Détail du package

method-override

expressjs4.4mMIT3.0.0

Override HTTP verbs

readme

method-override

NPM Version NPM Downloads Build Status Test Coverage

Lets you use HTTP verbs such as PUT or DELETE in places where the client doesn't support it.

Install

This is a Node.js module available through the npm registry. Installation is done using the npm install command:

$ npm install method-override

API

NOTE It is very important that this module is used before any module that needs to know the method of the request (for example, it must be used prior to the csurf module).

methodOverride(getter, options)

Create a new middleware function to override the req.method property with a new value. This value will be pulled from the provided getter.

  • getter - The getter to use to look up the overridden request method for the request. (default: X-HTTP-Method-Override)
  • options.methods - The allowed methods the original request must be in to check for a method override value. (default: ['POST'])

If the found method is supported by node.js core, then req.method will be set to this value, as if it has originally been that value. The previous req.method value will be stored in req.originalMethod.

getter

This is the method of getting the override value from the request. If a function is provided, the req is passed as the first argument, the res as the second argument and the method is expected to be returned. If a string is provided, the string is used to look up the method with the following rules:

  • If the string starts with X-, then it is treated as the name of a header and that header is used for the method override. If the request contains the same header multiple times, the first occurrence is used.
  • All other strings are treated as a key in the URL query string.

options.methods

This allows the specification of what methods(s) the request MUST be in in order to check for the method override value. This defaults to only POST methods, which is the only method the override should arrive in. More methods may be specified here, but it may introduce security issues and cause weird behavior when requests travel through caches. This value is an array of methods in upper-case. null can be specified to allow all methods.

Examples

override using a header

To use a header to override the method, specify the header name as a string argument to the methodOverride function. To then make the call, send a POST request to a URL with the overridden method as the value of that header. This method of using a header would typically be used in conjunction with XMLHttpRequest on implementations that do not support the method you are trying to use.

var express = require('express')
var methodOverride = require('method-override')
var app = express()

// override with the X-HTTP-Method-Override header in the request
app.use(methodOverride('X-HTTP-Method-Override'))

Example call with header override using XMLHttpRequest:

var xhr = new XMLHttpRequest()
xhr.onload = onload
xhr.open('post', '/resource', true)
xhr.setRequestHeader('X-HTTP-Method-Override', 'DELETE')
xhr.send()

function onload () {
  alert('got response: ' + this.responseText)
}

override using a query value

To use a query string value to override the method, specify the query string key as a string argument to the methodOverride function. To then make the call, send a POST request to a URL with the overridden method as the value of that query string key. This method of using a query value would typically be used in conjunction with plain HTML <form> elements when trying to support legacy browsers but still use newer methods.

var express = require('express')
var methodOverride = require('method-override')
var app = express()

// override with POST having ?_method=DELETE
app.use(methodOverride('_method'))

Example call with query override using HTML <form>:

<form method="POST" action="/resource?_method=DELETE">
  <button type="submit">Delete resource</button>
</form>

multiple format support

var express = require('express')
var methodOverride = require('method-override')
var app = express()

// override with different headers; last one takes precedence
app.use(methodOverride('X-HTTP-Method')) //          Microsoft
app.use(methodOverride('X-HTTP-Method-Override')) // Google/GData
app.use(methodOverride('X-Method-Override')) //      IBM

custom logic

You can implement any kind of custom logic with a function for the getter. The following implements the logic for looking in req.body that was in method-override@1:

var bodyParser = require('body-parser')
var express = require('express')
var methodOverride = require('method-override')
var app = express()

// NOTE: when using req.body, you must fully parse the request body
//       before you call methodOverride() in your middleware stack,
//       otherwise req.body will not be populated.
app.use(bodyParser.urlencoded())
app.use(methodOverride(function (req, res) {
  if (req.body && typeof req.body === 'object' && '_method' in req.body) {
    // look in urlencoded POST bodies and delete it
    var method = req.body._method
    delete req.body._method
    return method
  }
}))

Example call with query override using HTML <form>:

<!-- enctype must be set to the type you will parse before methodOverride() -->
<form method="POST" action="/resource" enctype="application/x-www-form-urlencoded">
  <input type="hidden" name="_method" value="DELETE">
  <button type="submit">Delete resource</button>
</form>

License

MIT

changelog

3.0.0 / 2018-07-11

  • Drop support for Node.js below 0.10
  • deps: debug@3.1.0
    • Add DEBUG_HIDE_DATE environment variable
    • Change timer to per-namespace instead of global
    • Change non-TTY date format
    • Remove DEBUG_FD environment variable support
    • Support 256 namespace colors

2.3.10 / 2017-09-27

  • deps: debug@2.6.9
  • deps: parseurl@~1.3.2
    • perf: reduce overhead for full URLs
    • perf: unroll the "fast-path" RegExp
  • deps: vary@~1.1.2
    • perf: improve header token parsing speed
  • perf: skip unnecessary parsing of entire header

2.3.9 / 2017-05-19

  • deps: debug@2.6.8
    • deps: ms@2.0.0
  • deps: vary@~1.1.1
    • perf: hoist regular expression

2.3.8 / 2017-03-24

  • deps: debug@2.6.3
    • Allow colors in workers
    • Deprecated DEBUG_FD environment variable
    • Fix: DEBUG_MAX_ARRAY_LENGTH
    • Use same color for same namespace

2.3.7 / 2016-11-19

  • deps: debug@2.3.3
    • Fix error when running under React Native
    • deps: ms@0.7.2
  • perf: remove argument reassignment

2.3.6 / 2016-05-20

  • deps: methods@~1.1.2
    • perf: enable strict mode
  • deps: parseurl@~1.3.1
    • perf: enable strict mode
  • deps: vary@~1.1.0

2.3.5 / 2015-07-31

  • perf: enable strict mode

2.3.4 / 2015-07-14

  • deps: vary@~1.0.1

2.3.3 / 2015-05-12

  • deps: debug@~2.2.0
    • deps: ms@0.7.1

2.3.2 / 2015-03-14

  • deps: debug@~2.1.3
    • Fix high intensity foreground color for bold
    • deps: ms@0.7.0

2.3.1 / 2014-12-30

  • deps: debug@~2.1.1
  • deps: methods@~1.1.1

2.3.0 / 2014-10-16

  • deps: debug@~2.1.0
    • Implement DEBUG_FD env variable support

2.2.0 / 2014-09-02

  • deps: debug@~2.0.0

2.1.3 / 2014-08-10

  • deps: parseurl@~1.3.0
  • deps: vary@~1.0.0

2.1.2 / 2014-07-22

  • deps: debug@1.0.4
  • deps: parseurl@~1.2.0
    • Cache URLs based on original value
    • Remove no-longer-needed URL mis-parse work-around
    • Simplify the "fast-path" RegExp

2.1.1 / 2014-07-11

  • deps: debug@1.0.3
    • Add support for multiple wildcards in namespaces

2.1.0 / 2014-07-08

  • add simple debug output
  • deps: methods@1.1.0
    • add CONNECT
  • deps: parseurl@~1.1.3
    • faster parsing of href-only URLs

2.0.2 / 2014-06-05

  • use vary module for better Vary behavior

2.0.1 / 2014-06-02

  • deps: methods@1.0.1

2.0.0 / 2014-06-01

  • Default behavior only checks X-HTTP-Method-Override header
  • New interface, less magic
    • Can specify what header to look for override in, if wanted
    • Can specify custom function to get method from request
  • Only POST requests are examined by default
  • Remove req.body support for more standard query param support
    • Use custom getter function if req.body support is needed
  • Set Vary header when using built-in header checking

1.0.2 / 2014-05-22

  • Handle req.body key referencing array or object
  • Handle multiple HTTP headers

1.0.1 / 2014-05-17

  • deps: pin dependency versions

1.0.0 / 2014-03-03

  • Genesis from connect