{"id":15013084,"url":"https://github.com/ellado-fbit/express-middleware","last_synced_at":"2026-02-17T05:31:56.826Z","repository":{"id":40764226,"uuid":"271742333","full_name":"ellado-fbit/express-middleware","owner":"ellado-fbit","description":"A miscellaneous collection of Express middlewares to parse string properties into numbers or booleans, validate data with JSON Schema, and sign/verify JSON Web Tokens.","archived":false,"fork":false,"pushed_at":"2025-02-12T10:58:57.000Z","size":461,"stargazers_count":1,"open_issues_count":0,"forks_count":0,"subscribers_count":1,"default_branch":"master","last_synced_at":"2025-09-27T10:40:44.006Z","etag":null,"topics":["express","express-middlewares","ip-address","json-schema","jsonwebtoken","middleware","nodejs"],"latest_commit_sha":null,"homepage":"","language":"JavaScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/ellado-fbit.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":null,"license":"LICENSE.md","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2020-06-12T07:58:14.000Z","updated_at":"2025-02-12T10:48:55.000Z","dependencies_parsed_at":"2025-04-12T04:28:51.993Z","dependency_job_id":"1af1b079-7fce-4f5c-a3c6-9a0aa02d9b30","html_url":"https://github.com/ellado-fbit/express-middleware","commit_stats":{"total_commits":98,"total_committers":2,"mean_commits":49.0,"dds":"0.24489795918367352","last_synced_commit":"2ce64e60e94d72a4a13fefe6570737782c142662"},"previous_names":[],"tags_count":7,"template":false,"template_full_name":null,"purl":"pkg:github/ellado-fbit/express-middleware","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ellado-fbit%2Fexpress-middleware","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ellado-fbit%2Fexpress-middleware/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ellado-fbit%2Fexpress-middleware/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ellado-fbit%2Fexpress-middleware/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/ellado-fbit","download_url":"https://codeload.github.com/ellado-fbit/express-middleware/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ellado-fbit%2Fexpress-middleware/sbom","scorecard":{"id":373241,"data":{"date":"2025-08-11","repo":{"name":"github.com/ellado-fbit/express-middleware","commit":"a3fa64c99a85a4ac67c2ef66c2de8ec8ae6ab0a6"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":2.5,"checks":[{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Token-Permissions","score":-1,"reason":"No tokens found","details":null,"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Dangerous-Workflow","score":-1,"reason":"no workflows found","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Code-Review","score":0,"reason":"Found 0/3 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Pinned-Dependencies","score":-1,"reason":"no dependencies found","details":null,"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE.md:0","Info: FSF or OSI recognized license: MIT License: LICENSE.md:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 27 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":6,"reason":"4 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-968p-4wvh-cqc8","Warn: Project is vulnerable to: GHSA-v6h2-p8h4-qcjw","Warn: Project is vulnerable to: GHSA-3xgq-45jj-v275","Warn: Project is vulnerable to: GHSA-52f5-9888-hmc6"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-18T13:29:05.477Z","repository_id":40764226,"created_at":"2025-08-18T13:29:05.478Z","updated_at":"2025-08-18T13:29:05.478Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":29534932,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-02-17T05:00:25.817Z","status":"ssl_error","status_checked_at":"2026-02-17T04:57:16.126Z","response_time":100,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["express","express-middlewares","ip-address","json-schema","jsonwebtoken","middleware","nodejs"],"created_at":"2024-09-24T19:43:43.165Z","updated_at":"2026-02-17T05:31:56.809Z","avatar_url":"https://github.com/ellado-fbit.png","language":"JavaScript","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Miscellaneous Express middlewares\n\nA miscellaneous collection of Express middlewares.\n\n*Note: For specific Express middleware wrappers for Redis and MongoDB, please visit* [@fundaciobit/express-redis-mongo](https://www.npmjs.com/package/@fundaciobit/express-redis-mongo)\n\n## Middlewares\n\n| middleware         | description                                           |\n|--------------------|-------------------------------------------------------|\n| ipv4               | Extracts IP address and converts IPv6 format to IPv4. |\n| parseTypes         | Parses string properties into numbers or booleans.    |\n| validateJsonSchema | Validates an instance with a provided JSON Schema.    |\n| verifyJWT          | Verify a JSON Web Token.                              |\n| signJWT            | Sign a JSON Web Token.                                |\n\n## Install\n\n```bash\nnpm install @fundaciobit/express-middleware\n```\n\n## Index\n\n- [`ipv4`](#ipv4)\n- [`parseTypes`](#parsetypes)\n- [`validateJsonSchema`](#validatejsonschema)\n- [`verifyJWT`](#verifyjwt)\n- [`signJWT`](#signjwt)\n\n## `ipv4`\n\nMiddleware to extract the IPv4 address from the request object (it converts IPv6 format to IPv4 format). The extracted address will be available on the request via the `ipv4` property.\n\n### Usage\n\n```js\nconst express = require('express')\nconst { ipv4 } = require('@fundaciobit/express-middleware')\n\nconst app = express()\n\napp.use(ipv4())\n\napp.get('/ip', (req, res) =\u003e {\n  const { ipv4 } = req\n  res.json({ ipv4 })\n})\n\napp.use((err, req, res, next) =\u003e {\n  res.status(500).send(err.toString())\n})\n\nconst port = 3000\napp.listen(port, () =\u003e { console.log(`Server running on port ${port}...`) })\n\n```\n\n## `parseTypes`\n\nMiddleware to convert string properties of an object to numbers (integers or floats) or booleans. The provided object will not be mutated. The copied and parsed object will be available on the request via `parsedObject` property.\n\n### Parameters\n\n- `objectToParse`: (*required*) Function that accepts the request object as parameter, that returns the object to parse.\n- `properties`: (*optional*) Array of properties to parse. If not provided, the conversion is applied to all properties of the object.\n\n### Usage\n\n```js\nconst express = require('express')\nconst { parseTypes } = require('@fundaciobit/express-middleware')\n\nconst app = express()\n\napp.get('/users/min_age/:min_age/max_age/:max_age/is_employee/:is_employee/min_salary/:min_salary/max_salary/:max_salary',\n  parseTypes({\n    objectToParse: (req) =\u003e req.params\n  }),\n  (req, res) =\u003e {\n    const { params, parsedObject } = req\n    res.status(200).json({ params, parsedObject })\n  })\n\napp.use((err, req, res, next) =\u003e {\n  if (!err.statusCode) err.statusCode = 500\n  res.status(err.statusCode).send(err.toString())\n})\n\nconst port = 3000\napp.listen(port, () =\u003e { console.log(`Server running on port ${port}...`) })\n\n```\n\n## `validateJsonSchema`\n\nMiddleware to validate the structure of an instance with the provided JSON Schema.\n\n### Parameters\n\n- `schema`: (*required*) is a JSON Schema object.\n- `instanceToValidate`: (*required*) is a function that accepts the request object as parameter, that returns the 'instance' to validate (string, array or object).\n\n### Usage\n\n```js\nconst express = require('express')\nconst bodyParser = require('body-parser')\nconst { validateJsonSchema } = require('@fundaciobit/express-middleware')\n\nconst app = express()\n\napp.use(bodyParser.json())\n\napp.post('/login',\n  validateJsonSchema({\n    schema: {\n      type: 'object',\n      required: ['username', 'password'],\n      properties: {\n        username: { type: 'string' },\n        password: { type: 'string' },\n      },\n      additionalProperties: false\n    },\n    instanceToValidate: (req) =\u003e req.body\n  }),\n  (req, res) =\u003e {\n    res.sendStatus(200)\n  })\n\napp.use((err, req, res, next) =\u003e {\n  if (!err.statusCode) err.statusCode = 500\n  res.status(err.statusCode).send(err.toString())\n})\n\nconst port = 3000\napp.listen(port, () =\u003e { console.log(`Server running on port ${port}...`) })\n\n```\n\n## `verifyJWT`\n\nMiddleware to verify a JSON Web Token. The token to verify is extracted from:\n\n- the `Authorization` header as a bearer token ( `Authorization: Bearer AbCdEf123456` ),\n- or through a `token` query parameter ( `http://...?token=AbCdEf123456` ).\n\nIf the token is verified, then the decoded token payload is available on the request via the `tokenPayload` property, and the control is passed to the next middleware.\n\n### Parameters\n\n- `secret`: (*required*) is a string, buffer, or object containing either the secret for HMAC algorithms or the PEM encoded private key for RSA and ECDSA, as described in [jsonwebtoken](https://www.npmjs.com/package/jsonwebtoken).\n\n### Usage\n\n```js\nconst express = require('express')\nconst { verifyJWT } = require('@fundaciobit/express-middleware')\n\nconst app = express()\n\napp.get('/protected',\n  verifyJWT({ secret: 'my_secret' }),\n  (req, res) =\u003e {\n    res.sendStatus(200)\n  })\n\napp.use((err, req, res, next) =\u003e {\n  if (!err.statusCode) err.statusCode = 500\n  res.status(err.statusCode).send(err.toString())\n})\n\nconst port = 3000\napp.listen(port, () =\u003e { console.log(`Server running on port ${port}...`) })\n\n```\n\n## `signJWT`\n\nMiddleware to sign a JSON Web Token. The signed token will be available on the request via `token` property.\n\n### Parameters\n\n- `payload`: (*required*) is a function that accepts the request object as parameter, that returns an object literal, buffer or string representing valid JSON.\n- `secret`: (*required*) is a string, buffer, or object containing either the secret for HMAC algorithms or the PEM encoded private key for RSA and ECDSA, as described in [jsonwebtoken](https://www.npmjs.com/package/jsonwebtoken).\n- `signOptions`: (*optional*) is an object with extra info to encode, as described in [jsonwebtoken](https://www.npmjs.com/package/jsonwebtoken). `Eg: { expiresIn: '24h' }`\n\n### Usage\n\n```js\nconst express = require('express')\nconst bodyParser = require('body-parser')\nconst { signJWT } = require('@fundaciobit/express-middleware')\n\nconst app = express()\n\napp.use(bodyParser.json())\n\napp.post('/login',\n  // Here include a middleware to verify user credentials from req.body:\n  //  If Ok: set user info in req.user (without password) and call next().\n  //  Else: call next(error) to handle the authentication error.\n  signJWT({\n    payload: (req) =\u003e ({\n      username:  req.user.username,\n      role: req.user.role\n    }),\n    secret: 'my_secret',\n    signOptions: { expiresIn: '24h' }\n  }),\n  (req, res) =\u003e {\n    const { token } = req\n    res.status(200).json({ token })\n  })\n\napp.use((err, req, res, next) =\u003e {\n  if (!err.statusCode) err.statusCode = 500\n  res.status(err.statusCode).send(err.toString())\n})\n\nconst port = 3000\napp.listen(port, () =\u003e { console.log(`Server running on port ${port}...`) })\n\n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fellado-fbit%2Fexpress-middleware","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fellado-fbit%2Fexpress-middleware","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fellado-fbit%2Fexpress-middleware/lists"}