
Security News
Open VSX Begins Implementing Pre-Publish Security Checks After Repeated Supply Chain Incidents
Following multiple malicious extension incidents, Open VSX outlines new safeguards designed to catch risky uploads earlier.
@mjackson/form-data-parser
Advanced tools
A streaming multipart/form-data parser that solves memory issues with file uploads in server environments. Built as an enhanced replacement for the native request.formData() API, it enables efficient handling of large file uploads by streaming directly to disk or cloud storage services like AWS S3 or Cloudflare R2, preventing server crashes from memory exhaustion.
request.formData() with streaming file upload supportrequest.formData() for non-multipart/form-data requestsThe native request.formData() method has a major flaw in server environments: it buffers all file uploads in memory. When your users upload large files, this can quickly exhaust your server's RAM and crash your application.
form-data-parser solves this by handling file uploads as they arrive in the request body stream, allowing the user to safely put the file in storage, and use some other value (like a unique identifier for that file) in the returned FormData object.
Install from npm:
npm install @mjackson/form-data-parser
This library pairs really well with the file-storage library for keeping files in various storage backends.
import { LocalFileStorage } from '@mjackson/file-storage/local';
import type { FileUpload } from '@mjackson/form-data-parser';
import { parseFormData } from '@mjackson/form-data-parser';
// Set up storage for uploaded files
const fileStorage = new LocalFileStorage('/uploads/user-avatars');
// Define how to handle incoming file uploads
async function uploadHandler(fileUpload: FileUpload) {
// Is this file upload from the <input type="file" name="user-avatar"> field?
if (fileUpload.fieldName === 'user-avatar') {
let storageKey = `user-${user.id}-avatar`;
// Put the file in storage
await fileStorage.set(storageKey, fileUpload);
// Return a lazy File object that can access the stored file when needed
return fileStorage.get(storageKey);
// Note: You could also just return the `storageKey` here if
// that's the value you want to show up in the `FormData` object
// at the "user-avatar" key.
}
// Ignore unrecognized fields
}
// Handle form submissions with file uploads
async function requestHandler(request: Request) {
// Parse the form data, streaming any files through your upload handler
let formData = await parseFormData(request, uploadHandler);
// Access uploaded files just like with native FormData
let file = formData.get('user-avatar'); // File object
file.name; // "my-avatar.jpg" (original filename)
file.size; // File size in bytes
file.type; // "image/jpeg" (MIME type)
}
file-storage - A simple key/value interface for storing FileUpload objects you get from the parsermultipart-parser - The parser used internally for parsing multipart/form-data HTTP messagesSee LICENSE
FAQs
A request.formData() wrapper with streaming file upload handling
We found that @mjackson/form-data-parser demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Following multiple malicious extension incidents, Open VSX outlines new safeguards designed to catch risky uploads earlier.

Research
/Security News
Threat actors compromised four oorzc Open VSX extensions with more than 22,000 downloads, pushing malicious versions that install a staged loader, evade Russian-locale systems, pull C2 from Solana memos, and steal macOS credentials and wallets.

Security News
Lodash 4.17.23 marks a security reset, with maintainers rebuilding governance and infrastructure to support long-term, sustainable maintenance.