npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2024 – Pkg Stats / Ryan Hefner

@cityssm/express-abuse-points

v3.0.0

Published

Express.js middleware for tracking and blocking abusive behaviour.

Downloads

129

Readme

express-abuse-points

npm DeepSource Code Climate maintainability codecov Coverage Testing

Express.js middleware for tracking and blocking abusive behaviour.

Need to block a user repeatedly entering incorrect passwords into a login form?

Need to stop a user testing invalid product SKUs and coupon codes in an online store?

Need to discourage a user from testing out functions they don't have permission to use?

This middleware is for you!

Installation

npm install @cityssm/express-abuse-points

Usage

It is recommended to include the middleware as early as possible in the middleware chain to enforce the block as soon as possible.

Initializing

import { abuseCheck } from '@cityssm/express-abuse-points'

app.use(abuseCheck())

Recording Abuse

import { recordAbuse } from '@cityssm/express-abuse-points'

if (userDidSomethingBad) {
  recordAbuse(req, 3)
}

API

abuseCheck([options: {}])

The function to include in the Express application setup to initialize the middleware. It accepts the following options.

| Property Name | Description | Default Value | | ----------------------- | ----------------------------------------------------------------------------------------------- | ----------------------- | | byIP | Whether or not abuse points should be tracked by IP address. | true | | byXForwardedFor | Whether or not abuse points should be tracked by the X-Forwarded-For header (proxy situations). | false | | abusePoints | The default number of points assigned to an abuse event. | 1 | | expiryMillis | The default number of milliseconds an abuse record is enforced before expiring. | 300000 (five minutes) | | abusePointsMax | The total number of points a user can accumulate before being blocked. | 10 | | clearIntervalMillis | The frequency the memory is cleared of expired abuse records. | 3600000 |

recordAbuse(req: Request, [abusePoints: number, [expiryMillis: number]])

The function to include in the Express handlers to record abusive behaviours.

An optional abusePoints parameter is available if the record should have more or less weight than the default abusePoints.

An optional expiryMillis parameter is available if the record should expiry sooner or later than the default expiryMillis.

isAbuser(req: Request)

Returns true if the given requestor has reached the abuse points threshold.

clearAbuse(req: Request)

Clears all abuse records for the given requestor, expired or not. Helpful if, for example, abuse was tracked for incorrect password attempts, but the user was finally successful.