{"_id":"@microsoft/antissrf","_rev":"5-ca2d3a62c05e81c54e17dee89018a0bb","name":"@microsoft/antissrf","dist-tags":{"latest":"1.0.0"},"versions":{"0.1.0":{"name":"@microsoft/antissrf","version":"0.1.0","author":{"name":"Microsoft"},"_id":"@microsoft/antissrf@0.1.0","maintainers":[{"name":"microsoft1es","email":"npmjs@microsoft.com"},{"name":"microsoft-oss-releases","email":"microsoft-oss-publishing@microsoft.com"}],"dist":{"shasum":"83552f97bbdd56807a4c6439327835573b2b9d5b","tarball":"https://registry.npmjs.org/@microsoft/antissrf/-/antissrf-0.1.0.tgz","fileCount":22,"integrity":"sha512-48DBSvWaWsj5vuxkZ4yK+mfUglSIcHiux4VO8Wtbpo2z1xDQLm+VxO6QPpKIlVAhZfs/r0L/0zIy/rbwObiusg==","signatures":[{"sig":"MEUCIAfvHhIdsubgjF0egwHA3NHbfyKzRAjW+juwfIOSyL8jAiEAgLYd+GV+3+FifkmuzeYQuPm9A68qF/GVWS80uioC9Xs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":34226},"main":"./out/src/index.js","_from":"file:M:\\SvcFab\\_App\\MS.Ess.PackageManager.Publisher_App1\\temp\\b945aa1c-d363-4936-b3bf-edcfdc9df87b\\microsoft-antissrf-0.1.0.tgz","types":"./out/src/index.d.ts","scripts":{"lint":"eslint src","test":"mocha --recursive --timeout 15000 --require ts-node/register --no-strip-types \"tests/{UnitTests,FunctionalTests}/**/*.test.ts\"","build":"tsc --project ./tsconfig.json","format":"prettier --write .","test:unit":"mocha --recursive --timeout 15000 --require ts-node/register --no-strip-types tests/UnitTests/**/*.test.ts","test:functional":"mocha --recursive --timeout 15000 --require ts-node/register --no-strip-types tests/FunctionalTests/**/*.test.ts","test:prepublish":"mocha --recursive --timeout 15000 tests/PrePublishTests/**/*.test.js"},"_npmUser":{"name":"microsoft1es","email":"npmjs@microsoft.com"},"_resolved":"M:\\SvcFab\\_App\\MS.Ess.PackageManager.Publisher_App1\\temp\\b945aa1c-d363-4936-b3bf-edcfdc9df87b\\microsoft-antissrf-0.1.0.tgz","_integrity":"sha512-48DBSvWaWsj5vuxkZ4yK+mfUglSIcHiux4VO8Wtbpo2z1xDQLm+VxO6QPpKIlVAhZfs/r0L/0zIy/rbwObiusg==","description":"A library to prevent SSRF vulnerabilities in Node.js applications","directories":{},"_nodeVersion":"18.5.0","_hasShrinkwrap":false,"devDependencies":{"tar":"^7.4.3","axios":"^1.12.2","mocha":"^11.7.5","eslint":"^9.20.0","ts-node":"^10.9.2","prettier":"^3.5.3","@eslint/js":"^9.20.0","node-fetch":"^3.3.2","typescript":"^5.7.3","@types/mocha":"^10.0.10","follow-redirects":"^1.15.9","@types/node-fetch":"^2.6.13","typescript-eslint":"^8.59.1","eslint-plugin-security":"^3.0.1","@types/follow-redirects":"^1.14.4"},"_npmOperationalInternal":{"tmp":"tmp/antissrf_0.1.0_1780004834902_0.9371128489650467","host":"s3://npm-registry-packages-npm-production"}},"1.0.0":{"name":"@microsoft/antissrf","version":"1.0.0","keywords":["ssrf","anti-ssrf","security","sanitizer","url-validation"],"author":{"name":"Microsoft"},"license":"MIT","_id":"@microsoft/antissrf@1.0.0","maintainers":[{"name":"microsoft1es","email":"npmjs@microsoft.com"},{"name":"microsoft-oss-releases","email":"microsoft-oss-publishing@microsoft.com"}],"homepage":"https://microsoft.github.io/AntiSSRF/","bugs":{"url":"https://github.com/microsoft/AntiSSRF/issues","email":"antissrf-oss@microsoft.com"},"dist":{"shasum":"3e52d19354e45b1ff023c6eaf894d2d58ec10f07","tarball":"https://registry.npmjs.org/@microsoft/antissrf/-/antissrf-1.0.0.tgz","fileCount":24,"integrity":"sha512-AmO1ykSha52Ef/7UXvHgu8ElsGdgcLkF5nTl7YZGyR1AkbmlQYtiVeWp+CsjkFaJzKAH5ofXLZveMmOHwX/7Jw==","signatures":[{"sig":"MEUCIQCcE+vMJeigFUcTTzngkuAM/hLQP1qm3WVsCiaPzLGcZgIgWLWOHc5LK/xVXduZryGW2AYfp/gO7kCY6fN3rWF95x4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":59329},"main":"./out/src/index.js","_from":"file:M:\\SvcFab\\_App\\MS.Ess.PackageManager.Publisher_App1\\temp\\303dc6a4-59de-49a8-97f7-684140c79256\\microsoft-antissrf-1.0.0.tgz","types":"./out/src/index.d.ts","scripts":{"lint":"eslint src","test":"mocha --recursive --timeout 15000 --require ts-node/register --no-strip-types \"tests/{UnitTests,FunctionalTests}/**/*.test.ts\"","build":"tsc --project ./tsconfig.json","format":"prettier --write .","test:unit":"mocha --recursive --timeout 15000 --require ts-node/register --no-strip-types tests/UnitTests/**/*.test.ts","test:functional":"mocha --recursive --timeout 15000 --require ts-node/register --no-strip-types tests/FunctionalTests/**/*.test.ts","test:prepublish":"mocha --recursive --timeout 15000 tests/PrePublishTests/**/*.test.js"},"_npmUser":{"name":"microsoft1es","email":"npmjs@microsoft.com"},"_resolved":"M:\\SvcFab\\_App\\MS.Ess.PackageManager.Publisher_App1\\temp\\303dc6a4-59de-49a8-97f7-684140c79256\\microsoft-antissrf-1.0.0.tgz","overrides":{"mocha":{"diff":"8.0.4","serialize-javascript":"7.0.5"}},"_integrity":"sha512-AmO1ykSha52Ef/7UXvHgu8ElsGdgcLkF5nTl7YZGyR1AkbmlQYtiVeWp+CsjkFaJzKAH5ofXLZveMmOHwX/7Jw==","repository":{"url":"git+https://github.com/microsoft/AntiSSRF.git","type":"git"},"description":"A library to prevent SSRF vulnerabilities in Node.js applications","directories":{},"_nodeVersion":"18.5.0","_hasShrinkwrap":false,"devDependencies":{"tar":"^7.4.3","axios":"^1.16.1","mocha":"^11.7.6","eslint":"^9.20.0","ts-node":"^10.9.2","prettier":"^3.5.3","@eslint/js":"^9.20.0","node-fetch":"^3.3.2","typescript":"^5.7.3","@types/mocha":"^10.0.10","follow-redirects":"^1.15.9","@types/node-fetch":"^2.6.13","typescript-eslint":"^8.59.1","eslint-plugin-security":"^3.0.1","@types/follow-redirects":"^1.14.4"},"_npmOperationalInternal":{"tmp":"tmp/antissrf_1.0.0_1780095025118_0.29644260833366154","host":"s3://npm-registry-packages-npm-production"}}},"time":{"created":"2026-05-28T21:47:14.772Z","modified":"2026-07-16T15:43:04.258Z","0.1.0":"2026-05-28T21:47:15.041Z","1.0.0":"2026-05-29T22:50:25.257Z"},"bugs":{"url":"https://github.com/microsoft/AntiSSRF/issues","email":"antissrf-oss@microsoft.com"},"author":{"name":"Microsoft"},"license":"MIT","homepage":"https://microsoft.github.io/AntiSSRF/","keywords":["ssrf","anti-ssrf","security","sanitizer","url-validation"],"repository":{"url":"git+https://github.com/microsoft/AntiSSRF.git","type":"git"},"description":"A library to prevent SSRF vulnerabilities in Node.js applications","maintainers":[{"email":"npmjs@microsoft.com","name":"microsoft1es"},{"email":"microsoft-oss-publishing@microsoft.com","name":"microsoft-oss-releases"}],"readme":"## Microsoft AntiSSRF Library for Node.js\n\nThe Microsoft AntiSSRF Library for Node.js is a security-developed, exhaustively-tested library that provides robust URL validation to protect Node.js applications from Server-Side Request Forgery (SSRF) vulnerabilities. It integrates seamlessly with Node.js HTTP/HTTPS agents, allowing developers to secure outbound HTTP requests with minimal code changes.\n\n## How to Use\n\nThe AntiSSRF Library provides validation for different scenarios based on your trust requirements:\n\n| Use Case | Description | Documentation Link |\n| --- | --- | --- |\n| **General Case** | The untrusted URL can belong to **any domain** or an **untrusted domain**. | [AntiSSRFPolicy](https://microsoft.github.io/AntiSSRF/nodejs-api/antissrfpolicy) |\n| **Azure Key Vault Domain** | The untrusted URL must be an **Azure Key Vault endpoint**. | [URIValidator.inAzureKeyVaultDomain](https://microsoft.github.io/AntiSSRF/nodejs-api/urivalidator/inazurekeyvaultdomain) |\n| **Azure Storage Domain** | The untrusted URL must be an **Azure Storage endpoint**. | [URIValidator.inAzureStorageDomain](https://microsoft.github.io/AntiSSRF/nodejs-api/urivalidator/inazurestoragedomain) |\n| **Allowlist of Trusted Domains** | The untrusted URL must belong to a **specific, trusted domain**. | [URIValidator.inDomain](https://microsoft.github.io/AntiSSRF/nodejs-api/urivalidator/indomain) |\n\n## Key Features\n\n* **SSRF Attack Prevention** - Blocks malicious server-side request forgery attempts\n\n* **Private Network Protection** - Separate built-in configuration options for internal vs. external address HTTP clients\n\n* **DNS Rebinding Protection** - Guards against DNS-based attacks\n\n* **Redirect Protection** - Re-validates on all redirects to prevent bypass attempts\n\n* **Protocol Validation** - Ensures only safe protocols are used\n\n* **Fully Customizable** - Configure domain allowlists, IP ranges, headers, and validation policies\n\n## Additional Documentation\n\nExplore our comprehensive documentation to get the most out of Microsoft AntiSSRF:\n\n### Getting Started\n- [Microsoft AntiSSRF Documentation](https://microsoft.github.io/AntiSSRF/)\n- [Quick Start Guide](https://microsoft.github.io/AntiSSRF/getting-started)\n- [Security Best Practices](https://microsoft.github.io/AntiSSRF/getting-started#best-practices)\n- [Frequently Asked Questions](https://microsoft.github.io/AntiSSRF/faq)\n- [Changelog](https://microsoft.github.io/AntiSSRF/nodejs-api/changelog)\n\n### API Documentation\n- [Complete Node.js API Documentation](https://microsoft.github.io/AntiSSRF/nodejs-api)\n- [AntiSSRF Node.js Agent](https://microsoft.github.io/AntiSSRF/nodejs-api/antissrfpolicy/methods/gethttpsagent)\n- [AntiSSRFPolicy](https://microsoft.github.io/AntiSSRF/nodejs-api/antissrfpolicy)\n- [URIValidator](https://microsoft.github.io/AntiSSRF/nodejs-api/urivalidator)\n\n## Feedback & Contributing\n\nWe welcome feedback and contributions from the community! Here's how you can get involved:\n\n- **Report Issues**: [GitHub Issues](https://github.com/Microsoft/AntiSSRF/issues) - Report bugs or request new features\n- **Contribute**: [Contributing Guide](https://github.com/Microsoft/AntiSSRF/blob/main/CONTRIBUTING.md) - Learn how to contribute to the project\n- **Contact**: [antissrf-oss@microsoft.com](mailto:antissrf-oss@microsoft.com) - Direct email for questions and feedback\n\n## Support Policy\n\nFor support inquiries, contact [antissrf-oss@microsoft.com](mailto:antissrf-oss@microsoft.com).","readmeFilename":"README.md"}