{"_id":"elysia-xss","_rev":"5-446cd4b4e440f26ef7ce036c8542f075","name":"elysia-xss","dist-tags":{"latest":"1.0.4"},"versions":{"1.0.0":{"name":"elysia-xss","version":"1.0.0","_id":"elysia-xss@1.0.0","maintainers":[{"name":"abshahin","email":"abdelrahmanshaheeen8@gmail.com"}],"dist":{"shasum":"1f0b7066ffc30d423a4e39d8326efadf3e7f3c7f","tarball":"https://registry.npmjs.org/elysia-xss/-/elysia-xss-1.0.0.tgz","fileCount":8,"integrity":"sha512-atK9RZubO4OQb70R7ROxO2X5HVYHqWsiGh0ulpd2HHNqGTav2D9ONRsciZJhim9ncl5+RbEChxAbX0mqe4+UUQ==","signatures":[{"sig":"MEUCIQCj7B0p5c+ytUGl8Xs33gtBO22yQ0HGdLPSUv0thFeydAIga/ldnMzU16K0DbWF/WOVx6mGXLwS4cijHlJWt6Bu5TM=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":10205},"scripts":{"dev":"bun  --watch src/index.ts"},"_npmUser":{"name":"abshahin","email":"abdelrahmanshaheeen8@gmail.com"},"_npmVersion":"10.8.2","description":"A plugin for Elysia.js that provides XSS (Cross-Site Scripting) protection by sanitizing request body data.","directories":{},"_nodeVersion":"20.18.0","dependencies":{"xss":"^1.0.15","elysia":"^1.1.5"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"^1.1.6","typescript":"^5.5.4"},"_npmOperationalInternal":{"tmp":"tmp/elysia-xss_1.0.0_1733584747283_0.36403832689414495","host":"s3://npm-registry-packages"}},"1.0.1":{"name":"elysia-xss","version":"1.0.1","_id":"elysia-xss@1.0.1","maintainers":[{"name":"abshahin","email":"abdelrahmanshaheeen8@gmail.com"}],"dist":{"shasum":"af2fffde5e5a4e5203711c385bece42ff7ce6792","tarball":"https://registry.npmjs.org/elysia-xss/-/elysia-xss-1.0.1.tgz","fileCount":6,"integrity":"sha512-P6N8sgvkTjYSqtpxJRRycC4z1dB4fapH75ZbWvgi4+lKbuDl9Q5Jn7rRLXHX5VgiPdSRaicY1PPihyA6YGfG+A==","signatures":[{"sig":"MEQCIAipiw9aSwU37QZaK0Q3sh6sd0eP5YEwNj7h3fvvpgSqAiBtDlyxUwIsRKjJrf3bUWZqgjKtsqxYNrRUW5vL3LkC0Q==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":5646},"main":"dist/index.js","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"dev":"bun --watch src/index.ts","build":"tsc","prepublishOnly":"npm run build"},"_npmUser":{"name":"abshahin","email":"abdelrahmanshaheeen8@gmail.com"},"_npmVersion":"10.8.2","description":"A plugin for Elysia.js that provides XSS (Cross-Site Scripting) protection by sanitizing request body data.","directories":{},"_nodeVersion":"20.18.0","dependencies":{"xss":"^1.0.15","elysia":"^1.1.5"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"^1.1.6","typescript":"^5.5.4"},"_npmOperationalInternal":{"tmp":"tmp/elysia-xss_1.0.1_1733585279153_0.7182250157973133","host":"s3://npm-registry-packages"}},"1.0.2":{"name":"elysia-xss","version":"1.0.2","_id":"elysia-xss@1.0.2","maintainers":[{"name":"abshahin","email":"abdelrahmanshaheeen8@gmail.com"}],"dist":{"shasum":"a63df383c27c69860c27f6563d01efae9aecd038","tarball":"https://registry.npmjs.org/elysia-xss/-/elysia-xss-1.0.2.tgz","fileCount":6,"integrity":"sha512-2NrrQfkTLYlLs1T5XlkPlu+wJGpUzUiymkdEOkQs8syHVnUpW0kElAVP47wW9DgoCnvyOkWpwwVXS3Fj9XPRHQ==","signatures":[{"sig":"MEYCIQDaDXZWs1LagyTHI0HDqwyBpha++eI2SVQ1mpYlEo+hRQIhAMk7tLlGnbTDHmuelKxkHfdtMu/p0YhGdxSRnAg8r3df","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":5801},"main":"dist/index.js","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"dev":"bun --watch src/index.ts","build":"tsc","prepublishOnly":"npm run build"},"_npmUser":{"name":"abshahin","email":"abdelrahmanshaheeen8@gmail.com"},"_npmVersion":"10.8.2","description":"A plugin for Elysia.js that provides XSS (Cross-Site Scripting) protection by sanitizing request body data.","directories":{},"_nodeVersion":"20.18.0","dependencies":{"xss":"^1.0.15","elysia":"^1.1.5"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"^1.1.6","typescript":"^5.5.4"},"_npmOperationalInternal":{"tmp":"tmp/elysia-xss_1.0.2_1733586106448_0.4454028262516059","host":"s3://npm-registry-packages"}},"1.0.3":{"name":"elysia-xss","version":"1.0.3","keywords":["elysia","xss","security","sanitize","xss-sanitize","xss-protect","xss-filter","xss-protect-elysia","elysia-xss","elysia-plugin","elysia-plugin-xss","elysia-xss-plugin","elysia-xss-protect","bun"],"author":{"name":"Abdelrahman Shaheen"},"_id":"elysia-xss@1.0.3","maintainers":[{"name":"abshahin","email":"abdelrahmanshaheeen8@gmail.com"}],"homepage":"https://github.com/aashahin/elysia-xss#readme","bugs":{"url":"https://github.com/aashahin/elysia-xss/issues"},"dist":{"shasum":"c036b79f4a06d5c2cf7aac20c98ebae55820efd5","tarball":"https://registry.npmjs.org/elysia-xss/-/elysia-xss-1.0.3.tgz","fileCount":6,"integrity":"sha512-2kR9RBevoi3jXqnp8tbGBsRZ4P8Ah93m+vTUNL74z5dEVNcT6oEEQcs0inx4wJBJt+c/KOLLSPtDY6P7ErFnDg==","signatures":[{"sig":"MEQCIFXg8zrvcxrGnKuk6BOFa9WBWoJw5IYJ3lHcenrQC8LkAiAxTOadhICihZQswWgd2Hv++l+h+4aRArqhdNuF7w0fBQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":6308},"main":"dist/index.js","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"c0be0d699f7382e66ba069968d894688f6f2b683","scripts":{"dev":"bun --watch src/index.ts","build":"tsc","prepublishOnly":"npm run build"},"_npmUser":{"name":"abshahin","email":"abdelrahmanshaheeen8@gmail.com"},"repository":{"url":"git+https://github.com/aashahin/elysia-xss.git","type":"git"},"_npmVersion":"10.8.2","description":"A plugin for Elysia.js that provides XSS (Cross-Site Scripting) protection by sanitizing request body data.","directories":{},"_nodeVersion":"20.18.0","dependencies":{"xss":"^1.0.15","elysia":"^1.1.5"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"^1.1.6","typescript":"^5.5.4"},"_npmOperationalInternal":{"tmp":"tmp/elysia-xss_1.0.3_1733586513242_0.6875864377187737","host":"s3://npm-registry-packages"}},"1.0.4":{"name":"elysia-xss","version":"1.0.4","description":"A plugin for Elysia.js that provides XSS (Cross-Site Scripting) protection by sanitizing request body data.","author":{"name":"Abdelrahman Shaheen"},"repository":{"type":"git","url":"git+https://github.com/aashahin/elysia-xss.git"},"keywords":["elysia","xss","security","sanitize","xss-sanitize","xss-protect","xss-filter","xss-protect-elysia","elysia-xss","elysia-plugin","elysia-plugin-xss","elysia-xss-plugin","elysia-xss-protect","bun"],"main":"dist/index.js","types":"dist/index.d.ts","scripts":{"dev":"bun --watch src/index.ts","build":"tsc","prepublishOnly":"bun run build"},"dependencies":{"elysia":"^1.4.21","xss":"^1.0.15"},"devDependencies":{"typescript":"^5.9.3","@types/bun":"^1.3.5"},"exports":{".":{"import":"./dist/index.js","types":"./dist/index.d.ts"}},"_id":"elysia-xss@1.0.4","gitHead":"e7719448b2ad68644bce72a28c2acb73d1bf3b0d","bugs":{"url":"https://github.com/aashahin/elysia-xss/issues"},"homepage":"https://github.com/aashahin/elysia-xss#readme","_nodeVersion":"22.20.0","_npmVersion":"10.9.3","dist":{"integrity":"sha512-2rtOh3xOPPp8dQfivdAjMHPXLukI5yg7hEqS3fmw5OhltsJ9pTc0EUHldHnPhbxS0M7xNa6GsbIoEi9POqV09g==","shasum":"dfe7ef448c7a84b74436ddc24e686a245dca01f1","tarball":"https://registry.npmjs.org/elysia-xss/-/elysia-xss-1.0.4.tgz","fileCount":6,"unpackedSize":5717,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIHraK6hudP76ZwXFsq43y0guoAlWGdub7/zRFKKwo9t+AiEAzSafJZiDi19TvMX5otqxcWy5mdFLW77jiBN6MepJq2U="}]},"_npmUser":{"name":"abshahin","email":"abdelrahmanshaheeen8@gmail.com"},"directories":{},"maintainers":[{"name":"abshahin","email":"abdelrahmanshaheeen8@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/elysia-xss_1.0.4_1768292820705_0.270188774269567"},"_hasShrinkwrap":false}},"time":{"created":"2024-12-07T15:19:07.282Z","modified":"2026-01-13T08:27:01.056Z","1.0.0":"2024-12-07T15:19:07.461Z","1.0.1":"2024-12-07T15:27:59.334Z","1.0.2":"2024-12-07T15:41:46.674Z","1.0.3":"2024-12-07T15:48:33.435Z","1.0.4":"2026-01-13T08:27:00.853Z"},"bugs":{"url":"https://github.com/aashahin/elysia-xss/issues"},"author":{"name":"Abdelrahman Shaheen"},"homepage":"https://github.com/aashahin/elysia-xss#readme","keywords":["elysia","xss","security","sanitize","xss-sanitize","xss-protect","xss-filter","xss-protect-elysia","elysia-xss","elysia-plugin","elysia-plugin-xss","elysia-xss-plugin","elysia-xss-protect","bun"],"repository":{"type":"git","url":"git+https://github.com/aashahin/elysia-xss.git"},"description":"A plugin for Elysia.js that provides XSS (Cross-Site Scripting) protection by sanitizing request body data.","maintainers":[{"name":"abshahin","email":"abdelrahmanshaheeen8@gmail.com"}],"readme":"# Elysia XSS\n\nA plugin for Elysia.js that provides XSS (Cross-Site Scripting) protection by sanitizing request body data.\n\n## Features\n\n- 🛡️ Automatic XSS protection for request body data\n- 🔄 Recursive sanitization of nested objects and arrays\n- 🎯 Configurable scope options\n- ⚡ Zero Runtime Overhead (Instantiated once)\n- 🪶 Lightweight with minimal dependencies\n- 🚀 Built for Elysia.js and Bun\n\n## Installation\n\n```bash\nbun add elysia-xss\n```\n\n## Usage\n\n```typescript\nimport { Elysia } from 'elysia'\nimport { elysiaXSS } from 'elysia-xss'\n\nconst app = new Elysia()\n    .use(elysiaXSS()) // Use default XSS options\n    .post(\"/comment\", ({ body }) => body)\n    .listen(3000)\n```\n\n### Configuration\n\nThe plugin accepts standard [xss](https://github.com/leizongmin/js-xss#customize-whitelist) configuration options. By default, it uses the standard whitelist provided by the `xss` library.\n\n```typescript\nconst app = new Elysia()\n    .use(elysiaXSS({\n        whiteList: { a: ['href', 'title', 'target'] }, // Custom whitelist\n        stripIgnoreTag: true // Filter out all HTML not in the whitelist\n    }))\n```\n\n## How it Works\n\n1. **Auto-Sanitization**: Automatically sanitizes all string values in the request body (including nested objects and arrays).\n2. **Secure by Design**: Sanitization happens **before** validation. This prevents malicious payloads from bypassing validation rules (e.g., a huge payload that becomes small after stripping tags will still fail validation if checked against the original raw length, or vice versa).\n   - *Note*: Validation logic will see the *sanitized* content.\n3. **Type Safety**: Preserves input types and schema inference.\n\n## Dependencies\n\n- [Elysia](https://elysiajs.com/) - The web framework\n- [xss](https://www.npmjs.com/package/xss) - XSS sanitizer\n\n## License\n\nMIT\n\n## Contributing\n\nContributions are welcome! Please feel free to submit a Pull Request.","readmeFilename":"README.md"}