Changelog
mongoose-guard follows semantic versioning. Before 1.0, minor versions (0.x) may include breaking changes, and each one is listed here.
First release.
createGuardandvalidateBodyvalidate a request body against a Mongoose model with a per-routeallowlist.- Strict type checks with no casting for every built-in SchemaType, including arrays, Maps and sub-schemas.
__proto__,constructor,prototype,$and dotted keys are rejected anywhere in the body.partialmode for PATCH routes andunknown: "strip"for lenient routes.- Express adapter (
mongoose-guard/express) and WebRequestadapter (mongoose-guard/web). - Tested against Mongoose 8 and 9, and Express 4 and 5.