Storage & Parsingv0.1.4
@tekir/static
Static file serving with ETags, MIME detection, and Cache-Control.
Installation
$
bun add @tekir/staticFeatures
- Serve static files from a directory
- ETag generation for cache validation
- Automatic MIME type detection
- Cache-Control header support
- StaticProvider for DI registration
Quick Example
TypeScript
import { serveStatic } from '@tekir/static'
app.router.use(serveStatic({
root: './public',
maxAge: 86400,
}))Changelog
v0.1.4LatestSeptember 16, 2026
- Published output now uses the shared Node-targeted ESM bundle pipeline with external dependencies and generated TypeScript declarations, while Bun consumers keep the native source export.
v0.1.3July 23, 2026
- Package metadata now follows the shared compatible
0.1.xdependency range used by this coordinated Tekir release.
v0.1.2June 13, 2026
- A decoded path containing a null byte is now rejected as malformed instead of reaching the filesystem.
- Symlink traversal is now blocked when opted in. With
symlinks: 'deny', the resolved real path is verified to stay under the root in both the middleware and the provider fallback (default stays'follow'for backward compatibility). - A read error mid-request now falls through to
next()instead of crashing, and the docs call out thatdotFiles: 'allow'will serve.env/.git. - Found and fixed with Fable.
v0.1.1May 17, 2026
- Malformed percent-encoded paths (
/foo%, truncated sequences) now respond with400 Bad Requestinstead of crashing the request with a generic 500. The decode step is wrapped and the failure reason is surfaced to the caller. - Dotfile policy now applies to every path segment, not just the trailing filename. With the default
dotFiles: 'ignore'setting,GET /.git/configandGET /.env/foono longer reach the filesystem;dotFiles: 'deny'returns403 Forbiddenfor the same paths, anddotFiles: 'allow'opts into the previous behaviour for use cases like.well-known/. - The segment scan recognises both
/and\\as separators. Windows previously accepted backslash-encoded requests likeGET /assets%5C.git/configbecause the runtime resolves\\as a path separator while the dotfile filter only split on/. POSIX behaviour is unchanged. - Windows cross-drive paths are now blocked. A request whose decoded path resolves to a different drive than the configured
diris treated as traversal even whenrelative()does not return a..-prefixed result. POSIX behaviour is unchanged. - The middleware and the
StaticProviderfallback now share a singleresolveSafePath()helper so both surfaces apply the same encoding, dotfile, and traversal rules.
v0.1.0April 1, 2026
- Initial release