- Configuration interface for Report-To header\n- For usage instruction, see `Usage` section\n\n### **`CSPConfig` Interface**\n\n- Configuration interface for Content Security Policy\n- For usage instruction, see `Usage` section\n\n### **`HSTSConfig` Interface**\n\n- Configuration inerface for HTTP Strict Transport Security\n- For usage instruction, see `Usage` section\n\n### **`SecurityConfig` Interface**\n\n- Configuration interface for Security Headers\n- For usage instruction, see `Usage` section\n\n### **`permission` Object**\n\n- An object containing permission related constants for some security configurations\n- For usage instruction, see `Usage` section\n\n### **`elysiaHelmet` Function**\n\n- Creates an Elysia middleware that adds security headers to all responses\n- Optimized for performance with minimal object spread operations\n- For usage instruction, see `Usage` section\n\n&nbsp;\n\n## **_Use Case:_**\n\n- Elysia.js\n\n&nbsp;\n\n## **_Requirements:_**\n\n### This library has peer dependency for Elysia.js 1.2.25. It may or may not work on 2.x\n\n- 💀 Minimum [elysia](https://www.npmjs.com/package/elysia) Version: `1.2.25`\n\n&nbsp;\n\n## **_Usage:_**\n\n### To install the package, type the following in console\n\n> ```zsh\n> npm add @best-skn/elysia-helmet\n> #or\n> yarn add @best-skn/elysia-helmet\n> #or\n> pnpm add @best-skn/elysia-helmet\n> #or\n> bun add @best-skn/elysia-helmet\n> ```\n\n### Basic Usage\n\n```typescript\nimport { Elysia } from \"elysia\";\nimport { elysiaHelmet } from \"@best-skn/elysia-helmet\";\n\nconst app = new Elysia()\n  .use(elysiaHelmet({}))\n  .get(\"/\", () => \"Hello, Secure World!\")\n  .listen(3000);\n```\n\n> **Note**: Production mode is automatically enabled when `NODE_ENV` is set to `'production'`. In production mode, additional security measures are enforced.\n\n### Advanced Configuration\n\n```typescript\nimport { Elysia } from \"elysia\";\nimport { elysiaHelmet, permission } from \"@best-skn/elysia-helmet\";\n\nconst app = new Elysia()\n  .use(\n    elysiaHelmet({\n      csp: {\n        defaultSrc: [permission.SELF],\n        scriptSrc: [permission.SELF, permission.UNSAFE_INLINE],\n        styleSrc: [permission.SELF, permission.UNSAFE_INLINE],\n        imgSrc: [permission.SELF, permission.DATA, permission.HTTPS],\n        useNonce: true,\n      },\n      hsts: {\n        maxAge: 31536000,\n        includeSubDomains: true,\n        preload: true,\n      },\n      frameOptions: \"DENY\",\n      referrerPolicy: \"strict-origin-when-cross-origin\",\n      permissionsPolicy: {\n        camera: [permission.NONE],\n        microphone: [permission.NONE],\n      },\n    })\n  )\n  .listen(3000);\n```\n\n### Types Usage\n\n```typescript\nimport type { CSPConfig, HSTSConfig, ReportToConfig, SecurityConfig } from \"@best-skn/elysia-helmet\";\n```\n\n#### These types are extremely useful if you want to define configurations in separate files\n\n#### See `Configuration Options` below to get the type info\n\n### Configuration Options\n\n#### Content Security Policy (CSP)\n\n```typescript\nexport interface CSPConfig {\n  /** Default source directive */\n  defaultSrc?: string[];\n  /** Script source directive */\n  scriptSrc?: string[];\n  /** Style source directive */\n  styleSrc?: string[];\n  /** Image source directive */\n  imgSrc?: string[];\n  /** Font source directive */\n  fontSrc?: string[];\n  /** Connect source directive */\n  connectSrc?: string[];\n  /** Frame source directive */\n  frameSrc?: string[];\n  /** Object source directive */\n  objectSrc?: string[];\n  /** Base URI directive */\n  baseUri?: string[];\n  /** Report URI directive */\n  reportUri?: string;\n  /** Use nonce for script and style tags */\n  useNonce?: boolean;\n  /** Report-only mode */\n  reportOnly?: boolean;\n}\n```\n\n#### HSTS Configuration\n\n```typescript\nexport interface HSTSConfig {\n  /** Maximum age */\n  maxAge?: number;\n  /** Include sub-domains */\n  includeSubDomains?: boolean;\n  /** Preload */\n  preload?: boolean;\n}\n```\n\n#### Report-To Configuration\n\n```typescript\nexport interface ReportToConfig {\n  /** Group name for the endpoint */\n  group: string;\n  /** Maximum age of the endpoint configuration (in seconds) */\n  maxAge: number;\n  /** Endpoints to send reports to */\n  endpoints: Array<{\n    url: string;\n    priority?: number;\n    weight?: number;\n  }>;\n  /** Include subdomains in reporting */\n  includeSubdomains?: boolean;\n}\n```\n\n#### Security Configuration\n\n```typescript\nexport interface SecurityConfig {\n  /** Content Security Policy configuration */\n  csp?: CSPConfig;\n  /** Enable or disable X-Frame-Options (DENY, SAMEORIGIN, ALLOW-FROM) */\n  frameOptions?: \"DENY\" | \"SAMEORIGIN\" | \"ALLOW-FROM\";\n  /** Enable or disable XSS Protection */\n  xssProtection?: boolean;\n  /** Enable or disable DNS Prefetch Control */\n  dnsPrefetch?: boolean;\n  /** Configure Referrer Policy */\n  referrerPolicy?:\n    | \"no-referrer\"\n    | \"no-referrer-when-downgrade\"\n    | \"origin\"\n    | \"origin-when-cross-origin\"\n    | \"same-origin\"\n    | \"strict-origin\"\n    | \"strict-origin-when-cross-origin\"\n    | \"unsafe-url\";\n  /** Configure Permissions Policy */\n  permissionsPolicy?: Record<string, string[]>;\n  /** Configure HSTS (HTTP Strict Transport Security) */\n  hsts?: HSTSConfig;\n  /** Enable or disable Cross-Origin Resource Policy */\n  corp?: \"same-origin\" | \"same-site\" | \"cross-origin\";\n  /** Enable or disable Cross-Origin Opener Policy */\n  coop?: \"unsafe-none\" | \"same-origin-allow-popups\" | \"same-origin\";\n  /** Configure Report-To header */\n  reportTo?: ReportToConfig[];\n  /** Custom headers to add */\n  customHeaders?: Record<string, string>;\n}\n```\n\n#### Permission Configuration\n\n```typescript\nexport const permission = {\n  /** Source: Self allowed */\n  SELF: \"'self'\",\n  /** Source: Unsafe Inline allowed */\n  UNSAFE_INLINE: \"'unsafe-inline'\",\n  /** Source: HTTPS allowed */\n  HTTPS: \"https:\",\n  /** Source: Data allowed */\n  DATA: \"data:\",\n  /** Source: None is allowed */\n  NONE: \"'none'\",\n  /** Source: Blob allowed */\n  BLOB: \"blob:\",\n} as const;\n```\n\n### Default Configuration\n\nThe middleware comes with secure defaults:\n\n- CSP with `'self'` as default source\n- Frame options set to `DENY`\n- XSS Protection enabled\n- DNS Prefetch Control disabled\n- Strict Referrer Policy\n- And more secure defaults\n\nYou can override any of these defaults by passing your own configuration.\n\n&nbsp;\n\n## **_Dedicated To:_**\n\n- 👩‍🎨`Prodipta Das Logno` & 🧛‍♀️`Atoshi Sarker Prithula`: The two most special ladies of my life. My best wishes will always be with you two. May you two always be happy.\n- 💯`My Parents`: The greatest treasures of my life ever.\n\n&nbsp;\n\n## **_License:_**\n\nCopyright (C) 2024 SKN Shukhan\n\nLicensed under the MIT License\n\n&nbsp;\n\n## **_Credits:_**\n\n- All credits for building the logic goes to [aashahin](https://github.com/aashahin)\n","readmeFilename":"README.md"}