http-customs
v0.0.0
Published
Rust-powered static HTTP call analysis for JavaScript and TypeScript
Readme
http-customs
Find potential HTTP calls in JavaScript and TypeScript files without executing
them. Supports common APIs including fetch, Node HTTP, Axios, Got, Ky, Undici,
and browser networking APIs.
Requires Node.js 22.12+ and a packaged native binary for your platform. npm release pending.
Get started
npm install http-customsimport customs from "http-customs";
const report = customs("./setup.js");
for (const call of report.calls) {
console.log(call.method, call.url, call.file, call.location.start.line);
}
// Inspect multiple files and their imports.
const project = customs(["./setup.js", "./prepare.ts"], {
followImports: true,
});customs is synchronous. It accepts one path or an array of paths, relative to
your working directory or absolute. JS, TS, JSX, and TSX are supported; files are
validated by content, even with other extensions. TypeScript types are included.
Read the result
The returned object is JSON-serializable:
| Field | Contents |
| ------------- | ---------------------------------------------------------------- |
| calls | Detected APIs, methods, URLs, destinations, and source locations |
| files | Absolute paths of inspected files |
| entryPoints | Unique, canonical input paths |
| imports | Imports and their resolution status |
| warnings | Known gaps such as dynamic URLs or skipped imports |
Unknown methods and URLs are null. destination contains the URL's protocol,
hostname, port, and origin, or is null when unknown or relative. Lines and
columns start at 1.
Options
Pass options as the second argument:
| Option | Default | Purpose |
| ---------------- | ---------- | ------------------------------------------ |
| followImports | false | Inspect statically resolvable dependencies |
| maxFiles | 1000 | Limit entry points and inspected files |
| maxFileBytes | 2097152 | Limit bytes per file (2 MiB) |
| maxTotalBytes | 33554432 | Limit total source bytes (32 MiB) |
| maxImportDepth | 100 | Limit dependency traversal depth |
| maxAstNodes | 250000 | Limit syntax nodes per file |
Missing or dynamic imports produce warnings. Invalid source or exceeded limits throw instead of returning a partial report. Limits must be positive safe integers.
Handle errors
import customs, { CustomsError } from "http-customs";
try {
const report = customs("./setup.js");
console.log(report.calls, report.warnings);
} catch (error) {
if (!(error instanceof CustomsError)) throw error;
console.error(error.code, error.file, error.message);
}Error codes: INVALID_INPUT, READ_ERROR, INVALID_SOURCE, LIMIT_EXCEEDED.
No detected calls does not mean safe. Review warnings and the
analysis limitations. For a terminal interface, install
http-customs-cli.
