
Security News
AI Slop Is Polluting Bug Bounty Platforms with Fake Vulnerability Reports
AI-generated slop reports are making bug bounty triage harder, wasting maintainer time, and straining trust in vulnerability disclosure programs.
@fastify/env
Advanced tools
Fastify plugin to check environment variables
npm i @fastify/env
Plugin version | Fastify version |
---|---|
^5.x | ^5.x |
^4.x | ^4.x |
^2.x | ^3.x |
^0.x | ^2.x |
^0.x | ^1.x |
Please note that if a Fastify version is out of support, then so are the corresponding versions of this plugin in the table above. See Fastify's LTS policy for more details.
const fastify = require('fastify')()
const fastifyEnv = require('@fastify/env')
const schema = {
type: 'object',
required: [ 'PORT' ],
properties: {
PORT: {
type: 'string',
default: 3000
}
}
}
const options = {
confKey: 'config', // optional, default: 'config'
schema: schema,
data: data // optional, default: process.env
}
fastify
.register(fastifyEnv, options)
.ready((err) => {
if (err) console.error(err)
console.log(fastify.config) // or fastify[options.confKey]
console.log(fastify.getEnvs())
// output: { PORT: 3000 }
})
You can also use the function getEnvs()
of the Request from within a handler function:
fastify.get('/', (request, reply) => {
console.log(request.getEnvs())
// output: { PORT: 3000 }
})
Note that the getEnvs
decorators will not be added if they already exist.
This module is a wrapper around env-schema.
To read a .env
file you must set dotenv
in the options:
const options = {
dotenv: true // will read .env in root folder
}
// or, pass config options available on dotenv module
const options = {
dotenv: {
path: `${__dirname}/.env`,
debug: true
}
}
The @fastify/env
plugin loads asynchronously. If you wish to use its values in a different plugin before the boot sequence, you need to make sure that:
@fastify/env
is registered first.await fastify.register(fastifyEnv)
// fastify.config can be used in here
OR
fastify.register(fastifyEnv)
await fastify
// fastify.config can be used in here
NB Support for additional properties in the schema is disabled for this plugin, with the additionalProperties
flag set to false
internally.
To have typings for the fastify instance, you should either:
declaration merging
technique to enhance the FastifyInstance
type with the property and its keys you have defined in the options:declare module 'fastify' {
interface FastifyInstance {
config: { // this should be the same as the confKey in options
// specify your typing here
FOO: string
};
}
}
const fastify = Fastify()
fastify.register(fastifyEnv)
fastify.config.FOO // will be a string
fastify.config.BAR // error: Property BAR does not exist on type { FOO: string }
getEnvs()
to get the already typed object:type Envs = {
FOO: string
}
const fastify = Fastify()
await fastify.register(fastifyEnv)
const envs = fastify.getEnvs<Envs>() // envs will be of type Envs
envs.FOO // will be a string
envs.BAR // error: Property BAR does not exist on type Envs
If this is the case it is suggested to use json-schema-to-ts to have the type always synchronized with the actual schema.
Kindly sponsored by Mia Platform.
Licensed under MIT.
FAQs
Fastify plugin to check environment variables
The npm package @fastify/env receives a total of 59,728 weekly downloads. As such, @fastify/env popularity was classified as popular.
We found that @fastify/env demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
AI-generated slop reports are making bug bounty triage harder, wasting maintainer time, and straining trust in vulnerability disclosure programs.
Research
Security News
The Socket Research team investigates a malicious Python package disguised as a Discord error logger that executes remote commands and exfiltrates data via a covert C2 channel.
Research
Socket uncovered npm malware campaign mimicking popular Node.js libraries and packages from other ecosystems; packages steal data and execute remote code.