mirror of
https://github.com/gosticks/DefinitelyTyped.git
synced 2026-10-04 06:47:03 +00:00
Reviewing Routes type implementation.
This commit is contained in:
+27
-26
@@ -1,33 +1,34 @@
|
||||
/**
|
||||
Default value: false (security headers disabled).
|
||||
Sets common security headers. To enable, set security to true or to an object with the following options:
|
||||
hsts - controls the 'Strict-Transport-Security' header, where:
|
||||
true - the header will be set to max-age=15768000. This is the default value.
|
||||
a number - the maxAge parameter will be set to the provided value.
|
||||
an object with the following fields:
|
||||
maxAge - the max-age portion of the header, as a number. Default is 15768000.
|
||||
includeSubDomains - a boolean specifying whether to add the includeSubDomains flag to the header.
|
||||
preload - a boolean specifying whether to add the 'preload' flag (used to submit domains inclusion in Chrome's HTTP Strict Transport Security (HSTS) preload list) to the header.
|
||||
xframe - controls the 'X-Frame-Options' header, where:
|
||||
true - the header will be set to 'DENY'. This is the default value.
|
||||
'deny' - the headers will be set to 'DENY'.
|
||||
'sameorigin' - the headers will be set to 'SAMEORIGIN'.
|
||||
an object for specifying the 'allow-from' rule, where:
|
||||
rule - one of:
|
||||
'deny'
|
||||
'sameorigin'
|
||||
'allow-from'
|
||||
source - when rule is 'allow-from' this is used to form the rest of the header, otherwise this field is ignored. If rule is 'allow-from' but source is unset, the rule will be automatically changed to 'sameorigin'.
|
||||
xss - boolean that controls the 'X-XSS-PROTECTION' header for Internet Explorer. Defaults to true which sets the header to equal '1; mode=block'.
|
||||
Note: this setting can create a security vulnerability in versions of Internet Exploere below 8, as well as unpatched versions of IE8. See here and here for more information. If you actively support old versions of IE, it may be wise to explicitly set this flag to false.
|
||||
noOpen - boolean controlling the 'X-Download-Options' header for Internet Explorer, preventing downloads from executing in your context. Defaults to true setting the header to 'noopen'.
|
||||
noSniff - boolean controlling the 'X-Content-Type-Options' header. Defaults to true setting the header to its only and default option, 'nosniff'.
|
||||
* Default value: false (security headers disabled).
|
||||
* Sets common security headers. To enable, set security to true or to an object with the following options:
|
||||
* * hsts - controls the 'Strict-Transport-Security' header, where:
|
||||
* * * true - the header will be set to max-age=15768000. This is the default value.
|
||||
* * * a number - the maxAge parameter will be set to the provided value.
|
||||
* * * an object with the following fields:
|
||||
* * * * maxAge - the max-age portion of the header, as a number. Default is 15768000.
|
||||
* * * * includeSubDomains - a boolean specifying whether to add the includeSubDomains flag to the header.
|
||||
* * * * preload - a boolean specifying whether to add the 'preload' flag (used to submit domains inclusion in Chrome's HTTP Strict Transport Security (HSTS) preload list) to the header.
|
||||
* * xframe - controls the 'X-Frame-Options' header, where:
|
||||
* * * true - the header will be set to 'DENY'. This is the default value.
|
||||
* * * 'deny' - the headers will be set to 'DENY'.
|
||||
* * * 'sameorigin' - the headers will be set to 'SAMEORIGIN'.
|
||||
* * * an object for specifying the 'allow-from' rule, where:
|
||||
* * * * rule - one of:
|
||||
* * * * * 'deny'
|
||||
* * * * * 'sameorigin'
|
||||
* * * * * 'allow-from'
|
||||
* * * * source - when rule is 'allow-from' this is used to form the rest of the header, otherwise this field is ignored. If rule is 'allow-from' but source is unset, the rule will be automatically changed to 'sameorigin'.
|
||||
* * xss - boolean that controls the 'X-XSS-PROTECTION' header for Internet Explorer. Defaults to true which sets the header to equal '1; mode=block'.
|
||||
* Note: this setting can create a security vulnerability in versions of Internet Exploere below 8, as well as unpatched versions of IE8. See here and here for more information. If you actively support old versions of IE, it may be wise to explicitly set this flag to false.
|
||||
* * noOpen - boolean controlling the 'X-Download-Options' header for Internet Explorer, preventing downloads from executing in your context. Defaults to true setting the header to 'noopen'.
|
||||
* * noSniff - boolean controlling the 'X-Content-Type-Options' header. Defaults to true setting the header to its only and default option, 'nosniff'.
|
||||
* [See docs](https://github.com/hapijs/hapi/blob/master/API.md#-routeoptionssecurity)
|
||||
*/
|
||||
export interface RouteOptionsSecureObject {
|
||||
hsts?: boolean | number | {
|
||||
maxAge?: number;
|
||||
includeSubdomains?: boolean;
|
||||
preload?: boolean;
|
||||
maxAge: number;
|
||||
includeSubdomains: boolean;
|
||||
preload: boolean;
|
||||
};
|
||||
xframe?: true | 'deny' | 'sameorigin' | {
|
||||
rule: 'deny' | 'sameorigin' | 'allow-from';
|
||||
|
||||
+62
-56
@@ -1,86 +1,92 @@
|
||||
import {Lifecycle} from "hapi";
|
||||
import {ValidationOptions} from "joi";
|
||||
|
||||
/**
|
||||
Default value: { headers: true, params: true, query: true, payload: true, failAction: 'error' }.
|
||||
Request input validation rules for various request components.
|
||||
* Default value: { headers: true, params: true, query: true, payload: true, failAction: 'error' }.
|
||||
* Request input validation rules for various request components.
|
||||
* [See docs](https://github.com/hapijs/hapi/blob/master/API.md#-routeoptionsvalidate)
|
||||
*/
|
||||
export interface RouteOptionsValidate {
|
||||
|
||||
/**
|
||||
Default value: none.
|
||||
An optional object with error fields copied into every validation error response.
|
||||
* Default value: none.
|
||||
* An optional object with error fields copied into every validation error response.
|
||||
* [See docs](https://github.com/hapijs/hapi/blob/master/API.md#-routeoptionsvalidateerrorfields)
|
||||
*/
|
||||
errorFields?: any;
|
||||
|
||||
/**
|
||||
Default value: 'error' (return a Bad Request (400) error response).
|
||||
A failAction value which determines how to handle failed validations. When set to a function, the err argument includes the type of validation error under err.output.payload.validation.source.
|
||||
* Default value: 'error' (return a Bad Request (400) error response).
|
||||
* A failAction value which determines how to handle failed validations. When set to a function, the err argument includes the type of validation error under err.output.payload.validation.source.
|
||||
* [See docs](https://github.com/hapijs/hapi/blob/master/API.md#-routeoptionsvalidatefailaction)
|
||||
*/
|
||||
failAction?: Lifecycle.FailAction;
|
||||
|
||||
/**
|
||||
Default value: true (no validation).
|
||||
Validation rules for incoming request headers:
|
||||
true - any headers allowed (no validation performed).
|
||||
a joi validation object.
|
||||
a validation function using the signature async function(value, options) where:
|
||||
value - the request.headers object containing the request headers.
|
||||
options - options.
|
||||
if a value is returned, the value is used as the new request.headers value and the original value is stored in request.orig.headers. Otherwise, the headers are left unchanged. If an error is thrown, the error is handled according to failAction.
|
||||
Note that all header field names must be in lowercase to match the headers normalized by node.
|
||||
* Default value: true (no validation).
|
||||
* Validation rules for incoming request headers:
|
||||
* * true - any headers allowed (no validation performed).
|
||||
* * a joi validation object.
|
||||
* * a validation function using the signature async function(value, options) where:
|
||||
* * * value - the request.headers object containing the request headers.
|
||||
* * * options - options.
|
||||
* * * if a value is returned, the value is used as the new request.headers value and the original value is stored in request.orig.headers. Otherwise, the headers are left unchanged. If an error is thrown, the error is handled according to failAction.
|
||||
* Note that all header field names must be in lowercase to match the headers normalized by node.
|
||||
* [See docs](https://github.com/hapijs/hapi/blob/master/API.md#-routeoptionsvalidateheaders)
|
||||
*/
|
||||
headers?: boolean | any; // TODO need to implementation. Here is JOI and more.
|
||||
headers?: boolean | ValidationOptions | ((value: any, option: any) => Function);
|
||||
|
||||
/**
|
||||
Default value: none.
|
||||
An options object passed to the joi rules or the custom validation methods. Used for setting global options such as stripUnknown or abortEarly (the complete list is available here).
|
||||
If a custom validation function (see headers, params, query, or payload above) is defined then options can an arbitrary object that will be passed to this function as the second parameter.
|
||||
The values of the other inputs (i.e. headers, query, params, payload, app, and auth) are added to the options object under the validation context (accessible in rules as Joi.ref('$query.key')).
|
||||
Note that validation is performed in order (i.e. headers, params, query, and payload) and if type casting is used (e.g. converting a string to a number), the value of inputs not yet validated will reflect the raw, unvalidated and unmodified values.
|
||||
If the validation rules for headers, params, query, and payload are defined at both the server routes level and at the route level, the individual route settings override the routes defaults (the rules are not merged).
|
||||
* Default value: none.
|
||||
* An options object passed to the joi rules or the custom validation methods. Used for setting global options such as stripUnknown or abortEarly (the complete list is available here).
|
||||
* If a custom validation function (see headers, params, query, or payload above) is defined then options can an arbitrary object that will be passed to this function as the second parameter.
|
||||
* The values of the other inputs (i.e. headers, query, params, payload, app, and auth) are added to the options object under the validation context (accessible in rules as Joi.ref('$query.key')).
|
||||
* Note that validation is performed in order (i.e. headers, params, query, and payload) and if type casting is used (e.g. converting a string to a number), the value of inputs not yet validated will reflect the raw, unvalidated and unmodified values.
|
||||
* If the validation rules for headers, params, query, and payload are defined at both the server routes level and at the route level, the individual route settings override the routes defaults (the rules are not merged).
|
||||
* [See docs](https://github.com/hapijs/hapi/blob/master/API.md#-routeoptionsvalidateparams)
|
||||
*/
|
||||
options?: any; // TODO need to be implementation
|
||||
options?: ValidationOptions | Object; // TODO need review
|
||||
|
||||
/**
|
||||
Default value: true (no validation).
|
||||
Validation rules for incoming request path parameters, after matching the path against the route, extracting any parameters, and storing them in request.params, where:
|
||||
true - any path parameter value allowed (no validation performed).
|
||||
a joi validation object.
|
||||
a validation function using the signature async function(value, options) where:
|
||||
value - the request.params object containing the request path parameters.
|
||||
options - options.
|
||||
if a value is returned, the value is used as the new request.params value and the original value is stored in request.orig.params. Otherwise, the path parameters are left unchanged. If an error is thrown, the error is handled according to failAction.
|
||||
Note that failing to match the validation rules to the route path parameters definition will cause all requests to fail.
|
||||
* Default value: true (no validation).
|
||||
* Validation rules for incoming request path parameters, after matching the path against the route, extracting any parameters, and storing them in request.params, where:
|
||||
* * true - any path parameter value allowed (no validation performed).
|
||||
* * a joi validation object.
|
||||
* * a validation function using the signature async function(value, options) where:
|
||||
* * * value - the request.params object containing the request path parameters.
|
||||
* * * options - options.
|
||||
* if a value is returned, the value is used as the new request.params value and the original value is stored in request.orig.params. Otherwise, the path parameters are left unchanged. If an error is thrown, the error is handled according to failAction.
|
||||
* Note that failing to match the validation rules to the route path parameters definition will cause all requests to fail.
|
||||
* [See docs](https://github.com/hapijs/hapi/blob/master/API.md#-routeoptionsvalidateparams)
|
||||
*/
|
||||
params?: boolean | any; // TODO need to implementation. Here is JOI and more.
|
||||
params?: boolean | ValidationOptions | ((value: any, option: any) => Function); // TODO need review
|
||||
|
||||
/**
|
||||
Default value: true (no validation).
|
||||
Validation rules for incoming request payload (request body), where:
|
||||
true - any payload allowed (no validation performed).
|
||||
false - no payload allowed.
|
||||
a joi validation object.
|
||||
Note that empty payloads are represented by a null value. If a validation schema is provided and empty payload are allowed, the schema must be explicitly defined by setting the rule to a joi schema with null allowed (e.g. Joi.object({ keys here }).allow(null)).
|
||||
a validation function using the signature async function(value, options) where:
|
||||
value - the request.query object containing the request query parameters.
|
||||
options - options.
|
||||
if a value is returned, the value is used as the new request.payload value and the original value is stored in request.orig.payload. Otherwise, the payload is left unchanged. If an error is thrown, the error is handled according to failAction.
|
||||
Note that validating large payloads and modifying them will cause memory duplication of the payload (since the original is kept), as well as the significant performance cost of validating large amounts of data.
|
||||
* Default value: true (no validation).
|
||||
* Validation rules for incoming request payload (request body), where:
|
||||
* * true - any payload allowed (no validation performed). false - no payload allowed.
|
||||
* * a joi validation object. Note that empty payloads are represented by a null value. If a validation schema is provided and empty payload are allowed, the schema must be explicitly defined by setting the rule to a joi schema with null allowed (e.g. Joi.object({ keys here }).allow(null)).
|
||||
* * a validation function using the signature async function(value, options) where:
|
||||
* * * value - the request.query object containing the request query parameters.
|
||||
* * * options - options.
|
||||
* if a value is returned, the value is used as the new request.payload value and the original value is stored in request.orig.payload. Otherwise, the payload is left unchanged. If an error is thrown, the error is handled according to failAction.
|
||||
* Note that validating large payloads and modifying them will cause memory duplication of the payload (since the original is kept), as well as the significant performance cost of validating large amounts of data.
|
||||
* [See docs](https://github.com/hapijs/hapi/blob/master/API.md#-routeoptionsvalidatepayload)
|
||||
*/
|
||||
payload?: boolean | any; // TODO need to implementation. Here is JOI and more.
|
||||
payload?: boolean | ValidationOptions | ((value: any, option: any) => Function); // TODO need review
|
||||
|
||||
/**
|
||||
Default value: true (no validation).
|
||||
Validation rules for incoming request URI query component (the key-value part of the URI between '?' and '#'). The query is parsed into its individual key-value pairs, decoded, and stored in request.query prior to validation. Where:
|
||||
true - any query parameter value allowed (no validation performed).
|
||||
false - no query parameter value allowed.
|
||||
a joi validation object.
|
||||
a validation function using the signature async function(value, options) where:
|
||||
value - the request.query object containing the request query parameters.
|
||||
options - options.
|
||||
if a value is returned, the value is used as the new request.query value and the original value is stored in request.orig.query. Otherwise, the query parameters are left unchanged. If an error is thrown, the error is handled according to failAction.
|
||||
Note that changes to the query parameters will not be reflected in request.url.
|
||||
* Default value: true (no validation).
|
||||
* Validation rules for incoming request URI query component (the key-value part of the URI between '?' and '#'). The query is parsed into its individual key-value pairs, decoded, and stored in request.query prior to validation. Where:
|
||||
* * true - any query parameter value allowed (no validation performed). false - no query parameter value allowed.
|
||||
* * a joi validation object.
|
||||
* * a validation function using the signature async function(value, options) where:
|
||||
* * * value - the request.query object containing the request query parameters.
|
||||
* * * options - options.
|
||||
* if a value is returned, the value is used as the new request.query value and the original value is stored in request.orig.query. Otherwise, the query parameters are left unchanged. If an error is thrown, the error is handled according to failAction.
|
||||
* Note that changes to the query parameters will not be reflected in request.url.
|
||||
* [See docs](https://github.com/hapijs/hapi/blob/master/API.md#-routeoptionsvalidatequery)
|
||||
*/
|
||||
query?: boolean | any; // TODO need to implementation. Here is JOI and more.
|
||||
query?: boolean | ValidationOptions | ((value: any, option: any) => Function); // TODO need review
|
||||
|
||||
}
|
||||
|
||||
+49
-36
@@ -204,37 +204,39 @@ export interface RouteOptions {
|
||||
response?: RouteOptionsResponse;
|
||||
|
||||
/**
|
||||
Default value: false (security headers disabled).
|
||||
Sets common security headers. To enable, set security to true or to an object with the following options:
|
||||
hsts - controls the 'Strict-Transport-Security' header, where:
|
||||
true - the header will be set to max-age=15768000. This is the default value.
|
||||
a number - the maxAge parameter will be set to the provided value.
|
||||
an object with the following fields:
|
||||
maxAge - the max-age portion of the header, as a number. Default is 15768000.
|
||||
includeSubDomains - a boolean specifying whether to add the includeSubDomains flag to the header.
|
||||
preload - a boolean specifying whether to add the 'preload' flag (used to submit domains inclusion in Chrome's HTTP Strict Transport Security (HSTS) preload list) to the header.
|
||||
xframe - controls the 'X-Frame-Options' header, where:
|
||||
true - the header will be set to 'DENY'. This is the default value.
|
||||
'deny' - the headers will be set to 'DENY'.
|
||||
'sameorigin' - the headers will be set to 'SAMEORIGIN'.
|
||||
an object for specifying the 'allow-from' rule, where:
|
||||
rule - one of:
|
||||
'deny'
|
||||
'sameorigin'
|
||||
'allow-from'
|
||||
source - when rule is 'allow-from' this is used to form the rest of the header, otherwise this field is ignored. If rule is 'allow-from' but source is unset, the rule will be automatically changed to 'sameorigin'.
|
||||
xss - boolean that controls the 'X-XSS-PROTECTION' header for Internet Explorer. Defaults to true which sets the header to equal '1; mode=block'.
|
||||
Note: this setting can create a security vulnerability in versions of Internet Exploere below 8, as well as unpatched versions of IE8. See here and here for more information. If you actively support old versions of IE, it may be wise to explicitly set this flag to false.
|
||||
noOpen - boolean controlling the 'X-Download-Options' header for Internet Explorer, preventing downloads from executing in your context. Defaults to true setting the header to 'noopen'.
|
||||
noSniff - boolean controlling the 'X-Content-Type-Options' header. Defaults to true setting the header to its only and default option, 'nosniff'.
|
||||
* Default value: false (security headers disabled).
|
||||
* Sets common security headers. To enable, set security to true or to an object with the following options:
|
||||
* * hsts - controls the 'Strict-Transport-Security' header, where:
|
||||
* * * true - the header will be set to max-age=15768000. This is the default value.
|
||||
* * * a number - the maxAge parameter will be set to the provided value.
|
||||
* * * an object with the following fields:
|
||||
* * * * maxAge - the max-age portion of the header, as a number. Default is 15768000.
|
||||
* * * * includeSubDomains - a boolean specifying whether to add the includeSubDomains flag to the header.
|
||||
* * * * preload - a boolean specifying whether to add the 'preload' flag (used to submit domains inclusion in Chrome's HTTP Strict Transport Security (HSTS) preload list) to the header.
|
||||
* * xframe - controls the 'X-Frame-Options' header, where:
|
||||
* * * true - the header will be set to 'DENY'. This is the default value.
|
||||
* * * 'deny' - the headers will be set to 'DENY'.
|
||||
* * * 'sameorigin' - the headers will be set to 'SAMEORIGIN'.
|
||||
* * * an object for specifying the 'allow-from' rule, where:
|
||||
* * * * rule - one of:
|
||||
* * * * * 'deny'
|
||||
* * * * * 'sameorigin'
|
||||
* * * * * 'allow-from'
|
||||
* * * * source - when rule is 'allow-from' this is used to form the rest of the header, otherwise this field is ignored. If rule is 'allow-from' but source is unset, the rule will be automatically changed to 'sameorigin'.
|
||||
* * xss - boolean that controls the 'X-XSS-PROTECTION' header for Internet Explorer. Defaults to true which sets the header to equal '1; mode=block'.
|
||||
* Note: this setting can create a security vulnerability in versions of Internet Exploere below 8, as well as unpatched versions of IE8. See here and here for more information. If you actively support old versions of IE, it may be wise to explicitly set this flag to false.
|
||||
* * noOpen - boolean controlling the 'X-Download-Options' header for Internet Explorer, preventing downloads from executing in your context. Defaults to true setting the header to 'noopen'.
|
||||
* * noSniff - boolean controlling the 'X-Content-Type-Options' header. Defaults to true setting the header to its only and default option, 'nosniff'.
|
||||
* [See docs](https://github.com/hapijs/hapi/blob/master/API.md#-routeoptionssecurity)
|
||||
*/
|
||||
security?: RouteOptionsSecure;
|
||||
|
||||
/**
|
||||
Default value: { parse: true, failAction: 'error' }.
|
||||
HTTP state management (cookies) allows the server to store information on the client which is sent back to the server with every request (as defined in RFC 6265). state supports the following options:
|
||||
parse - determines if incoming 'Cookie' headers are parsed and stored in the request.state object.
|
||||
failAction - A failAction value which determines how to handle cookie parsing errors. Defaults to 'error' (return a Bad Request (400) error response).
|
||||
* Default value: { parse: true, failAction: 'error' }.
|
||||
* HTTP state management (cookies) allows the server to store information on the client which is sent back to the server with every request (as defined in RFC 6265). state supports the following options:
|
||||
* parse - determines if incoming 'Cookie' headers are parsed and stored in the request.state object.
|
||||
* failAction - A failAction value which determines how to handle cookie parsing errors. Defaults to 'error' (return a Bad Request (400) error response).
|
||||
* [See docs](https://github.com/hapijs/hapi/blob/master/API.md#-routeoptionsstate)
|
||||
*/
|
||||
state?: {
|
||||
parse?: boolean;
|
||||
@@ -242,26 +244,37 @@ export interface RouteOptions {
|
||||
}
|
||||
|
||||
/**
|
||||
Default value: none.
|
||||
Route tags used for generating documentation (array of strings).
|
||||
This setting is not available when setting server route defaults using server.options.routes.
|
||||
* Default value: none.
|
||||
* Route tags used for generating documentation (array of strings).
|
||||
* This setting is not available when setting server route defaults using server.options.routes.
|
||||
* [See docs](https://github.com/hapijs/hapi/blob/master/API.md#-routeoptionstags)
|
||||
*/
|
||||
tags?: string[];
|
||||
|
||||
/**
|
||||
Default value: { server: false }.
|
||||
Timeouts for processing durations.
|
||||
* Default value: { server: false }.
|
||||
* Timeouts for processing durations.
|
||||
* [See docs](https://github.com/hapijs/hapi/blob/master/API.md#-routeoptionstimeout)
|
||||
*/
|
||||
timeout?: {
|
||||
/** response timeout in milliseconds. Sets the maximum time allowed for the server to respond to an incoming client request before giving up and responding with a Service Unavailable (503) error response. Disabled by default (false). */
|
||||
|
||||
/**
|
||||
* Response timeout in milliseconds. Sets the maximum time allowed for the server to respond to an incoming request before giving up and responding with a Service Unavailable (503) error response.
|
||||
*/
|
||||
server?: boolean | number;
|
||||
/** by default, node sockets automatically timeout after 2 minutes. Use this option to override this behavior. Defaults to undefined which leaves the node default unchanged. Set to false to disable socket timeouts. */
|
||||
|
||||
/**
|
||||
* Default value: none (use node default of 2 minutes).
|
||||
* By default, node sockets automatically timeout after 2 minutes. Use this option to override this behavior. Set to false to disable socket timeouts.
|
||||
*/
|
||||
socket?: boolean | number;
|
||||
|
||||
};
|
||||
|
||||
/**
|
||||
Default value: { headers: true, params: true, query: true, payload: true, failAction: 'error' }.
|
||||
Request input validation rules for various request components.
|
||||
* Default value: { headers: true, params: true, query: true, payload: true, failAction: 'error' }.
|
||||
* Request input validation rules for various request components.
|
||||
* [See docs](https://github.com/hapijs/hapi/blob/master/API.md#-routeoptionsvalidate)
|
||||
*/
|
||||
validate?: RouteOptionsValidate;
|
||||
|
||||
|
||||
Reference in New Issue
Block a user