Skip to main content

Security

Runtime: any — Node.js ≥ 22 or a modern browser

A small set of security-adjacent helpers: password-strength checks and coarse script stripping. For secure random tokens use crypto.randomHex (generateSecureToken lived here until 5.0) — the Math.random helpers in random are never an acceptable substitute. stripScriptish (called sanitizeString before 3.0) removes only <script> blocks and inline on* handlers, so treat it as defence in depth: escape untrusted values with html.escapeHtml, or run a real sanitizer such as DOMPurify when markup must survive. It was renamed precisely because the old name promised a guarantee it never delivered.

Example​

import { randomHex } from '@rtorcato/js-common/crypto'
import { isStrongPassword } from '@rtorcato/js-common/security'

isStrongPassword('hunter2') // false — needs 8+ chars, upper, lower, digit, symbol
isStrongPassword('Hunter2!x') // true

// Password-reset link: crypto.getRandomValues, never Math.random.
const token = randomHex(32) // 64 hex characters

Import​

import { isStrongPassword, stripScriptish } from '@rtorcato/js-common/security'

Exports​

NameSummary
isStrongPasswordChecks if a password is strong (min 8 chars, upper, lower, number, special char).
stripScriptishRemoves <script> blocks and inline on*= event-handler attributes from a string.

See also​

  • emails — validate, normalize and mask email addresses
  • url — parse, validate and edit URLs and query params
  • validation — type guards — isString, isNumber, isDefined
  • crypto — hashing, HMAC, base64, random hex