A lightweight, fast, and secure form validation library for TypeScript/JavaScript applications. Built with performance and security in mind, featuring input sanitization, comprehensive validation rules, and early return optimization.
- High Performance - Optimized validation with early return
- Security First - Built-in XSS protection and input sanitization
- TypeScript Support - Full type safety and IntelliSense
- Well Tested - Comprehensive unit test coverage
- Zero Dependencies - No external dependencies
- Lightweight - Minimal bundle size
- Flexible - Customizable validation rules
- Safe - Immutable validation results
npm install secure-form-validatorimport{validate,ValidationResult}from'secure-form-validator'// Define your validation schemaconstschema={username: {required: true,minLength: 3,maxLength: 20,type: 'string',sanitize: true},email: {required: true,type: 'string',regex: '^[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\\.[a-zA-Z]{2,}$',sanitize: true},age: {required: true,type: 'number'}}// Your form dataconstdata={username: 'john_doe',email: 'john@example.com',age: 25}// Validate the dataconstresult: ValidationResult=validate(data,schema)if(result.isValid){console.log('Validation passed!')console.log('Sanitized data:',result.sanitizedData)}else{console.log('Validation failed:',result.errors)}Validates that a field has a value and is not empty.
{fieldName: {required: true}}Validates minimum and maximum string length.
{fieldName: {minLength: 3,// Minimum 3 charactersmaxLength: 50// Maximum 50 characters}}Validates data types.
{fieldName: {type: 'string'// 'string' | 'number' | 'boolean' | 'array' | 'object'}}Validates against regular expressions.
{email: {regex: '^[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\\.[a-zA-Z]{2,}$'}}Sanitizes input to prevent XSS attacks.
{fieldName: {sanitize: true// Removes script tags, event handlers, etc.}}Validates form data against a schema.
Parameters:
data: Record<string, any>- The data to validateschema: Record<string, any>- Validation schemaoptions: { locale?: string }- Optional configuration
Returns:
interfaceValidationResult{isValid: booleanerrors: Record<string,string>sanitizedData: Record<string,any>rawData?: Record<string,any>}Automatically sanitizes dangerous content:
constschema={content: {sanitize: true}}constdata={content: '<script>alert("xss")</script>Hello World'}constresult=validate(data,schema)// result.sanitizedData.content = "Hello World"Removes:
- Script tags (
<script>,</script>) - Event handlers (
onclick,onload, etc.) - JavaScript URLs (
javascript:) - HTML tags
- SQL meta characters
- Zero-width characters
- Early Return: Stops validation on first error for better performance
- Optimized Loops: Uses
for...ofwithObject.entries()for better performance - Immutable Results: No mutation of input data
- Lightweight: Minimal memory footprint
Run the test suite:
# Run tests
npm test# Run tests in watch mode
npm run test:watch
# Run tests with coverage
npm run test:coverageconstregistrationSchema={username: {required: true,minLength: 3,maxLength: 20,type: 'string',sanitize: true},email: {required: true,type: 'string',regex: '^[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\\.[a-zA-Z]{2,}$',sanitize: true},password: {required: true,minLength: 8,type: 'string'},age: {required: true,type: 'number'},terms: {required: true,type: 'boolean'}}constcontactSchema={name: {required: true,minLength: 2,maxLength: 50,type: 'string',sanitize: true},email: {required: true,type: 'string',regex: '^[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\\.[a-zA-Z]{2,}$',sanitize: true},message: {required: true,minLength: 10,maxLength: 1000,type: 'string',sanitize: true}}The validator returns detailed error information:
constresult=validate(data,schema)if(!result.isValid){// Handle validation errorsObject.entries(result.errors).forEach(([field,error])=>{console.log(`${field}: ${error}`)})}constresult=validate(data,schema,{locale: 'en'// Future i18n support})constresult=validate(data,schema)// Check if validation passedif(result.isValid){// Use sanitized dataprocessFormData(result.sanitizedData)}else{// Handle errorsdisplayErrors(result.errors)}// Access original dataconsole.log('Original data:',result.rawData)- Fork the repository
- Create your feature branch (
git checkout -b feature/amazing-feature) - Commit your changes (
git commit -m 'Add some amazing feature') - Push to the branch (
git push origin feature/amazing-feature) - Open a Pull Request
This project is licensed under the MIT License - see the LICENSE file for details.
- Built with TypeScript for type safety
- Jest for comprehensive testing
- Focus on security and performance
Made with love for secure web applications