# fi-security

> Security component for Node.js Express applications

Latest version **3.0.0** (published 2019-12-31) · MIT license · 0 weekly downloads

> **Deprecated.** This package is deprecated.

## Install

```sh
npm install fi-security
pnpm add fi-security
yarn add fi-security
bun add fi-security
```

## Health

**Score 10/100 (F)** — status: deprecated.

Negative: deprecated.

## Facts

| | |
|---|---|
| Version | 3.0.0 |
| Published | 2019-12-31 |
| First published | 2015-12-23 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | none |
| Module format | CommonJS |
| Node | 12 |
| Dependencies | 2 |
| Unpacked size | 100.6 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| GitHub stars | 0 |
| Author | DOT |
| Maintainers | leonardo.ramos, stgogm |
| Keywords | component, security, express, exclude, fi-seed, x-frame, xframe, aegis, xsrf, hsts, csrf, csp, p3p, xss |

## Links

- npm: https://www.npmjs.com/package/fi-security
- Repository: https://github.com/dotstudio-io/fi-security
- Homepage: https://github.com/dotstudio-io/fi-security#readme
- Issues: https://github.com/dotstudio-io/fi-security/issues
- npm.io page: https://npm.io/package/fi-security

## Dependencies (2)

- [fi-is](https://npm.io/package/fi-is.md) ^4.0.0
- [fi-aegis](https://npm.io/package/fi-aegis.md) ^2.0.1

## Recent versions

- 3.0.0 (latest) — 2019-12-31
- 2.0.3 — 2019-12-31
- 2.0.1 — 2019-12-31
- 2.0.0 — 2018-11-12
- 1.2.0 — 2017-07-28
- 1.1.1 — 2016-12-29
- 1.1.0 — 2016-12-29
- 1.0.0 — 2015-12-23

## README

# Fi Security

Application security module for Node.js Express applications.

## Installing

```sh
npm install --save fi-security
```

## Usage

### Initialization

You must call it with your Express' application instance, to attach the routes, and a configuration object. It's important to initialize the Express' session before you configure **Fi Security**:

```js
var session = require('express-session');
var security = require('fi-security');
var express = require('express');

var app = express();

app.use(session());

security(app, config);

/* And now your routes... */
app.get('/', (req, res, next) => {
  //...
});
```

### Configuration

The configuration `Object` must be pretty much like a [Fi Aegis](https://github.com/FinalDevStudio/fi-aegis#api) configuration `Object`, since this module is based on it.

- **debug**: This option can be a `Function` to log with or a `Boolean`. If `true` it'll use `console.log`.
- **csrf**: Same as [Fi Aegis](https://github.com/FinalDevStudio/fi-aegis#cross-site-request-forgery) with the addition of the `exclude` property:
  - **exclude**: An array of routes with their method(s) and path(s) to be excluded from `CSRF` checks:
    - **method**: A single `POST`, `PUT` or `DELETE` method or an array of them. Empty means `ALL`.
    - **path**: A valid [Express route path](http://expressjs.com/en/guide/routing.html#route-paths).
- **csp**: Same as [Fi Aegis](https://github.com/FinalDevStudio/fi-aegis#content-security-policy).
- **xframe**: Same as [Fi Aegis](https://github.com/FinalDevStudio/fi-aegis#x-frame-options).
- **hsts**: Same as [Fi Aegis](https://github.com/FinalDevStudio/fi-aegis#http-strict-transport-security).
- **nosniff**: Same as [Fi Aegis](https://github.com/FinalDevStudio/fi-aegis#x-content-type-options).
- **xssProtection**: Same as [Fi Aegis](https://github.com/FinalDevStudio/fi-aegis#x-xss-protection).
- **p3p**: Same as [Fi Aegis](https://github.com/FinalDevStudio/fi-aegis#platform-for-privacy-preferences-p3p-project).

#### Example configuration

```js
{
  debug: true,

  p3p: 'ABCDEF',

  csrf: {
    exclude: [{
      method: 'POST',
      path: '/no-csrf'
    }, {
      path: '/api/external'
    }]
  },

  xframe: 'DENY',

  xssProtection: {
    enabled: true
  },

  csp: {
    reportUri: 'https://example.com',
    policy: {
      'default-src': "'self'"
    }
  },

  hsts: {
    includeSubDomains: true,
    maxAge: 31536000
  },

  nosniff: true
}
```

### Using with AngularJS

Just add this to your **Fi Security** configuration:

```js
//...

csrf: {
  angular: true
  //...
}

//...
```

See [this](https://docs.angularjs.org/api/ng/service/$http#cross-site-request-forgery-xsrf-protection) for more information regarding AngularJS' XSRF approach.

---
_Source: https://npm.io/package/fi-security · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
