# @288-toolkit/hooks

> ```sh npm i @288-toolkit/hooks ```

Latest version **1.5.0** (published 2026-07-16) · MIT license · 0 weekly downloads

## Install

```sh
npm install @288-toolkit/hooks
pnpm add @288-toolkit/hooks
yarn add @288-toolkit/hooks
bun add @288-toolkit/hooks
```

## Health

**Score 60/100 (C)** — status: active.

Positive: esm support; no vulnerabilities; has provenance; recently updated.

Warnings: low downloads; no types.

## Facts

| | |
|---|---|
| Version | 1.5.0 |
| Published | 2026-07-16 |
| First published | 2024-05-02 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | none |
| Module format | ESM |
| Dependencies | 2 |
| Unpacked size | 21.3 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| Provenance | attested (GitHub Actions) |
| GitHub stars | 1 |
| Author | DeuxHuitHuit |
| Maintainers | nitriques |

## Links

- npm: https://www.npmjs.com/package/@288-toolkit/hooks
- Repository: https://github.com/DeuxHuitHuit/288-toolkit
- Homepage: https://github.com/DeuxHuitHuit/288-toolkit/blob/main/packages/hooks/README.md
- Issues: https://github.com/DeuxHuitHuit/288-toolkit/issues
- npm.io page: https://npm.io/package/@288-toolkit/hooks

## Dependencies (2)

- [@288-toolkit/types](https://npm.io/package/@288-toolkit/types.md) 3.1.0
- [@288-toolkit/strings](https://npm.io/package/@288-toolkit/strings.md) 4.3.1

## Recent versions

- 1.5.0 (latest) — 2026-07-16
- 1.4.1 — 2025-05-06
- 1.4.0 — 2025-04-09
- 1.3.0 — 2025-04-09
- 1.2.1 — 2025-03-17
- 1.2.0 — 2025-03-17
- 1.1.1 — 2025-02-12
- 1.1.0 — 2025-02-07
- 1.0.4 — 2025-02-04
- 1.0.3 — 2025-02-03
- 1.0.2 — 2024-05-16
- 1.0.1 — 2024-05-02
- 1.0.0 — 2024-05-02

## README

# Hooks

```sh
npm i @288-toolkit/hooks
```

A collection of Sveltekit hooks.

## `server`

### `date`

Replaces a marker in the html response with the current date. The default marker is `%request.date%`
but can be customized via options.

```ts
export const handle = sequence(
	date({
		marker: '%my-custom-marker%'
	})
);
```

### `httpAuth`

HTTP Basic Auth middleware.

You must provide an auth string in the form of 'username:password'.

You can also disable the handle by passing `enabled: false`. This is useful for disabling auth when
the app is building.

```ts
import { building } from '$app/environment';

export const handle = sequence(httpAuth({ authString: 'username:password', enabled: !building }));
```

### `performanceHeaders`

Adds custom headers to the response to measure the performance of requests.

The added headers are:

-   `x-request-id`: An id to identify the request.
-   `x-response-time`: The response time of the request.

### `preloads`

Preloads css, js, and font files.

### `preflightCheck`

Checks if the request is allowed to be served by the server.

Returns empty responses to pathname that could be used to attack the server, including:

-   `.zip`
-   `.rar`
-   `.tar`
-   `.tar.gz`
-   `.7z`
-   `.sql`
-   `.db`
-   `.ini`
-   `.log`
-   `.php`
-   `.html`
-   `.htm`
-   `.aspx`
-   `.pdf`
-   `.doc`
-   `.docx`
-   `.xsl`
-   `.xslx`
-   `wp-content`
-   `wp-includes`

Returns empty responses to pathnames that are under `\_app/immutable`. Those requests will never be
served by the edge/serverless function, so we can save bandwidth and time when they do hit the
function.

Returns empty responses to requests to service worker file. We have seen this in the wild, and it
seems to be a problem on iOS devices.

### `securityHeaders`

Adds security headers to the response.

The following headers are added by default:

-   `x-xss-protection`: '1; mode=block'
-   `x-frame-options`: 'SAMEORIGIN'
-   `x-content-type-options`: 'nosniff'
-   `referrer-policy`: 'strict-origin-when-cross-origin'

The `x-frame-options` header prevents any pages from being embedded inside an iframe. To allow some
urls to do that, use the `allowedFrameAncestors`:

```ts
export const handle = sequence(
	securityHeaders({
		allowedFrameAncestors: ['https://my-url.com', 'https://another-url.com']
	})
);
```

This will add the following header:

-   `content-security-policy`, "frame-ancestors 'self' https://my-url.com https://another-url.com"

### `createSiteRouter()`

Creates a site router handle.

```ts
import { createSiteRouter } from '@288-toolkit/hooks/server';

export const handle = sequence(
	createSiteRouter({
		defaultSiteUri: 'en',
		defaultEntryUri: '__home-page__'
	})
);
```

The following options are available:

-   `defaultSiteUri`: The default site uri, when the pathname is empty.
-   `defaultEntryUri`: The default entry uri, when the pathname is empty.
-   `siteHandle`: A function to format the site handle.
-   `pathnameSplitter`: A function to split the pathname into site and entry parts.
-   `partsToSiteRouterObject`: A function to convert the parts into a site router object.

---
_Source: https://npm.io/package/@288-toolkit/hooks · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
