
Security News
NVD Concedes Inability to Keep Pace with Surging CVE Disclosures in 2025
Security experts warn that recent classification changes obscure the true scope of the NVD backlog as CVE volume hits all-time highs.
An RFC 3986 compliant, scheme extendable URI parsing/validating/resolving library for JavaScript.
The uri-js package is a utility for working with URIs (Uniform Resource Identifiers) in JavaScript. It provides functions for parsing, serializing, normalizing, and resolving URIs, as well as working with individual URI components.
Parsing URIs
This feature allows you to parse a URI string into its components, such as scheme, authority, path, query, and fragment.
const URI = require('uri-js');
const parsedURI = URI.parse('https://example.com:8080/path?query=string#fragment');
Serializing URIs
This feature allows you to build a URI string from its individual components.
const URI = require('uri-js');
const components = {
scheme: 'https',
userinfo: 'user:pass',
host: 'example.com',
port: 8080,
path: '/path',
query: 'query=string',
fragment: 'fragment'
};
const serializedURI = URI.serialize(components);
Normalizing URIs
This feature allows you to normalize a URI by converting it to its canonical form, which is useful for URI comparison.
const URI = require('uri-js');
const normalizedURI = URI.normalize('HTTP://EXAMPLE.COM:80/a/../b/./c%2f?%61');
Resolving URIs
This feature allows you to resolve a relative URI against a base URI, resulting in an absolute URI.
const URI = require('uri-js');
const baseURI = 'http://example.com/dir/';
const relativeURI = '../other';
const resolvedURI = URI.resolve(baseURI, relativeURI);
The url-parse package offers similar functionalities for parsing and handling URLs. It provides a more straightforward API for parsing URLs and has additional features for working with query strings.
This package implements the URL standard as specified by the WHATWG (Web Hypertext Application Technology Working Group). It is designed to mimic the URL class available in modern web browsers, providing a comprehensive API for working with URLs.
URI.js is an RFC 3986 compliant, scheme extendable URI parsing/validating/resolving library for all JavaScript environments (browsers, Node.js, etc).
To load in a browser, use the following tag:
<script type="text/javascript" src="uri-js/dist/uri.min.js"></script>
To load in a CommonJS (Node.js) environment, simply use:
var URI = require("./uri-js");
var components = URI.parse("uri://user:pass@example.com:123/one/two.three?q1=a1&q2=a2#body");
//returns:
//{
// errors : [],
// scheme : "uri",
// userinfo : "user:pass",
// host : "example.com",
// port : 123,
// path : "/one/two.three",
// query : "q1=a1&q2=a2",
// fragment : "body"
//}
URI.serialize({scheme : "http", host : "example.com", fragment : "footer"}) === "http://example.com/#footer"
URI.resolve("uri://a/b/c/d?q", "../../g") === "uri://a/g"
URI.normalize("HTTP://ABC.com/%7Esmith/home.html") === "http://abc.com/~smith/home.html"
URI.equal("example://a/b/c/%7Bfoo%7D", "eXAMPLE://a/./b/../b/%63/%7bfoo%7d") === true
All of the above functions can accept an additional options argument that is an object that can contain one or more of the following properties:
scheme
Indicates the scheme that the URI should be treated as, overriding the URI's normal scheme parsing behavior.
reference
If set to "suffix"
, it indicates that the URI is in the suffix format, and the validator will use the option's scheme
property to determine the URI's scheme.
tolerant
If set to true
, the parser will not report invalid URIs. It will also relax URI resolving rules.
URI.js supports inserting custom scheme dependent processing rules. For example, here is the code for HTTP scheme normalization:
URI.SCHEMES["http"] = {
serialize : function (components, options) {
//normalize the default port
if (components.port === 80) {
components.port = undefined;
}
//normalize the empty path
if (!components.path) {
components.path = "/";
}
return components;
}
};
Currently, URI.js has built in support for the following schemes:
Copyright 2011 Gary Court. All rights reserved.
Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met:
Redistributions of source code must retain the above copyright notice, this list of conditions and the following disclaimer.
Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution.
THIS SOFTWARE IS PROVIDED BY GARY COURT "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL GARY COURT OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
The views and conclusions contained in the software and documentation are those of the authors and should not be interpreted as representing official policies, either expressed or implied, of Gary Court.
FAQs
An RFC 3986/3987 compliant, scheme extendable URI/IRI parsing/validating/resolving library for JavaScript.
The npm package uri-js receives a total of 41,721,677 weekly downloads. As such, uri-js popularity was classified as popular.
We found that uri-js demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Security experts warn that recent classification changes obscure the true scope of the NVD backlog as CVE volume hits all-time highs.
Security Fundamentals
Attackers use obfuscation to hide malware in open source packages. Learn how to spot these techniques across npm, PyPI, Maven, and more.
Security News
Join Socket for exclusive networking events, rooftop gatherings, and one-on-one meetings during BSidesSF and RSA 2025 in San Francisco.