tekir
All Packages
Storage & Parsingv0.1.4

@tekir/static

Static file serving with ETags, MIME detection, and Cache-Control.

Installation

$bun add @tekir/static

Features

  • Serve static files from a directory
  • ETag generation for cache validation
  • Automatic MIME type detection
  • Cache-Control header support
  • StaticProvider for DI registration

Quick Example

TypeScript
import { serveStatic } from '@tekir/static'

app.router.use(serveStatic({
  root: './public',
  maxAge: 86400,
}))

Changelog

v0.1.4LatestSeptember 16, 2026
  • Published output now uses the shared Node-targeted ESM bundle pipeline with external dependencies and generated TypeScript declarations, while Bun consumers keep the native source export.
v0.1.3July 23, 2026
  • Package metadata now follows the shared compatible 0.1.x dependency range used by this coordinated Tekir release.
v0.1.2June 13, 2026
  • A decoded path containing a null byte is now rejected as malformed instead of reaching the filesystem.
  • Symlink traversal is now blocked when opted in. With symlinks: 'deny', the resolved real path is verified to stay under the root in both the middleware and the provider fallback (default stays 'follow' for backward compatibility).
  • A read error mid-request now falls through to next() instead of crashing, and the docs call out that dotFiles: 'allow' will serve .env/.git.
  • Found and fixed with Fable.
v0.1.1May 17, 2026
  • Malformed percent-encoded paths (/foo%, truncated sequences) now respond with 400 Bad Request instead of crashing the request with a generic 500. The decode step is wrapped and the failure reason is surfaced to the caller.
  • Dotfile policy now applies to every path segment, not just the trailing filename. With the default dotFiles: 'ignore' setting, GET /.git/config and GET /.env/foo no longer reach the filesystem; dotFiles: 'deny' returns 403 Forbidden for the same paths, and dotFiles: 'allow' opts into the previous behaviour for use cases like .well-known/.
  • The segment scan recognises both / and \\ as separators. Windows previously accepted backslash-encoded requests like GET /assets%5C.git/config because the runtime resolves \\ as a path separator while the dotfile filter only split on /. POSIX behaviour is unchanged.
  • Windows cross-drive paths are now blocked. A request whose decoded path resolves to a different drive than the configured dir is treated as traversal even when relative() does not return a ..-prefixed result. POSIX behaviour is unchanged.
  • The middleware and the StaticProvider fallback now share a single resolveSafePath() helper so both surfaces apply the same encoding, dotfile, and traversal rules.
v0.1.0April 1, 2026
  • Initial release

Other Storage & Parsing packages