Securityv0.1.5
@tekir/shield
CSRF protection, Content Security Policy, and security headers.
Installation
$
bun add @tekir/shieldFeatures
- CSRF token generation and validation
- Content Security Policy with presets
- Helmet-style security headers (HSTS, X-Frame, etc.)
- XSS sanitization: sanitize(), escapeHtml()
- Rate limit header helpers
- Composable shield() middleware
Quick Example
TypeScript
import { shield, csrf, helmet, csp } from '@tekir/shield'
app.router.use(shield())
// Or compose individually
app.router.use(csrf())
app.router.use(helmet())
app.router.use(csp({ directives: { defaultSrc: ["'self'"] } }))Changelog
v0.1.5LatestSeptember 16, 2026
- Shield and CSRF middleware now operate against real Tekir request/response contexts without producing integration-time 500 responses.
- Published output now uses the shared Node-targeted ESM bundle pipeline with external dependencies and generated TypeScript declarations, while Bun consumers keep the native source export.
v0.1.4July 23, 2026
- Package metadata now follows the shared compatible
0.1.xdependency range used by this coordinated Tekir release.
v0.1.3July 16, 2026
- CSRF exception matching now respects path boundaries, preventing a configured path such as
/api/publicfrom excluding attacker-chosen prefix lookalikes.
v0.1.2June 13, 2026
- CSRF tokens are now HMAC-signed when a
secretis set. The session stores only the random value and verification recomputes the HMAC and compares in constant time. Verification is now fail-closed: a missing token is rejected instead of being lazily minted as valid. - Added
rotateCsrfToken(ctx)(call it after login/logout) pluscsrf({ rotateOnUse: true })for one-time rotation after each successful mutation. shield()now applies CSP defaults even whencspis not specified; passcsp: falseto disable it.X-Frame-Optionsis restricted toDENY/SAMEORIGIN(the deprecatedALLOW-FROMis removed), and HSTSpreloadnow defaults tofalse(opt-in).- Found and fixed with Fable.
v0.1.0April 1, 2026
- Initial release