🚀 Major Improvements & Changes
-
Full Support for Express v5
Middleware now officially supports Express 5 alongside Express 4.
Adaptations and fixes applied to ensure compatibility and seamless usage across both major versions. -
Enhanced Debug Logging & Diagnostics
Introduced a configurable debugging system with multiple log levels:silent,error,warn,info,debug, andtrace.
Logs can include detailed info on:
- Sanitization operations on request objects (
body,query,params). - Pattern matches triggering sanitization.
- Skipped routes and keys.
- Parameter sanitization changes.
Added colored and timestamped console output for easier troubleshooting during development.
-
Modular Refactoring & Code Quality
Extracted constants (patterns, defaults, log levels/colors) into dedicated immutable objects (Object.freeze).
Extensive JSDoc documentation added throughout for better maintainability and IDE support.
Cleaner and consistent code style across all sanitization utilities and middleware logic. -
Custom Sanitizer & Manual Sanitization Mode
Users can now provide a custom sanitizer function for full control over sanitization logic.
Manual mode exposes areq.sanitize()function to sanitize on-demand rather than auto on every request. -
Comprehensive Option Validation
Robust validation of options passed to the middleware with detailed error throwing.
Support for new options including:
debugconfig withenabled,level, andlogSkippedRoutes.- Granular control over
allowedKeys/deniedKeys. - Recursive sanitization toggling.
- String and array options refined and extended.
-
Param Sanitizer Middleware
AddedparamSanitizeHandlermiddleware factory for sanitizing route parameters.
Logs sanitized parameters with before/after values if debug is enabled. -
Improved Handling of Edge Cases
Email addresses are preserved and not sanitized unintentionally.
Empty objects and keys removed whenremoveEmptyis enabled.
Filtering and deduplication of arrays with detailed debug logs.
Enhanced detection of writable properties to safely mutate request objects.
📋 Breaking Changes
None. All improvements are backward-compatible with version 1.0.0.
📝 Summary
Upgraded from version 1.0.0 to 1.1.0.
Major new debug infrastructure added.
Express v5 support finalized.
Added manual sanitization mode and param handler.
Improved code modularity and documentation.
All previous options retained and enhanced.
📦 Installation
npm install @exortek/express-mongo-sanitize@1.1.0🛠️ Usage Example with Debugging Enabled
const express = require('express');
const expressMongoSanitize = require('@exortek/express-mongo-sanitize');
const app = express();
app.use(express.json());
app.use(expressMongoSanitize({
debug: {
enabled: true,
level: 'debug', // Trace, debug, info, warn, error, silent
logSkippedRoutes: true,
},
mode: 'auto',
skipRoutes: ['/healthcheck'],
}));
app.listen(3000);Full Changelog: v1.0.0...v1.1.x