Skip to content

refactor(factory.ts): improve typing - #1300

Merged
chimurai merged 1 commit into
masterfrom
type-factory.ts
Oct 4, 2026
Merged

chimurai merged 1 commit into
masterfrom
type-factory.ts

Conversation

@chimurai

@chimurai chimurai commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

Summary by CodeRabbit

  • TypeScript Improvements
    • Proxy middleware now supports custom types for the callback passed to continue request handling or report an error.
    • Callback types are preserved when creating and using middleware, improving compatibility with applications that provide their own compatible callback signatures. The default callback type remains unchanged for callers that do not specify a custom type.

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 38c123f9-6772-4a95-8763-5deed77d367d
📥 Commits

Reviewing files that changed from the base of the PR and between 4ed80ab and 1bb6fb2.

📒 Files selected for processing (2)
  • src/factory.ts
  • src/http-proxy-middleware.ts

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review.


📝 Walkthrough

Walkthrough

The middleware factory and HttpProxyMiddleware now propagate a configurable TNext callback type. The factory returns the middleware without a type assertion.

Changes

Middleware callback types

Layer / File(s) Summary
Callback type propagation
src/http-proxy-middleware.ts, src/factory.ts
HttpProxyMiddleware adds a TNext generic and uses it for its public middleware property. createProxyMiddleware constrains and passes TNext, then returns the middleware without a type assertion.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Refactor

Merge Risk: ⚪ Minimal · up to 1bb6f

Consumers retain the default callback type or can specify a custom one through the factory. No concrete compatibility or runtime regression is established, so the change is mergeable subject to normal checks.

Security Architecture Review

Security architecture risk: ⚪ Minimal · up to 1bb6f

The change constrains and propagates callback types without changing executable request handling, proxy routing, or callback invocation. No introduced or worsened security risk was identified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The demonstrated impact is on callers compiling against the public handler types. Because the construction and handler execution paths are unchanged, this delta does not expand attacker-controlled runtime reachability or downstream authority.

Trust Boundaries and Controls

  • observed — The callback constraint is a compile-time contract, not a security enforcement boundary. Existing proxy-routing and target-validation behavior is preserved; its broader security adequacy is not established by this review.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the main change: improved typing in the factory and middleware API.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-new Bot commented Oct 4, 2026

Copy link
Copy Markdown
npm i https://pkg.pr.new/http-proxy-middleware@1300

commit: 1bb6fb2

@coveralls

Copy link
Copy Markdown

Coverage Status

coverage: 96.364%. remained the same — type-factory.ts into master

@chimurai
chimurai merged commit 64426dc into master Oct 4, 2026
26 checks passed
@chimurai
chimurai deleted the type-factory.ts branch October 4, 2026 12:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants