
Security News
NVD Quietly Sweeps 100K+ CVEs Into a “Deferred” Black Hole
NVD now marks all pre-2018 CVEs as "Deferred," signaling it will no longer enrich older vulnerabilities, further eroding trust in its data.
express-static-gzip
Advanced tools
simple wrapper on top of express.static, that allows serving pre-gziped files
Provides a small layer on top of serve-static, which allows to serve pre-gzipped files. Supports brotli and allows configuring any other compression you can think of as well.
If express-static-gzip
saved you some time, feel free to buy me a cup of coffee :)
For the express-static-gzip
middleware to work properly you need to first ensure that you have all files gzipped (or compressed with your desired algorithm) which you want to serve as a compressed version to the browser.
Simplest use case is to either have a folder with only .gz files, or you have a folder with the .gz files next to the original files. Same goes for other compressions.
$ npm install express-static-gzip
Even so this is a mayor release, this should be fully backwards compatible and should not have any breaking change to v1.1.3.
Moved all options for serveStatic
in its own section (serveStatic
) to prevent collisions when setting up your static fileserving middleware.
For backwards compatibility all root options that apply to serveStatic
will be copied to the new serveStatic
section, except if you have set values there already (no overwrite). Here is a small example of this behaviour:
{
enableBrotli: true, // not a serverStatic option, will not be moved
maxAge: 123, // not copied, as already present.
index: 'main.js', // copied to serveStatic section
serveStatic: {
maxAge: 234, // will be kept
cacheControl: false // will be kept as well
}
}
In the above scenario serveStatic will use cacheControl
: false, index
: 'main.js', maxAge
:234.
In case you just want to serve gzipped files only, this simple example would do:
var express = require("express");
var expressStaticGzip = require("express-static-gzip");
var app = express();
app.use("/", expressStaticGzip("/my/rootFolder/"));
While gzip compression is always enabled you now have the choice to add other types of compressions using the options object. Currently brotli can be enabled using the options.enableBrotli flag.
All other compressions need to be added by passing an array to options.customCompressions.
The options.serveStatic section is passed to the underlying serve-static
middleware, in case you want to configure this one as well.
The following example will show how to add brotli and deflate (with file extension .zz) to the middleware (it will still support gzip) and force brotli to be used if available (orderPreference
):
var express = require('express');
var expressStaticGzip = require('express-static-gzip');
var app = express();
app.use('/', expressStaticGzip('/my/rootFolder/', {
enableBrotli: true,
customCompressions: [{
encodingName: 'deflate',
fileExtension: 'zz'
}],
orderPreference: ['br']
}));
Compressions are selected in the following order if a file is requested from the middleware:
option.orderPreference
and supported by the clientFor more details see here, but not all of it is implemented at the moment.
When the middleware is created it will check the given root folder and all subfolders for files matching the registered compression. Adding files later to the folder will not be recognized by the middleware.
enableBrotli
: boolean (default: false)
Enables support for the brotli compression, using file extension 'br' (e.g. 'index.html.br').
index
: boolean | string (default: 'index.html')
By default this module will send "index.html" files in response to a request on a directory (url ending with '/'). To disable this set false or to supply a new index file pass a string (like 'index.htm').
customCompressions
: [{encodingName: string, fileExtension: string}]
Using this option, you can add any other compressions you would like. encodingName
will be checked against the Accept
-Header. fileExtension
is used to find files using this compression. fileExtension
does not require a dot (not '.gz', but 'gz'
).
orderPreference
: string[]
This options allows overwriting the client's requested encoding preference (see MDN) with a server side preference. Any encoding listed in orderPreference
will be used first (if supported by the client) before falling back to the client's supported encodings. The order of entries in orderPreference
is taken into account.
serveStatic
: ServeStaticOptions
This will be forwarded to the underlying serveStatic
instance used by expressStaticGzip
In default mode a request for "/" or "<somepath>/" will serve index.html as compressed version. This could lead to complications if you are serving a REST API from the same path, when express-server-static is registered before your API.
One solution would be to register express-server-static last. Otherwise you can set options.index to false:
app.use("/", expressStaticGzip("/my/rootFolder/", { index: false }));
Because this middleware was developed for a static production server use case to maximize performance, it is designed to look up and cache the compressed files corresponding to uncompressed file names on startup. This means that it will not be aware of compressed files being added or removed later on.
In case you have the following basic file structure
and you use set the enableBrotli flag to true, express-static-gzip will answer GET requests like this:
GET / >>> /my/rootFolder/index.html.br
GET /index.html >>> /my/rootFolder/index.html.br
GET /test.html >>> /my/rootFolder/test.html.gz
GET /main.js >>> /my/rootFolder/main.js
FAQs
simple wrapper on top of express.static, that allows serving pre-gziped files
The npm package express-static-gzip receives a total of 121,016 weekly downloads. As such, express-static-gzip popularity was classified as popular.
We found that express-static-gzip demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
NVD now marks all pre-2018 CVEs as "Deferred," signaling it will no longer enrich older vulnerabilities, further eroding trust in its data.
Research
Security News
Lazarus-linked threat actors expand their npm malware campaign with new RAT loaders, hex obfuscation, and over 5,600 downloads across 11 packages.
Security News
Safari 18.4 adds support for Iterator Helpers and two other TC39 JavaScript features, bringing full cross-browser coverage to key parts of the ECMAScript spec.