Skip to content

Latest commit

 

History

History

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 
 
 
 
 
 
 
 
 
 
 

@http-policy/core

Framework-independent HTTP policy engine for TypeScript — define caching, security headers, CORS and custom headers as typed, composable policies, then compile them once into deeply immutable objects with precomputed header strings.

Zero dependencies. No framework code — pair it with an adapter (@http-policy/express, @http-policy/fastify, @http-policy/hono, @http-policy/nestjs) or use applyPolicy directly on node:http.

import { policy } from '@http-policy/core';

const apiPolicy = policy()
  .cache((c) => c.public().browser('5m').cdn('1h').staleWhileRevalidate('10m'))
  .security((s) => s.nosniff().hsts('180d').referrer('strict-origin-when-cross-origin'))
  .cors((c) => c.origin('https://app.example.com').credentials())
  .headers((h) => h.set('X-App-Version', '1.0'))
  .compile();

Invalid combinations never compile — policy().cache((c) => c.private().cdn('1h')) is rejected because s-maxage only exists on the public cache model. CRLF injection is rejected at the call site; credentials() + wildcard CORS is a compile-time error.

See the full documentation.