# connect-block-hotlinks

> Middleware for blocking cross-origin requests (hotlinks)

Latest version **1.0.0** (published 2015-10-07) · MIT license · 0 weekly downloads

## Install

```sh
npm install connect-block-hotlinks
pnpm add connect-block-hotlinks
yarn add connect-block-hotlinks
bun add connect-block-hotlinks
```

## Health

**Score 15/100 (F)** — status: abandoned.

Positive: no vulnerabilities.

Warnings: low downloads; no types; no esm support.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 1.0.0 |
| Published | 2015-10-07 |
| First published | 2015-10-07 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | none |
| Module format | CommonJS |
| Dependencies | 0 |
| Known vulnerabilities | 0 |
| Install scripts | no |
| GitHub stars | 1 |
| Author | William Hilton |
| Maintainers | wmhilton |
| Keywords | hotlink, hotlinking, block, protect, images |

## Links

- npm: https://www.npmjs.com/package/connect-block-hotlinks
- Repository: https://github.com/wmhilton/connect-block-hotlinks
- Homepage: https://github.com/wmhilton/connect-block-hotlinks#readme
- Issues: https://github.com/wmhilton/connect-block-hotlinks/issues
- npm.io page: https://npm.io/package/connect-block-hotlinks

## Alternatives

- [exif-parser](https://npm.io/package/exif-parser.md) — 3.8M weekly downloads
- [vite-plugin-compression](https://npm.io/package/vite-plugin-compression.md) — 569.5K weekly downloads
- [pica](https://npm.io/package/pica.md) — 442.4K weekly downloads
- [@reportportal/client-javascript](https://npm.io/package/@reportportal/client-javascript.md) — 408.8K weekly downloads
- [@tldraw/state](https://npm.io/package/@tldraw/state.md) — 316.0K weekly downloads

## Recent versions

- 1.0.0 (latest) — 2015-10-07

## README

# connect-block-hotlinks

I wrote this middleware to keep people from embedding my site's images into their own sites.
It compares the HTTP headers `Host` and `Referer` to make sure they are from the same 2nd-level domain.
For example, if Host is `img.example.com` then referer can be `http://example.com/` or `http://blog.example.com/`
but not `http://another.com/`.

This will not stop a determined attacker! For that you should use CORS and authentication mechanisms. But it will
prevent people stealing your bandwidth by using a URL to your image in the 'src' of an <image> tag on another site.

## API

It follows a classic Connect/Express middleware pattern:

```
var express = require('express');
var blockHotlinks = require('connect-block-hotlinks');

var app = express();
app.use "/img/*", blockHotlinks
```

Depending on the request, the middleware will either:

- do nothing, and call next() so the route can be handled by the next route handler.
- return a 403 Forbidden "Missing 'Host' HTTP Header"
- return a 403 Forbidden "Missing 'Referer' HTTP Header"
- return a 200 OK hotlinking-disallowed.png

---
_Source: https://npm.io/package/connect-block-hotlinks · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
