express

typescript
import { randomBytes } from 'crypto';
import { Request, Response, NextFunction } from 'express';

interface CspOptions {
  reportOnly?: boolean;
  reportUri?: string;

Content Security Policy headers (defense-in-depth)

security express csp
by codesnips 3 tabs
typescript
import { z } from "zod";

const coerceNumber = z.preprocess((v) => {
  if (v === "" || v === undefined) return undefined;
  if (typeof v !== "string") return v;
  const n = Number(v);

API input coercion for query params (Zod preprocess)

typescript validation api
by codesnips 3 tabs
javascript
const { pool } = require('./db');

async function recordEvent(client, { eventId, type, payload }) {
  const { rows } = await client.query(
    `INSERT INTO webhook_events (event_id, type, payload, status)
     VALUES ($1, $2, $3, 'received')

Idempotent Stripe Webhook Processing With an Express Event-Store Middleware

express webhooks idempotency
by codesnips 3 tabs
javascript
const pino = require('pino');
const { AsyncLocalStorage } = require('async_hooks');

const als = new AsyncLocalStorage();

const logger = pino({

Request-Scoped Correlation ID Middleware and Child Logger in Express

express middleware logging
by codesnips 3 tabs
javascript
const rolePermissions = {
  guest: ['article:read'],
  author: ['article:read', 'article:create', 'article:update:own'],
  editor: ['article:publish', 'article:update:any'],
  admin: ['user:manage', 'role:assign']
};

Role-Based Access Control in Express with Permission Middleware and Protected Routes

express rbac authorization
by codesnips 3 tabs