Skip to content

v1.1.x

Latest

Choose a tag to compare

@ExorTek ExorTek released this 16 Jun 02:21
· 2 commits to master since this release

🚀 Major Improvements & Changes

  1. Full Support for Express v5
    Middleware now officially supports Express 5 alongside Express 4.
    Adaptations and fixes applied to ensure compatibility and seamless usage across both major versions.

  2. Enhanced Debug Logging & Diagnostics
    Introduced a configurable debugging system with multiple log levels: silent, error, warn, info, debug, and trace.

Logs can include detailed info on:

  • Sanitization operations on request objects (body, query, params).
  • Pattern matches triggering sanitization.
  • Skipped routes and keys.
  • Parameter sanitization changes.

Added colored and timestamped console output for easier troubleshooting during development.

  1. Modular Refactoring & Code Quality
    Extracted constants (patterns, defaults, log levels/colors) into dedicated immutable objects (Object.freeze).
    Extensive JSDoc documentation added throughout for better maintainability and IDE support.
    Cleaner and consistent code style across all sanitization utilities and middleware logic.

  2. Custom Sanitizer & Manual Sanitization Mode
    Users can now provide a custom sanitizer function for full control over sanitization logic.
    Manual mode exposes a req.sanitize() function to sanitize on-demand rather than auto on every request.

  3. Comprehensive Option Validation
    Robust validation of options passed to the middleware with detailed error throwing.
    Support for new options including:

  • debug config with enabled, level, and logSkippedRoutes.
  • Granular control over allowedKeys / deniedKeys.
  • Recursive sanitization toggling.
  • String and array options refined and extended.
  1. Param Sanitizer Middleware
    Added paramSanitizeHandler middleware factory for sanitizing route parameters.
    Logs sanitized parameters with before/after values if debug is enabled.

  2. Improved Handling of Edge Cases
    Email addresses are preserved and not sanitized unintentionally.
    Empty objects and keys removed when removeEmpty is enabled.
    Filtering and deduplication of arrays with detailed debug logs.
    Enhanced detection of writable properties to safely mutate request objects.


📋 Breaking Changes

None. All improvements are backward-compatible with version 1.0.0.


📝 Summary

Upgraded from version 1.0.0 to 1.1.0.
Major new debug infrastructure added.
Express v5 support finalized.
Added manual sanitization mode and param handler.
Improved code modularity and documentation.
All previous options retained and enhanced.


📦 Installation

npm install @exortek/express-mongo-sanitize@1.1.0

🛠️ Usage Example with Debugging Enabled

const express = require('express');
const expressMongoSanitize = require('@exortek/express-mongo-sanitize');

const app = express();

app.use(express.json());

app.use(expressMongoSanitize({
  debug: {
    enabled: true,
    level: 'debug',        // Trace, debug, info, warn, error, silent
    logSkippedRoutes: true,
  },
  mode: 'auto',
  skipRoutes: ['/healthcheck'],
}));

app.listen(3000);

Full Changelog: v1.0.0...v1.1.x