tekir
All Packages
Securityv0.1.5

@tekir/shield

CSRF protection, Content Security Policy, and security headers.

Installation

$bun add @tekir/shield

Features

  • CSRF token generation and validation
  • Content Security Policy with presets
  • Helmet-style security headers (HSTS, X-Frame, etc.)
  • XSS sanitization: sanitize(), escapeHtml()
  • Rate limit header helpers
  • Composable shield() middleware

Quick Example

TypeScript
import { shield, csrf, helmet, csp } from '@tekir/shield'

app.router.use(shield())

// Or compose individually
app.router.use(csrf())
app.router.use(helmet())
app.router.use(csp({ directives: { defaultSrc: ["'self'"] } }))

Changelog

v0.1.5LatestSeptember 16, 2026
  • Shield and CSRF middleware now operate against real Tekir request/response contexts without producing integration-time 500 responses.
  • Published output now uses the shared Node-targeted ESM bundle pipeline with external dependencies and generated TypeScript declarations, while Bun consumers keep the native source export.
v0.1.4July 23, 2026
  • Package metadata now follows the shared compatible 0.1.x dependency range used by this coordinated Tekir release.
v0.1.3July 16, 2026
  • CSRF exception matching now respects path boundaries, preventing a configured path such as /api/public from excluding attacker-chosen prefix lookalikes.
v0.1.2June 13, 2026
  • CSRF tokens are now HMAC-signed when a secret is set. The session stores only the random value and verification recomputes the HMAC and compares in constant time. Verification is now fail-closed: a missing token is rejected instead of being lazily minted as valid.
  • Added rotateCsrfToken(ctx) (call it after login/logout) plus csrf({ rotateOnUse: true }) for one-time rotation after each successful mutation.
  • shield() now applies CSP defaults even when csp is not specified; pass csp: false to disable it. X-Frame-Options is restricted to DENY/SAMEORIGIN (the deprecated ALLOW-FROM is removed), and HSTS preload now defaults to false (opt-in).
  • Found and fixed with Fable.
v0.1.0April 1, 2026
  • Initial release

Other Security packages