{"_id":"host-validation-middleware","_rev":"5-64e53a2a8c482cd18eac8a862383f0f5","name":"host-validation-middleware","dist-tags":{"latest":"0.1.4"},"versions":{"0.1.0":{"name":"host-validation-middleware","version":"0.1.0","keywords":["vite","vite-plugin"],"author":{"url":"https://github.com/sapphi-red","name":"sapphi-red"},"license":"MIT","_id":"host-validation-middleware@0.1.0","maintainers":[{"name":"sapphi-red","email":"green@sapphi.red"}],"homepage":"https://github.com/sapphi-red/host-validation-middleware#readme","bugs":{"url":"https://github.com/sapphi-red/host-validation-middleware/issues"},"dist":{"shasum":"afffa17599adb136e3f678cc57c5690cb07c9cc6","tarball":"https://registry.npmjs.org/host-validation-middleware/-/host-validation-middleware-0.1.0.tgz","fileCount":5,"integrity":"sha512-J/3ulu8axQXsjb2K7Z0ishjhuMKNqPEJtmn1TcgqC9cemIvSYi6GNd2mq+6AfOKm8VV4GxiM0N/pCWonAysGBA==","signatures":[{"sig":"MEUCIQChsF9zXCGdfonXN9CKPGvsC2vQYZgL+hIXHFdqqcZZMQIgeH5Bv0qJT+zSy+QoXX1zrGl0cEmSkgZkVtf+FL9dKsQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/host-validation-middleware@0.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":10366},"type":"module","_from":"file:host-validation-middleware-0.1.0.tgz","engines":{"node":"^18.0.0 || >=20.0.0"},"exports":"./dist/index.js","scripts":{"dev":"tsdown --watch","lint":"eslint --cache .","test":"vitest","build":"tsdown","format":"prettier --write --cache .","type-check":"tsc --noEmit","release:publish":"changeset publish","release:version":"changeset version && pnpm install --no-frozen-lockfile"},"_npmUser":{"name":"sapphi-red","email":"green@sapphi.red"},"_resolved":"/tmp/b00899aab5eaf8bc3c93ae159c78598e/host-validation-middleware-0.1.0.tgz","_integrity":"sha512-J/3ulu8axQXsjb2K7Z0ishjhuMKNqPEJtmn1TcgqC9cemIvSYi6GNd2mq+6AfOKm8VV4GxiM0N/pCWonAysGBA==","repository":{"url":"git+https://github.com/sapphi-red/host-validation-middleware.git","type":"git"},"_npmVersion":"10.9.2","description":"Middleware for validating host headers in requests to protect against DNS rebinding attacks.","directories":{},"_nodeVersion":"22.15.0","_hasShrinkwrap":false,"devDependencies":{"eslint":"^9.26.0","tsdown":"^0.11.2","vitest":"^3.1.2","prettier":"^3.5.3","@eslint/js":"^9.26.0","typescript":"^5.8.3","@types/node":"^22.15.3","escape-html":"^1.0.3","@changesets/cli":"^2.29.2","node-mocks-http":"^1.17.2","typescript-eslint":"^8.31.1","@types/escape-html":"^1.0.4","@vitest/eslint-plugin":"^1.1.44","eslint-config-prettier":"^10.1.2","@changesets/changelog-github":"^0.5.1","@types/eslint-config-prettier":"^6.11.3"},"_npmOperationalInternal":{"tmp":"tmp/host-validation-middleware_0.1.0_1746888451435_0.9817315988718045","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"host-validation-middleware","version":"0.1.1","keywords":["middleware","development","express","connect"],"author":{"url":"https://github.com/sapphi-red","name":"sapphi-red"},"license":"MIT","_id":"host-validation-middleware@0.1.1","maintainers":[{"name":"sapphi-red","email":"green@sapphi.red"}],"homepage":"https://github.com/sapphi-red/host-validation-middleware#readme","bugs":{"url":"https://github.com/sapphi-red/host-validation-middleware/issues"},"dist":{"shasum":"085c7750164f6b25fe843950a12a653f1e59ac2e","tarball":"https://registry.npmjs.org/host-validation-middleware/-/host-validation-middleware-0.1.1.tgz","fileCount":5,"integrity":"sha512-fakcpp+x4nbP0fACY5gaHWpaOfstq3w8uB6wvhbPBLqH9GV/tdiM9Ht5mclZVbUuPLGBw1bkH5yyTD6HZq057g==","signatures":[{"sig":"MEYCIQCPBLQUofYFPoHIuPJi80tqXixN+1DAb8kJ2OLEqvvRgwIhAIcQFMEQ3vRLqYY77XdOjDUhwEtZIWM66OxazUfo0pme","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/host-validation-middleware@0.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":10400},"type":"module","_from":"file:host-validation-middleware-0.1.1.tgz","engines":{"node":"^18.0.0 || >=20.0.0"},"exports":"./dist/index.js","scripts":{"dev":"tsdown --watch","lint":"eslint --cache .","test":"vitest","build":"tsdown","format":"prettier --write --cache .","type-check":"tsc --noEmit","release:publish":"changeset publish","release:version":"changeset version && pnpm install --no-frozen-lockfile"},"_npmUser":{"name":"sapphi-red","email":"green@sapphi.red"},"_resolved":"/tmp/877ffe4cbe6300a4f4a7cece2e459e94/host-validation-middleware-0.1.1.tgz","_integrity":"sha512-fakcpp+x4nbP0fACY5gaHWpaOfstq3w8uB6wvhbPBLqH9GV/tdiM9Ht5mclZVbUuPLGBw1bkH5yyTD6HZq057g==","repository":{"url":"git+https://github.com/sapphi-red/host-validation-middleware.git","type":"git"},"_npmVersion":"10.9.2","description":"Middleware for validating host headers in requests to protect against DNS rebinding attacks.","directories":{},"_nodeVersion":"22.15.0","_hasShrinkwrap":false,"devDependencies":{"eslint":"^9.26.0","tsdown":"^0.11.2","vitest":"^3.1.2","prettier":"^3.5.3","@eslint/js":"^9.26.0","typescript":"^5.8.3","@types/node":"^22.15.3","escape-html":"^1.0.3","@changesets/cli":"^2.29.2","node-mocks-http":"^1.17.2","typescript-eslint":"^8.31.1","@types/escape-html":"^1.0.4","@vitest/eslint-plugin":"^1.1.44","eslint-config-prettier":"^10.1.2","@changesets/changelog-github":"^0.5.1","@types/eslint-config-prettier":"^6.11.3"},"_npmOperationalInternal":{"tmp":"tmp/host-validation-middleware_0.1.1_1746889399597_0.991172007378301","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"host-validation-middleware","version":"0.1.2","keywords":["middleware","development","express","connect"],"author":{"url":"https://github.com/sapphi-red","name":"sapphi-red"},"license":"MIT","_id":"host-validation-middleware@0.1.2","maintainers":[{"name":"sapphi-red","email":"green@sapphi.red"}],"homepage":"https://github.com/sapphi-red/host-validation-middleware#readme","bugs":{"url":"https://github.com/sapphi-red/host-validation-middleware/issues"},"dist":{"shasum":"27d42d62133b1a8d3c8fca4c44dad6e71c36ca96","tarball":"https://registry.npmjs.org/host-validation-middleware/-/host-validation-middleware-0.1.2.tgz","fileCount":5,"integrity":"sha512-pg/prhP/e/TqIc3tGj8Nkza4o8j4GE212FNJJN+vhebYnHIPfLZbTmRp8yiT9vEtPeIWCz6sD41EpaO9ys5Tfg==","signatures":[{"sig":"MEYCIQCkIIwudvZUJjPk4LDOWKBs1969ErL5yGPLMybV2bsajQIhAMB0K9gxalBrQ43C11casu38XI8Yx5wq00hf2j/YQKmW","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/host-validation-middleware@0.1.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":10806},"type":"module","_from":"file:host-validation-middleware-0.1.2.tgz","engines":{"node":"^18.0.0 || >=20.0.0"},"exports":"./dist/index.js","scripts":{"dev":"tsdown --watch","lint":"eslint --cache .","test":"vitest","build":"tsdown","format":"prettier --write --cache .","type-check":"tsc --noEmit","release:publish":"changeset publish","release:version":"changeset version && pnpm install --no-frozen-lockfile"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:db6aa76f-e92a-4477-9a4e-dd9da26c97ef"}},"_resolved":"/tmp/77276cb7ae7ea3574809bfbfa547e1a4/host-validation-middleware-0.1.2.tgz","_integrity":"sha512-pg/prhP/e/TqIc3tGj8Nkza4o8j4GE212FNJJN+vhebYnHIPfLZbTmRp8yiT9vEtPeIWCz6sD41EpaO9ys5Tfg==","repository":{"url":"git+https://github.com/sapphi-red/host-validation-middleware.git","type":"git"},"_npmVersion":"11.6.1","description":"Middleware for validating host headers in requests to protect against DNS rebinding attacks.","directories":{},"_nodeVersion":"22.19.0","_hasShrinkwrap":false,"devDependencies":{"eslint":"^9.36.0","tsdown":"^0.15.6","vitest":"^3.2.4","prettier":"^3.6.2","@eslint/js":"^9.36.0","typescript":"^5.9.3","@types/node":"^22.18.8","escape-html":"^1.0.3","@changesets/cli":"^2.29.7","node-mocks-http":"^1.17.2","typescript-eslint":"^8.45.0","@types/escape-html":"^1.0.4","@vitest/eslint-plugin":"^1.3.13","eslint-config-prettier":"^10.1.8","@changesets/changelog-github":"^0.5.1","@types/eslint-config-prettier":"^6.11.3"},"_npmOperationalInternal":{"tmp":"tmp/host-validation-middleware_0.1.2_1759289661179_0.21521267310759362","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"host-validation-middleware","version":"0.1.3","keywords":["connect","development","express","middleware"],"author":{"url":"https://github.com/sapphi-red","name":"sapphi-red"},"license":"MIT","_id":"host-validation-middleware@0.1.3","maintainers":[{"name":"sapphi-red","email":"green@sapphi.red"}],"homepage":"https://github.com/sapphi-red/host-validation-middleware#readme","bugs":{"url":"https://github.com/sapphi-red/host-validation-middleware/issues"},"dist":{"shasum":"f8095328a0096d5fe24d61fe3ec9d086963b6be8","tarball":"https://registry.npmjs.org/host-validation-middleware/-/host-validation-middleware-0.1.3.tgz","fileCount":5,"integrity":"sha512-13/5isK2iYII9NGxnOMuDt24YwyzLwfEuu3fTwrx7wWSaqMFxqW7iX76UCCkjHOahRaVYM4bdmhRc1RW+OXBBg==","signatures":[{"sig":"MEUCIGkyZ4TeBioOKfeYwR0fRFL60pjR8jNWCtg8NlTQiM9hAiEA6KwCwjIKH7v/X0W/fURU8p/1TBWmkZOoml9FxgU+2hU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/host-validation-middleware@0.1.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":10616},"type":"module","_from":"file:host-validation-middleware-0.1.3.tgz","engines":{"node":"^18.0.0 || >=20.0.0"},"exports":"./dist/index.js","funding":{"url":"https://github.com/sponsors/sapphi-red","type":"github"},"scripts":{"dev":"tsdown --watch","lint":"oxlint --type-aware --type-check","test":"vitest","build":"tsdown","format":"oxfmt","release:publish":"changeset publish","release:version":"changeset version && pnpm install --no-frozen-lockfile"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:db6aa76f-e92a-4477-9a4e-dd9da26c97ef"}},"_resolved":"/tmp/e1eedf9e96babb8b86eac3d0e1f09e7d/host-validation-middleware-0.1.3.tgz","_integrity":"sha512-13/5isK2iYII9NGxnOMuDt24YwyzLwfEuu3fTwrx7wWSaqMFxqW7iX76UCCkjHOahRaVYM4bdmhRc1RW+OXBBg==","repository":{"url":"git+https://github.com/sapphi-red/host-validation-middleware.git","type":"git"},"_npmVersion":"11.12.1","description":"Middleware for validating host headers in requests to protect against DNS rebinding attacks.","directories":{},"_nodeVersion":"22.22.1","_hasShrinkwrap":false,"devDependencies":{"oxfmt":"^0.43.0","oxlint":"^1.58.0","tsdown":"^0.21.7","vitest":"^4.1.2","typescript":"^6.0.2","@types/node":"^22.19.15","escape-html":"^1.0.3","@changesets/cli":"^2.30.0","node-mocks-http":"^1.17.2","oxlint-tsgolint":"^0.19.0","@types/escape-html":"^1.0.4","@changesets/changelog-github":"^0.6.0"},"_npmOperationalInternal":{"tmp":"tmp/host-validation-middleware_0.1.3_1775011622528_0.5858722625321815","host":"s3://npm-registry-packages-npm-production"}},"0.1.4":{"name":"host-validation-middleware","version":"0.1.4","description":"Middleware for validating host headers in requests to protect against DNS rebinding attacks.","keywords":["connect","development","express","middleware"],"homepage":"https://github.com/sapphi-red/host-validation-middleware#readme","bugs":{"url":"https://github.com/sapphi-red/host-validation-middleware/issues"},"license":"MIT","author":{"name":"sapphi-red","url":"https://github.com/sapphi-red"},"repository":{"type":"git","url":"git+https://github.com/sapphi-red/host-validation-middleware.git"},"funding":{"type":"github","url":"https://github.com/sponsors/sapphi-red"},"type":"module","exports":"./dist/index.js","devDependencies":{"@changesets/changelog-github":"^0.6.0","@changesets/cli":"^2.30.0","@types/escape-html":"^1.0.4","@types/node":"^22.19.15","escape-html":"^1.0.3","node-mocks-http":"^1.17.2","oxfmt":"^0.43.0","oxlint":"^1.58.0","oxlint-tsgolint":"^0.19.0","tsdown":"^0.21.7","typescript":"^6.0.2","vitest":"^4.1.2"},"engines":{"node":"^18.0.0 || >=20.0.0"},"scripts":{"dev":"tsdown --watch","build":"tsdown","lint":"oxlint --type-aware --type-check","format":"oxfmt","test":"vitest","release:version":"changeset version && pnpm install --no-frozen-lockfile","release:publish":"changeset publish"},"_id":"host-validation-middleware@0.1.4","_integrity":"sha512-VW5VMj09+ZwwMmr+B6WvYl0M/G1x7JFyh2hP9DC2IEOm4BcT6+2/Zc5AILM/MBcfw5Zge8b0ogF7avAkXYwbxg==","_resolved":"/tmp/c0ee20ae0663acfedbca6a8ce84eebcf/host-validation-middleware-0.1.4.tgz","_from":"file:host-validation-middleware-0.1.4.tgz","_nodeVersion":"24.14.1","_npmVersion":"11.12.1","dist":{"integrity":"sha512-VW5VMj09+ZwwMmr+B6WvYl0M/G1x7JFyh2hP9DC2IEOm4BcT6+2/Zc5AILM/MBcfw5Zge8b0ogF7avAkXYwbxg==","shasum":"0e3002f578cf970bf24b42b01f18a48290d50bfc","tarball":"https://registry.npmjs.org/host-validation-middleware/-/host-validation-middleware-0.1.4.tgz","fileCount":5,"unpackedSize":10616,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/host-validation-middleware@0.1.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIA3elXzUi0mYtDp4zqL3o2CFAQfOC77+19ZJtWNTV6hrAiBBEGNLn1dEhBiPFrL5wqO2qKpNhMJgq2Y0bkz/k6kcZg=="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:db6aa76f-e92a-4477-9a4e-dd9da26c97ef"}},"directories":{},"maintainers":[{"name":"sapphi-red","email":"green@sapphi.red"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/host-validation-middleware_0.1.4_1775287575704_0.06423893861023977"},"_hasShrinkwrap":false}},"time":{"created":"2025-05-10T14:47:31.363Z","modified":"2026-04-04T07:26:16.097Z","0.1.0":"2025-05-10T14:47:31.614Z","0.1.1":"2025-05-10T15:03:19.804Z","0.1.2":"2025-10-01T03:34:21.382Z","0.1.3":"2026-04-01T02:47:02.704Z","0.1.4":"2026-04-04T07:26:15.824Z"},"bugs":{"url":"https://github.com/sapphi-red/host-validation-middleware/issues"},"author":{"name":"sapphi-red","url":"https://github.com/sapphi-red"},"license":"MIT","homepage":"https://github.com/sapphi-red/host-validation-middleware#readme","keywords":["connect","development","express","middleware"],"repository":{"type":"git","url":"git+https://github.com/sapphi-red/host-validation-middleware.git"},"description":"Middleware for validating host headers in requests to protect against DNS rebinding attacks.","maintainers":[{"name":"sapphi-red","email":"green@sapphi.red"}],"readme":"# host-validation-middleware\n\n[![npm version](https://badge.fury.io/js/host-validation-middleware.svg)](https://badge.fury.io/js/host-validation-middleware) ![CI](https://github.com/sapphi-red/host-validation-middleware/workflows/CI/badge.svg) [![MIT License](http://img.shields.io/badge/license-MIT-blue.svg?style=flat)](LICENSE)\n\nMiddleware for validating host headers in requests to protect against [DNS rebinding attacks](https://capec.mitre.org/data/definitions/275.html).\n\n> [!NOTE]\n> DNS rebinding attacks are not effective against HTTPS sites. Since HTTPS is now commonly used for production environments, this middleware is generally unnecessary for production sites.\n\n## Install\n\n```shell\nnpm i -D host-validation-middleware # pnpm add -D host-validation-middleware\n```\n\n## Usage\n\n### `hostValidationMiddleware`\n\nThis middleware is compatible with [Connect](https://github.com/senchalabs/connect) and frameworks like [Express](https://github.com/expressjs/express) that support Connect-style middleware.\n\n```ts\nimport connect from 'connect'\nimport { hostValidationMiddleware } from 'host-validation-middleware'\n\nconst app = connect()\n\napp.use(\n  hostValidationMiddleware({\n    // Values starting with `.` will allow all the subdomains under that domain\n    allowedHosts: Object.freeze(['example.com', '.mydomain.com']),\n    // Optionally customize the error message:\n    generateErrorMessage: (hostname) => `Access denied for host: ${hostname}`,\n    // Optionally set the error response content type:\n    errorResponseContentType: 'text/plain',\n  }),\n)\n\napp.use((req, res) => {\n  res.end('Hello, world!')\n})\n\napp.listen(3000, () => {\n  console.log('Server running on http://localhost:3000')\n})\n```\n\nIf the host header is not in the allowed hosts list, a 403 Forbidden response is sent.\n\n### `isHostAllowed`\n\nYou can also use the core host validation logic directly:\n\n```ts\nimport { isHostAllowed } from 'host-validation-middleware'\n\nconst allowedHosts = Object.freeze(['example.com', '.mydomain.com'])\n\nconsole.log(isHostAllowed('example.com', allowedHosts)) // true\nconsole.log(isHostAllowed('sub.mydomain.com', allowedHosts)) // true\nconsole.log(isHostAllowed('evil.com', allowedHosts)) // false\n```\n\nThis function will cache the result if the `allowedHosts` array is frozen.\n\n## Allowed Hosts\n\nThe host names listed in the `allowedHosts` options will be allowed.\nIf the host name starts with a dot, the domain without the dot and any subdomain of it will be allowed.\n\n- Example: With `allowedHosts: ['example.com', '.mydomain.com']`:\n  - Requests to `example.com` are allowed.\n  - Requests to `mydomain.com`, `foo.mydomain.com`, `bar.foo.mydomain.com` are also allowed.\n\nAlso the following hosts that cannot be used for DNS rebinding attacks are always allowed:\n\n- Any `localhost` or subdomain of `localhost` (e.g., `localhost`, `foo.localhost`)\n- Any IPv4 or IPv6 address (e.g., `127.0.0.1`, `[::1]`)\n- Any host using the `file:` or browser extension protocol\n\n## Credits\n\nThe API interface and the original implementation is based on [`webpack-dev-server`](https://github.com/webpack/webpack-dev-server)'s `allowedHosts` option.\n","readmeFilename":"README.md"}