{"_id":"@bozorgwar/express-slow-down-fixed","name":"@bozorgwar/express-slow-down-fixed","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@bozorgwar/express-slow-down-fixed","version":"1.0.0","description":"Basic IP rate-limiting middleware for Express that slows down responses rather than blocking the user.","homepage":"https://github.com/express-rate-limit/express-slow-down","author":{"name":"Nathan Friedly","url":"http://nfriedly.com/"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/express-rate-limit/express-slow-down.git"},"keywords":["express-rate-limit","express","rate","limit","ratelimit","rate-limit","middleware","ip","auth","authorization","security","brute","force","bruteforce","brute-force","attack"],"type":"module","exports":{".":{"import":{"types":"./dist/index.d.mts","default":"./dist/index.mjs"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}}},"main":"dist/index.cjs","module":"./dist/index.mjs","types":"./dist/index.d.ts","engines":{"node":">= 16"},"scripts":{"clean":"del-cli dist/ coverage/ *.log *.tmp *.bak *.tgz","build:cjs":"esbuild --platform=node --bundle --target=es2022 --packages=external --format=cjs --outfile=dist/index.cjs --footer:js=\"module.exports = slowDown; module.exports.default = slowDown; module.exports.slowDown = slowDown; \" source/index.ts","build:esm":"esbuild --platform=node --bundle --target=es2022 --packages=external --format=esm --outfile=dist/index.mjs source/index.ts","build:types":"dts-bundle-generator --out-file=dist/index.d.ts source/index.ts && shx cp dist/index.d.ts dist/index.d.cts && shx cp dist/index.d.ts dist/index.d.mts","compile":"run-s clean build:*","lint:code":"xo","lint:rest":"prettier --check .","lint":"run-s lint:*","format:code":"xo --fix","format:rest":"prettier --write .","format":"run-s format:*","test:lib":"jest test/library/","test:int":"jest test/integration/","test":"run-s lint test:*","pre-commit":"lint-staged","prepare":"run-s compile && husky install config/husky"},"peerDependencies":{"express":"4 || 5 || ^5.0.0-beta.1"},"dependencies":{"express-rate-limit":"8"},"devDependencies":{"@express-rate-limit/prettier":"1.1.1","@express-rate-limit/tsconfig":"1.0.2","@jest/globals":"29.7.0","@types/express":"4.17.18","@types/jest":"29.5.5","@types/supertest":"2.0.12","body-parser":"1.20.5","del-cli":"5.1.0","dts-bundle-generator":"8.0.1","esbuild":"0.28.1","express":"4.22.2","husky":"8.0.3","jest":"29.7.0","jest-expect-message":"1.1.3","lint-staged":"16.1.2","npm-run-all":"4.1.5","prettier":"3.0.3","supertest":"6.3.3","ts-jest":"29.1.1","typescript":"5.2.2","xo":"0.56.0"},"xo":{"prettier":true,"rules":{"@typescript-eslint/prefer-nullish-coalescing":["error",{"ignoreConditionalTests":true}],"@typescript-eslint/no-confusing-void-expression":0,"@typescript-eslint/consistent-indexed-object-style":["error","index-signature"],"unicorn/prefer-string-replace-all":0},"overrides":[{"files":"test/**/*.ts","rules":{"@typescript-eslint/no-unsafe-argument":0,"@typescript-eslint/no-unsafe-assignment":0,"@typescript-eslint/no-unsafe-call":0,"@typescript-eslint/no-unsafe-return":0,"@typescript-eslint/no-empty-function":0,"import/no-named-as-default":0,"unicorn/prefer-event-target":0,"unicorn/prevent-abbreviations":0}}]},"prettier":"@express-rate-limit/prettier","lint-staged":{"{source,test}/**/*.ts":"xo --fix","**/*.{json,yaml,md}":"prettier --write"},"gitHead":"69327b12d57147b35abd7913c8c38a0b6959a85a","_id":"@bozorgwar/express-slow-down-fixed@1.0.0","bugs":{"url":"https://github.com/express-rate-limit/express-slow-down/issues"},"_nodeVersion":"26.3.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-hwmfqzFMnqfwJIPVX6zElmmO5pbEy/EEsKkhtic5UZaIV0asJ3sZF9TXF7KXKrMly9fEBpTivTq5cpZavIVVzg==","shasum":"2e5c20a8fbed2f1364b5d070b072ae073c95c9c1","tarball":"https://registry.npmjs.org/@bozorgwar/express-slow-down-fixed/-/express-slow-down-fixed-1.0.0.tgz","fileCount":10,"unpackedSize":34768,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCa3cLBiXrf07DbtG0uJd/qRBCsPqfNiWFHC1as07NukQIhALMssPnnSSHcRe/vcEyRF3ctt1UE+cjm1GHlOEc2U5Vb"}]},"_npmUser":{"name":"bozorgwar","email":"ursa553@proton.me"},"directories":{},"maintainers":[{"name":"bozorgwar","email":"ursa553@proton.me"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/express-slow-down-fixed_1.0.0_1781482121401_0.6933933136137853"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-15T00:08:41.196Z","1.0.0":"2026-06-15T00:08:41.550Z","modified":"2026-06-15T00:08:41.773Z"},"maintainers":[{"name":"bozorgwar","email":"ursa553@proton.me"}],"description":"Basic IP rate-limiting middleware for Express that slows down responses rather than blocking the user.","homepage":"https://github.com/express-rate-limit/express-slow-down","keywords":["express-rate-limit","express","rate","limit","ratelimit","rate-limit","middleware","ip","auth","authorization","security","brute","force","bruteforce","brute-force","attack"],"repository":{"type":"git","url":"git+https://github.com/express-rate-limit/express-slow-down.git"},"author":{"name":"Nathan Friedly","url":"http://nfriedly.com/"},"bugs":{"url":"https://github.com/express-rate-limit/express-slow-down/issues"},"license":"MIT","readme":"# <div align=\"center\"> Express Slow Down </div>\n\n<div align=\"center\">\n\n[![tests](https://github.com/express-rate-limit/express-slow-down/actions/workflows/ci.yaml/badge.svg)](https://github.com/express-rate-limit/express-slow-down/actions/workflows/ci.yaml)\n[![npm version](https://img.shields.io/npm/v/express-slow-down.svg)](https://npmjs.org/package/express-slow-down 'View this project on NPM')\n[![npm downloads](https://img.shields.io/npm/dm/express-slow-down)](https://www.npmjs.com/package/express-slow-down)\n\nBasic rate-limiting middleware for Express that slows down responses rather than\nblocking them outright. Use to slow repeated requests to public APIs and/or\nendpoints such as password reset.\n\nPlays nice with (and built on top of)\n[Express Rate Limit](https://npmjs.org/package/express-rate-limit)\n\n</div>\n\n### Stores\n\nThe default memory store does not share state with any other processes or\nservers. It's sufficient for basic abuse prevention, but an external store will\nprovide more consistency.\n\nexpress-slow-down uses\n[express-rate-limit's stores](https://express-rate-limit.mintlify.app/reference/stores)\n\n> **Note**: when using express-slow-down and express-rate-limit with an external\n> store, you'll need to create two instances of the store and provide different\n> prefixes so that they don't double-count requests.\n\n## Installation\n\nFrom the npm registry:\n\n```sh\n# Using npm\n> npm install express-slow-down\n# Using yarn or pnpm\n> yarn/pnpm add express-slow-down\n```\n\nFrom Github Releases:\n\n```sh\n# Using npm\n> npm install https://github.com/express-rate-limit/express-slow-down/releases/download/v{version}/express-slow-down.tgz\n# Using yarn or pnpm\n> yarn/pnpm add https://github.com/express-rate-limit/express-slow-down/releases/download/v{version}/express-slow-down.tgz\n```\n\nReplace `{version}` with the version of the package that you want to your, e.g.:\n`2.0.0`.\n\n## Usage\n\n### Importing\n\nThis library is provided in ESM as well as CJS forms, and works with both\nJavascript and Typescript projects.\n\n**This package requires you to use Node 16 or above.**\n\nImport it in a CommonJS project (`type: commonjs` or no `type` field in\n`package.json`) as follows:\n\n```ts\nconst { slowDown } = require('express-slow-down')\n```\n\nImport it in a ESM project (`type: module` in `package.json`) as follows:\n\n```ts\nimport { slowDown } from 'express-slow-down'\n```\n\n### Examples\n\nTo use it in an API-only server where the speed-limiter should be applied to all\nrequests:\n\n```ts\nimport { slowDown } from 'express-slow-down'\n\nconst limiter = slowDown({\n\twindowMs: 15 * 60 * 1000, // 15 minutes\n\tdelayAfter: 5, // Allow 5 requests per 15 minutes.\n\tdelayMs: (hits) => hits * 100, // Add 100 ms of delay to every request after the 5th one.\n\n\t/**\n\t * So:\n\t *\n\t * - requests 1-5 are not delayed.\n\t * - request 6 is delayed by 600ms\n\t * - request 7 is delayed by 700ms\n\t * - request 8 is delayed by 800ms\n\t *\n\t * and so on. After 15 minutes, the delay is reset to 0.\n\t */\n})\n\n// Apply the delay middleware to all requests.\napp.use(limiter)\n```\n\nTo use it in a 'regular' web server (e.g. anything that uses\n`express.static()`), where the rate-limiter should only apply to certain\nrequests:\n\n```ts\nimport { slowDown } from 'express-slow-down'\n\nconst apiLimiter = slowDown({\n\twindowMs: 15 * 60 * 1000, // 15 minutes\n\tdelayAfter: 1, // Allow only one request to go at full-speed.\n\tdelayMs: (hits) => hits * hits * 1000, // 2nd request has a 4 second delay, 3rd is 9 seconds, 4th is 16, etc.\n})\n\n// Apply the delay middleware to API calls only.\napp.use('/api', apiLimiter)\n```\n\nTo use a custom store:\n\n```ts\nimport { slowDown } from 'express-slow-down'\nimport { MemcachedStore } from 'rate-limit-memcached'\n\nconst speedLimiter = slowDown({\n\twindowMs: 15 * 60 * 1000, // 15 minutes\n\tdelayAfter: 1, // Allow only one request to go at full-speed.\n\tdelayMs: (hits) => hits * hits * 1000, // Add exponential delay after 1 request.\n\tstore: new MemcachedStore({\n\t\t/* ... */\n\t}), // Use the external store\n})\n\n// Apply the rate limiting middleware to all requests.\napp.use(speedLimiter)\n```\n\n> **Note:** most stores will require additional configuration, such as custom\n> prefixes, when using multiple instances. The default built-in memory store is\n> an exception to this rule.\n\n## Configuration\n\n### [`windowMs`](https://express-rate-limit.mintlify.app/reference/configuration#windowms)\n\n> `number`\n\nTime frame for which requests are checked/remembered.\n\nNote that some stores have to be passed the value manually, while others infer\nit from the options passed to this middleware.\n\nDefaults to `60000` ms (= 1 minute).\n\n### `delayAfter`\n\n> `number` | `function`\n\nThe max number of requests allowed during `windowMs` before the middleware\nstarts delaying responses. Can be the limit itself as a number or a (sync/async)\nfunction that accepts the Express `req` and `res` objects and then returns a\nnumber.\n\nDefaults to `1`.\n\nAn example of using a function:\n\n```ts\nconst isPremium = async (user) => {\n\t// ...\n}\n\nconst limiter = slowDown({\n\t// ...\n\tdelayAfter: async (req, res) => {\n\t\tif (await isPremium(req.user)) return 10\n\t\telse return 1\n\t},\n})\n```\n\n### `delayMs`\n\n> `number | function`\n\nThe delay to apply to each request once the limit is reached. Can be the delay\nitself (in milliseconds) as a number or a (sync/async) function that accepts a\nnumber (number of requests in the current window), the Express `req` and `res`\nobjects and then returns a number.\n\nBy default, it increases the delay by 1 second for every request over the limit:\n\n```ts\nconst limiter = slowDown({\n\t// ...\n\tdelayMs: (used) => (used - delayAfter) * 1000,\n})\n```\n\n### `maxDelayMs`\n\n> `number | function`\n\nThe absolute maximum value for `delayMs`. After many consecutive attempts, the\ndelay will always be this value. This option should be used especially when your\napplication is running behind a load balancer or reverse proxy that has a\nrequest timeout. Can be the number itself (in milliseconds) or a (sync/async)\nfunction that accepts the Express `req` and `res` objects and then returns a\nnumber.\n\nDefaults to `Infinity`.\n\nFor example, for the following configuration:\n\n```ts\nconst limiter = slowDown({\n\t// ...\n\tdelayAfter: 1,\n\tdelayMs: (hits) => hits * 1000,\n\tmaxDelayMs: 4000,\n})\n```\n\nThe first request will have no delay. The second will have a 2 second delay, the\n3rd will have a 3 second delay, but the fourth, fifth, sixth, seventh and so on\nrequests will all have a 4 second delay.\n\n### Options from [`express-rate-limit`](https://github.com/express-rate-limit/express-rate-limit)\n\nBecause\n[`express-rate-limit`](https://github.com/express-rate-limit/express-rate-limit)\nis used internally, additional options that it supports may be passed in. Some\nof them are listed below; see `express-rate-limit`'s\n[documentation](https://express-rate-limit.mintlify.app/reference/configuration)\nfor the complete list.\n\n> **Note**: The `limit` (`max`) option is not supported (use `delayAfter`\n> instead), nor is the `handler` option.\n\n- [`standardHeaders`](https://express-rate-limit.mintlify.app/reference/configuration#standardheaders)\n- [`legacyHeaders`](https://express-rate-limit.mintlify.app/reference/configuration#legacyheaders)\n- [`requestPropertyName`](https://express-rate-limit.mintlify.app/reference/configuration#requestpropertyname)\n- [`skipFailedRequests`](https://express-rate-limit.mintlify.app/reference/configuration#skipfailedrequests)\n- [`skipSuccessfulRequests`](https://express-rate-limit.mintlify.app/reference/configuration#skipsuccessfulrequests)\n- [`keyGenerator`](https://express-rate-limit.mintlify.app/reference/configuration#keygenerator)\n- [`ipv6Subnet`](https://express-rate-limit.mintlify.app/reference/configuration#ipv6subnet)\n- [`skip`](https://express-rate-limit.mintlify.app/reference/configuration#skip)\n- [`requestWasSuccessful`](https://express-rate-limit.mintlify.app/reference/configuration#requestwassuccessful)\n- [`validate`](https://express-rate-limit.mintlify.app/reference/configuration#validate)\n- [`store`](https://express-rate-limit.mintlify.app/reference/configuration#store)\n\n## Request API\n\nA `req.slowDown` property is added to all requests with the `limit`, `used`, and\n`remaining` number of requests and, if the store provides it, a `resetTime` Date\nobject. It also has the `delay` property, which is the amount of delay imposed\non current request (milliseconds). These may be used in your application code to\ntake additional actions or inform the user of their status.\n\nNote that `used` includes the current request, so it should always be > 0.\n\nThe property name can be configured with the configuration option\n`requestPropertyName`.\n\n## Issues and Contributing\n\nIf you encounter a bug or want to see something added/changed, please go ahead\nand\n[open an issue](https://github.com/express-rate-limit/express-slow-down/issues/new)!\nIf you need help with something, feel free to\n[start a discussion](https://github.com/express-rate-limit/express-slow-down/discussions/new)!\n\nIf you wish to contribute to the library, thanks! First, please read\n[the contributing guide](contributing.md). Then you can pick up any issue and\nfix/implement it!\n\n## License\n\nMIT © [Nathan Friedly](http://nfriedly.com/),\n[Vedant K](https://github.com/gamemaker1)\n","readmeFilename":"readme.md","_rev":"1-0fc02b643f05c4cb7086677c8106fa8b"}