Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
@mjackson/form-data-parser
Advanced tools
A request.formData() wrapper with streaming file upload handling
form-data-parser
is a wrapper around request.formData()
that provides streaming support for handling file uploads. This is useful in server contexts where large files should be streamed to disk or some cloud storage service like AWS S3 or Cloudflare R2 instead of being buffered in memory.
request.formData()
with support for streaming file uploadsrequest.formData()
implementation for non-multipart/form-data
requestsThe web fetch API's built-in request.formData()
method is not a great fit for server environments because it doesn't provide a way to stream file uploads. This means that when you call request.formData()
in a server environment on a request that was submitted by a <form enctype="multipart/form-data">
, any file uploads contained in the request are buffered in memory. For small files this may not be an issue, but it's a total non-starter for large files that exceed the server's memory capacity.
form-data-parser
fixes this issue by providing an API to handle streaming file data.
Install from npm:
npm install @mjackson/form-data-parser
import { LocalFileStorage } from '@mjackson/file-storage/local';
import { type FileUpload, parseFormData } from '@mjackson/form-data-parser';
const fileStorage = new LocalFileStorage('/uploads/user-avatars');
async function uploadHandler(fileUpload: FileUpload) {
// Is this file upload from the <input type="file" name="user-avatar"> field?
if (fileUpload.fieldName === 'user-avatar') {
let storageKey = `user-${user.id}-avatar`;
// FileUpload objects are not meant to stick around for very long (they are
// streaming data from the request.body!) so we should store them as soon as
// possible.
await fileStorage.set(storageKey, fileUpload);
// Return a File for the FormData object. This is a LazyFile that knows how
// to access the file's content if needed (using e.g. file.stream()) but
// waits until it is requested to actually read anything.
return fileStorage.get(storageKey);
}
// Ignore any files we don't recognize the name of...
}
async function requestHandler(request: Request) {
let formData = await parseFormData(request, uploadHandler);
let file = formData.get('user-avatar'); // File
file.name; // "my-avatar.jpg" (name of the file on the user's computer)
file.size; // number
file.type; // "image/jpeg"
}
file-storage
- A simple key/value interface for storing FileUpload
objects you get from the parsermultipart-parser
- The parser used internally for parsing multipart/form-data
HTTP messagesSee LICENSE
FAQs
A request.formData() wrapper with streaming file upload handling
We found that @mjackson/form-data-parser demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.