{"_id":"@bybrave/url-parse2","_rev":"2-ac7217799cb9ac0ef7d054f3cafffb19","name":"@bybrave/url-parse2","dist-tags":{"latest":"2.0.1"},"versions":{"2.0.0":{"name":"@bybrave/url-parse2","version":"2.0.0","keywords":["url","parse","parser","uri","query","querystring","ssrf","security","hostname","searchparams","typescript","esm"],"author":{"url":"https://github.com/bybraveHQ","name":"bybrave"},"license":"MIT","_id":"@bybrave/url-parse2@2.0.0","maintainers":[{"name":"bybrave","email":"opmybrave@gmail.com"}],"contributors":[{"url":"author of the original url-parse","name":"Arnout Kazemier"}],"homepage":"https://github.com/bybraveHQ/url-parse2#readme","bugs":{"url":"https://github.com/bybraveHQ/url-parse2/issues"},"dist":{"shasum":"47729cf40d3d1a5b8c6e827df7e70e0d475765bf","tarball":"https://registry.npmjs.org/@bybrave/url-parse2/-/url-parse2-2.0.0.tgz","fileCount":6,"integrity":"sha512-zVbsKso+eE1ZIzaEL1YX2fxGU0LA9IrsoFp1rzCHnyEUKcWCoHnLzZv/b5PCPrGHhxJs1aKnD9qQzkfzmaP2Ew==","signatures":[{"sig":"MEQCIAQknmpNISLDmvFOsvVAoSS9JeNuNvdb8Fp+JOA0gEhtAiA8kNk513nJ2kOnOfxG4BU1/viACLXcR1i2mPSo4O7Zuw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":30112},"main":"index.js","types":"index.d.ts","module":"index.mjs","engines":{"node":">=18"},"exports":{".":{"types":"./index.d.ts","import":"./index.mjs","require":"./index.js"},"./package.json":"./package.json"},"funding":"https://ko-fi.com/bybrave","gitHead":"5d9938be0ba8f2c049a9f203f386a89cb3e282be","scripts":{"test":"node --test test/*.test.js","test-types":"tsc --noEmit --strict test/type-declarations.ts"},"_npmUser":{"name":"bybrave","email":"opmybrave@gmail.com"},"repository":{"url":"git+https://github.com/bybraveHQ/url-parse2.git","type":"git"},"_npmVersion":"10.8.2","description":"Maintained fork of url-parse — small-footprint URL parser with the Unicode hostname SSRF differential (GHSA-9pv6-g64m-xhrq) fixed, ESM, and bundled TypeScript types","directories":{},"_nodeVersion":"20.19.6","dependencies":{"requires-port":"^1.0.0","querystringify":"^2.1.1"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.5.0","@types/node":"^20.14.0"},"_npmOperationalInternal":{"tmp":"tmp/url-parse2_2.0.0_1783221613668_0.7710336133896283","host":"s3://npm-registry-packages-npm-production"}},"2.0.1":{"name":"@bybrave/url-parse2","version":"2.0.1","description":"Maintained fork of url-parse — small-footprint URL parser with the Unicode hostname SSRF differential (GHSA-9pv6-g64m-xhrq) fixed, ESM, and bundled TypeScript types","main":"index.js","module":"index.mjs","types":"index.d.ts","exports":{".":{"types":"./index.d.ts","import":"./index.mjs","require":"./index.js"},"./package.json":"./package.json"},"scripts":{"test":"node --test test/*.test.js","test-types":"tsc --noEmit --strict test/type-declarations.ts"},"repository":{"type":"git","url":"git+https://github.com/bybraveHQ/url-parse2.git"},"bugs":{"url":"https://github.com/bybraveHQ/url-parse2/issues"},"homepage":"https://github.com/bybraveHQ/url-parse2#readme","keywords":["url","parse","parser","uri","query","querystring","ssrf","security","hostname","searchparams","typescript","esm"],"author":{"name":"bybrave","url":"https://github.com/bybraveHQ"},"contributors":[{"name":"Arnout Kazemier","url":"author of the original url-parse"}],"license":"MIT","funding":"https://ko-fi.com/bybrave","engines":{"node":">=18"},"dependencies":{"querystringify":"^2.1.1","requires-port":"^1.0.0"},"devDependencies":{"@types/node":"^20.14.0","typescript":"^5.5.0"},"_id":"@bybrave/url-parse2@2.0.1","gitHead":"8c9f564bf4c2084e446a9aca23c3b0f4ec504e2d","_nodeVersion":"20.19.6","_npmVersion":"10.8.2","dist":{"integrity":"sha512-somVVIVt0JsExJtsb/T7bFeLlLZcbn8IOZy39Ots+6BIWk+AHqyPs4/BEvSN03EJw8QAogiJStMeDZYBdCKZ9A==","shasum":"2b38fe2d357b5a36dd814176fdac94da48797eec","tarball":"https://registry.npmjs.org/@bybrave/url-parse2/-/url-parse2-2.0.1.tgz","fileCount":6,"unpackedSize":30440,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIGwJ2GIIMiSiV28tVDyrmBLM4WfuQFG8D94gAxExkMUAAiEAj29yKwW3QURvTdkBJnkonBrUmDoW7jMKQ8GtfR9Sg4g="}]},"_npmUser":{"name":"bybrave","email":"opmybrave@gmail.com"},"directories":{},"maintainers":[{"name":"bybrave","email":"opmybrave@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/url-parse2_2.0.1_1783222042595_0.4279210592882492"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-05T03:20:13.542Z","modified":"2026-07-05T03:27:22.846Z","2.0.0":"2026-07-05T03:20:13.801Z","2.0.1":"2026-07-05T03:27:22.731Z"},"bugs":{"url":"https://github.com/bybraveHQ/url-parse2/issues"},"author":{"name":"bybrave","url":"https://github.com/bybraveHQ"},"license":"MIT","homepage":"https://github.com/bybraveHQ/url-parse2#readme","keywords":["url","parse","parser","uri","query","querystring","ssrf","security","hostname","searchparams","typescript","esm"],"repository":{"type":"git","url":"git+https://github.com/bybraveHQ/url-parse2.git"},"description":"Maintained fork of url-parse — small-footprint URL parser with the Unicode hostname SSRF differential (GHSA-9pv6-g64m-xhrq) fixed, ESM, and bundled TypeScript types","contributors":[{"name":"Arnout Kazemier","url":"author of the original url-parse"}],"maintainers":[{"name":"bybrave","email":"opmybrave@gmail.com"}],"readme":"# @bybrave/url-parse2\n\nMaintained, drop-in fork of [`url-parse`](https://github.com/unshiftio/url-parse) — a small-footprint URL parser that works across Node.js and browser environments.\n\nThe original has been unmaintained since 2022 (last release `1.5.10`) while still pulling ~163M downloads/month. This fork fixes an unpatched hostname SSRF differential, closes the most-requested open issues, and ships ESM plus bundled TypeScript types (no more separate `@types/url-parse`).\n\n```sh\nnpm install @bybrave/url-parse2\n```\n\n```js\nconst Url = require('@bybrave/url-parse2');   // CommonJS\nimport Url from '@bybrave/url-parse2';         // ESM\n```\n\nThe API is identical to `url-parse` — same constructor, same properties, same `.set()` / `.toString()`. Existing code keeps working; the changes below are either security hardening or additive.\n\n## What's fixed\n\n| Issue | Problem | Fix |\n|---|---|---|\n| [#241](https://github.com/unshiftio/url-parse/issues/241) | **SSRF / allowlist bypass.** Unicode confusable full stops (`。` U+3002, `．` U+FF0E, `｡` U+FF61) were left intact in `hostname`, while browsers and native `URL` normalize them to `.`. A validator could be tricked into trusting the wrong host. Advisory [GHSA-9pv6-g64m-xhrq](https://github.com/0xBassia/url-parse/security/advisories/GHSA-9pv6-g64m-xhrq). | `hostname`/`host` are normalized to an ASCII dot, matching the platform `URL`. |\n| [#239](https://github.com/unshiftio/url-parse/issues/239) | Prototype-pollution surface: a crafted location object could inject `__proto__` / `constructor` / `prototype`. | Reserved keys are never copied from a location object. |\n| [#38](https://github.com/unshiftio/url-parse/issues/38) | `origin` defaulted to the **truthy string `\"null\"`** for empty / relative URLs, inconsistent with every other empty field. | Empty / relative input now yields `origin === ''`. Opaque origins (a parsed non-special scheme such as `foo://bar`) still serialize to `\"null\"`, matching native `URL`. |\n| [#132](https://github.com/unshiftio/url-parse/issues/132) | No way to keep a port that equals the protocol default (`:80` for `http:`). | New `keepDefaultPort` option (see below). |\n| [#162](https://github.com/unshiftio/url-parse/issues/162) | `query` existed but `searchParams` (per MDN) did not. | New `searchParams` getter returning a `URLSearchParams`. |\n| [#168](https://github.com/unshiftio/url-parse/issues/168) | No ESM entry, no bundled types. | Ships `import`/`require` via an `exports` map and a bundled `index.d.ts`. |\n\n## New API\n\n### `keepDefaultPort` option\n\nThe fourth constructor argument accepts an options object. With `keepDefaultPort: true`, a port equal to the protocol default is preserved instead of stripped:\n\n```js\nnew Url('http://a.com:80').port;                                  // '' (default)\nnew Url('http://a.com:80', null, false, { keepDefaultPort: true }).port; // '80'\n```\n\nThe flag is stored as a non-enumerable property, so it does not change the shape of the parsed object or its JSON serialization, and `.set('port', …)` respects it too.\n\n### `searchParams`\n\nA `URLSearchParams` view over the parsed query, mirroring `URL.searchParams`:\n\n```js\nconst url = new Url('https://a.com/?x=1&y=2&x=3');\nurl.searchParams.get('x');      // '1'\nurl.searchParams.getAll('x');   // ['1', '3']\n```\n\nIt is computed on access from the current `query`. Mutating the returned object does **not** write back to the URL — assign `url.query` or use `url.set('query', …)` to change the query.\n\n## Migration from `url-parse`\n\nReplace the dependency and the import — the parser behaves the same, with two intentional behavior changes to be aware of on a major bump:\n\n1. **`origin`** is now `''` (not `'null'`) for empty/relative input. If you relied on the truthy `'null'`, check for a falsy origin instead.\n2. **`hostname`** normalizes Unicode confusable dots. If you deliberately depended on the raw character surviving, that no longer holds (it was a security bug).\n\nEverything else — properties, `.set()`, `.toString()`, the query parser (`querystringify`) — is unchanged.\n\n## Support\n\nIf this package saves you time, you can support maintenance:\n\n[![Ko-fi](https://img.shields.io/badge/Ko--fi-buy%20me%20a%20coffee-FF5E5B?logo=kofi&logoColor=white)](https://ko-fi.com/bybrave)\n[![Bitcoin](https://img.shields.io/badge/Bitcoin-BTC-F7931A?logo=bitcoin&logoColor=white)](#support)\n\nBitcoin (BTC): `bc1q37557q5jpeaxqydzwvf3jgj7zhnfpn2td3q40q`\n\n## Credits & license\n\nMIT, same as the original — see [LICENSE](./LICENSE).\nBased on [url-parse](https://github.com/unshiftio/url-parse) by Arnout Kazemier and contributors.\n","readmeFilename":"README.md"}