{"_id":"@bozorgwar/express-rate-limit","name":"@bozorgwar/express-rate-limit","dist-tags":{"latest":"1.0.1"},"versions":{"1.0.1":{"name":"@bozorgwar/express-rate-limit","version":"1.0.1","description":"Basic IP rate-limiting middleware for Express. This is a fork with additional fixes and improvements for IPv6 subnet validation, levenshtein suggestions, and more.","author":{"name":"bozorgwar","url":"https://github.com/bozorgwar"},"license":"MIT","homepage":"https://github.com/bozorgwar/express-rate-limit","repository":{"type":"git","url":"git+https://github.com/bozorgwar/express-rate-limit.git"},"keywords":["bozorgwar","express-rate-limit","express","rate","limit","ratelimit","rate-limit","middleware","ip","auth","authorization","security","brute","force","bruteforce","brute-force","attack"],"type":"module","exports":{".":{"import":{"types":"./dist/index.d.mts","default":"./dist/index.mjs"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}}},"main":"./dist/index.cjs","module":"./dist/index.mjs","types":"./dist/index.d.ts","engines":{"node":">= 16"},"scripts":{"clean":"del-cli dist/ coverage/ *.log *.tmp *.bak *.tgz","build:cjs":"esbuild --packages=external --platform=node --bundle --target=es2022 --format=cjs --outfile=dist/index.cjs --footer:js=\"module.exports = Object.assign(rateLimit, module.exports);\" source/index.ts","build:esm":"esbuild --packages=external --platform=node --bundle --target=es2022 --format=esm --outfile=dist/index.mjs source/index.ts","build:types":"dts-bundle-generator --out-file=dist/index.d.ts source/index.ts && copy dist\\index.d.ts dist\\index.d.cts && copy dist\\index.d.ts dist\\index.d.mts","compile":"run-s clean build:*","docs":"cd docs && mintlify dev","lint:code":"biome check","lint:docs":"prettier --check docs/ *.md","lint":"run-s lint:*","format:code":"biome check --write","format:docs":"prettier --write docs/ *.md","format":"run-s format:*","test:lib":"jest","test:ext":"cd test/external/ && bash run-all-tests","test":"run-s lint test:lib","format-test":"run-s format test:lib","pre-commit":"lint-staged","prepare":"run-s compile && husky"},"dependencies":{"ip-address":"^10.2.0"},"peerDependencies":{"express":">= 4.11"},"devDependencies":{"@biomejs/biome":"2.4.6","@express-rate-limit/prettier":"1.1.1","@express-rate-limit/tsconfig":"1.0.5","@jest/globals":"27.5.1","@types/express":"5.0.6","@types/jest":"30.0.0","@types/node":"25.9.2","@types/supertest":"7.2.0","del-cli":"7.0.0","dts-bundle-generator":"8.1.2","esbuild":"0.28.1","express":"5.2.1","husky":"9.1.7","jest":"25.0.0","lint-staged":"17.0.7","mintlify":"4.2.216","npm-run-all":"4.1.5","prettier":"3.8.4","ratelimit-header-parser":"0.1.0","supertest":"7.2.2","ts-jest":"29.1.2","ts-node":"10.9.2","typescript":"5.9.3"},"prettier":"@express-rate-limit/prettier","lint-staged":{"*.{js,ts,json}":"biome check --write","*.{md,yaml}":"prettier --write"},"gitHead":"4c0b5e9c9a666d9a6d45520f5575fa28a762f9e5","_id":"@bozorgwar/express-rate-limit@1.0.1","bugs":{"url":"https://github.com/bozorgwar/express-rate-limit/issues"},"_nodeVersion":"26.3.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-TW3EBGCOtDP1/pN17NGDZp25BycypAG1+3P8GiVgaCLvvVjiT4c1mreq5z56j8kx8Adyr7Ll67UPgL+nc7C59w==","shasum":"609322a50bb6e0091765a39f20d77d6b8fe71727","tarball":"https://registry.npmjs.org/@bozorgwar/express-rate-limit/-/express-rate-limit-1.0.1.tgz","fileCount":9,"unpackedSize":145744,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCpBSZypW6wejqg15ti5Mq/jLNAf1euyl1h73v3EEhoEgIgBXek87GwNrf1Jb88vi64hNVZXPPkxqYOl3xSHTgqXVc="}]},"_npmUser":{"name":"bozorgwar","email":"ursa553@proton.me"},"directories":{},"maintainers":[{"name":"bozorgwar","email":"ursa553@proton.me"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/express-rate-limit_1.0.1_1781620131958_0.27483683920193935"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-16T14:28:51.804Z","1.0.1":"2026-06-16T14:28:52.106Z","modified":"2026-06-16T14:28:52.311Z"},"maintainers":[{"name":"bozorgwar","email":"ursa553@proton.me"}],"description":"Basic IP rate-limiting middleware for Express. This is a fork with additional fixes and improvements for IPv6 subnet validation, levenshtein suggestions, and more.","homepage":"https://github.com/bozorgwar/express-rate-limit","keywords":["bozorgwar","express-rate-limit","express","rate","limit","ratelimit","rate-limit","middleware","ip","auth","authorization","security","brute","force","bruteforce","brute-force","attack"],"repository":{"type":"git","url":"git+https://github.com/bozorgwar/express-rate-limit.git"},"author":{"name":"bozorgwar","url":"https://github.com/bozorgwar"},"bugs":{"url":"https://github.com/bozorgwar/express-rate-limit/issues"},"license":"MIT","readme":"markdown\n<h1 align=\"center\"> <code>@bozorgwar/express-rate-limit</code> </h1>\n\n<div align=\"center\">\n\n[![tests](https://img.shields.io/github/actions/workflow/status/bozorgwar/express-rate-limit/ci.yaml)](https://github.com/bozorgwar/express-rate-limit/actions/workflows/ci.yaml)\n[![npm version](https://img.shields.io/npm/v/@bozorgwar/express-rate-limit.svg)](https://npmjs.org/package/@bozorgwar/express-rate-limit)\n[![npm downloads](https://img.shields.io/npm/dm/@bozorgwar/express-rate-limit)](https://www.npmjs.com/package/@bozorgwar/express-rate-limit)\n[![license](https://img.shields.io/npm/l/@bozorgwar/express-rate-limit)](license.md)\n\n</div>\n\n> **📢 This is a fork of [express-rate-limit](https://github.com/express-rate-limit/express-rate-limit) with additional fixes and improvements.**\n\nBasic rate-limiting middleware for [Express](http://expressjs.com/). Use to\nlimit repeated requests to public APIs and/or endpoints such as password reset.\n\n## 🔧 Changes in this fork\n\nThis fork includes the following improvements over the original package:\n\n- ✅ **Fixed `ipv6Subnet` validation range** – Now supports values from `1` to `120` (was limited to `32-64`), allowing more flexible IPv6 subnet configurations.\n- ✅ **Added `levenshteinDistance` for smart suggestions** – When you mistype an option (e.g., `windowMS` instead of `windowMs`), the error message now suggests the correct option.\n- ✅ **Improved `knownOptions` validation** – Uses Levenshtein distance to suggest the closest valid option when an unknown option is provided.\n- ✅ **Fixed `creationStack` validation** – Removed the conditional `localKeys` check, so the validation always throws an error when the rate limiter is created inside a request handler (preventing memory leaks).\n- ✅ **Added `windowMs` validation in `parseOptions`** – Validates `windowMs` during configuration parsing for MemoryStore, catching errors earlier.\n- ✅ **Fixed `RateLimit-Reset` header in `setDraft6Headers`** – Now the header is only set when the store actually provides a `resetTime`, as per the draft-6 specification.\n- ✅ **Exported `rawValidations`** – Allows advanced testing with validations that throw errors directly (without wrapping in try/catch).\n\n## Usage\n\n```ts\nimport { rateLimit } from '@bozorgwar/express-rate-limit'\n\nconst limiter = rateLimit({\n\twindowMs: 15 * 60 * 1000, // 15 minutes\n\tlimit: 100, // Limit each IP to 100 requests per `window` (here, per 15 minutes).\n\tstandardHeaders: 'draft-8',\n\tlegacyHeaders: false,\n\tipv6Subnet: 56, // Now supports any value between 1 and 120!\n})\n\napp.use(limiter)\nInstallation\nbash\nnpm install @bozorgwar/express-rate-limit\nData Stores\nThe rate limiter comes with a built-in memory store, and supports a variety of\nexternal data stores.\n\nConfiguration\nAll function options may be async. Click the name for additional info and\ndefault values.\n\nOption\tType\tRemarks\n[`windowMs`]\tnumber\tHow long to remember requests for, in milliseconds.\n[`limit`]\tnumber | function\tHow many requests to allow.\n[`message`]\tstring | json | function\tResponse to return after limit is reached.\n[`statusCode`]\tnumber\tHTTP status code after limit is reached (default is 429).\n[`handler`]\tfunction\tFunction to run after limit is reached (overrides message and statusCode settings, if set).\n[`legacyHeaders`]\tboolean\tEnable the X-Rate-Limit header.\n[`standardHeaders`]\t'draft-6' | 'draft-7' | 'draft-8'\tEnable the Ratelimit header.\n[`identifier`]\tstring | function\tName associated with the quota policy enforced by this rate limiter.\n[`store`]\tStore\tUse a custom store to share hit counts across multiple nodes.\n[`passOnStoreError`]\tboolean\tAllow (true) or block (false, default) traffic if the store becomes unavailable.\n[`keyGenerator`]\tfunction\tIdentify users (defaults to IP address).\n[`ipv6Subnet`]\tnumber (1-120) | function | false\tHow many bits of IPv6 addresses to use in default keyGenerator (now supports 1-120!)\n[`requestPropertyName`]\tstring\tAdd rate limit info to the req object.\n[`skip`]\tfunction\tReturn true to bypass the limiter for the given request.\n[`skipSuccessfulRequests`]\tboolean\tUncount 1xx/2xx/3xx responses.\n[`skipFailedRequests`]\tboolean\tUncount 4xx/5xx responses.\n[`requestWasSuccessful`]\tfunction\tUsed by skipSuccessfulRequests and skipFailedRequests.\n[`validate`]\tboolean | object\tEnable or disable built-in validation checks.\n[`logger`]\tLogger\tCustom logger\nIssues and Contributing\nIf you encounter a bug or want to see something added/changed, please go ahead\nand open an issue!\nIf you need help with something, feel free to\nstart a discussion!\n\nThank You\nThanks to the original authors (Nathan Friedly, Vedant K) for creating this excellent package, and to Mintlify for hosting the documentation at\nexpress-rate-limit.mintlify.app\n\n<p align=\"center\"> <a href=\"https://mintlify.com/?utm_campaign=devmark&utm_medium=readme&utm_source=express-rate-limit\"> <img height=\"75\" src=\"https://devmark-public-assets.s3.us-west-2.amazonaws.com/sponsorships/mintlify.svg\" alt=\"Create your docs today\"> </a> </p>\nLicense\nMIT © bozorgwar (this fork)\nOriginal work © Nathan Friedly, Vedant K\n\n[`windowMs`]:\n\thttps://express-rate-limit.mintlify.app/reference/configuration#windowms\n[`limit`]: https://express-rate-limit.mintlify.app/reference/configuration#limit\n[`message`]:\n\thttps://express-rate-limit.mintlify.app/reference/configuration#message\n[`statusCode`]:\n\thttps://express-rate-limit.mintlify.app/reference/configuration#statuscode\n[`handler`]:\n\thttps://express-rate-limit.mintlify.app/reference/configuration#handler\n[`legacyHeaders`]:\n\thttps://express-rate-limit.mintlify.app/reference/configuration#legacyheaders\n[`standardHeaders`]:\n\thttps://express-rate-limit.mintlify.app/reference/configuration#standardheaders\n[`identifier`]:\n\thttps://express-rate-limit.mintlify.app/reference/configuration#identifier\n[`store`]: https://express-rate-limit.mintlify.app/reference/configuration#store\n[`passOnStoreError`]:\n\thttps://express-rate-limit.mintlify.app/reference/configuration#passonstoreerror\n[`keyGenerator`]:\n\thttps://express-rate-limit.mintlify.app/reference/configuration#keygenerator\n[`ipv6Subnet`]:\n\thttps://express-rate-limit.mintlify.app/reference/configuration#ipv6subnet\n[`requestPropertyName`]:\n\thttps://express-rate-limit.mintlify.app/reference/configuration#requestpropertyname\n[`skip`]: https://express-rate-limit.mintlify.app/reference/configuration#skip\n[`skipSuccessfulRequests`]:\n\thttps://express-rate-limit.mintlify.app/reference/configuration#skipsuccessfulrequests\n[`skipFailedRequests`]:\n\thttps://express-rate-limit.mintlify.app/reference/configuration#skipfailedrequests\n[`requestWasSuccessful`]:\n\thttps://express-rate-limit.mintlify.app/reference/configuration#requestwassuccessful\n[`validate`]:\n\thttps://express-rate-limit.mintlify.app/reference/configuration#validate\n[`logger`]:\n\thttps://express-rate-limit.mintlify.app/reference/configuration#logger","readmeFilename":"readme.md","_rev":"1-13fc3eef1a662b26ba76c3ad6ce12dda"}