Express adapter for @http-policy/core — apply compiled HTTP policies as Express middleware.
npm install @http-policy/core @http-policy/expressimport express from 'express';
import { policy } from '@http-policy/core';
import { httpPolicy, getPolicyHandle } from '@http-policy/express';
const globalPolicy = policy()
.security((s) => s.nosniff().hsts('180d').referrer('strict-origin-when-cross-origin'))
.cors((c) => c.origin(['https://app.example.com']).credentials().preflight())
.compile();
const app = express();
app.use(httpPolicy(globalPolicy));
// Route policies merge over globals.
app.get('/products', httpPolicy(productsPolicy), (_req, res) => {
res.json({ products: [] });
});
// Per-request overrides without touching shared state:
app.get('/me', (req, res) => {
getPolicyHandle(req, res).cache((c) => c.private().maxAge('30s'));
res.json({ user: '…' });
});
app.listen(3000);The same policy definitions work unchanged with the Node.js, Fastify, Hono and NestJS adapters.
See the full documentation.