express-validator如何忽略未校验字段 仅保留checkSchema校验字段
express-validator 自动过滤未校验字段实现方案
express-validator v6及以上版本内置matchedData工具方法,可直接提取所有已定义校验规则且校验通过的字段,自动过滤所有未纳入校验规则的额外字段,无需手动解构。
实现步骤
- 从express-validator包中导入
matchedData方法,同时导入校验需要用到的checkSchema、validationResult - 在校验中间件中,先判断校验是否通过,校验通过后调用
matchedData获取合法字段集合,直接赋值给req.body即可 - 后续业务逻辑中拿到的
req.body将仅保留你在checkSchema中定义过、且校验合法的字段
代码示例
1. 导入依赖
const express = require('express'); const { checkSchema, validationResult, matchedData } = require('express-validator'); const app = express(); app.use(express.json());
2. 路由配置
app.post('/api/auth/signup', // 原有checkSchema校验规则保持不变 checkSchema({ name: { isAlpha: { errorMessage: 'Your name must contain letters only', }, isLength: { errorMessage: 'First name must be between 3 and 10 chars', options: { min: 3, max: 10, }, }, }, email: { isEmail: { errorMessage: 'Email is not valid', }, custom: { options: async (value, { req }) => { const user = await User.findOne({ where: { email: value } }); if (user) throw new Error('Email already used'); return true; }, }, normalizeEmail: [], }, password: { notEmpty: { errorMessage: 'Choose a password for your account', }, isLength: { errorMessage: 'Password must be between 6 and 30 chars', options: { min: 6, max: 30, }, }, custom: { options: (value, { req }) => { if (value !== req.body.confirm_password) throw new Error('Please confirm your password'); return true; }, }, }, }), // 校验处理+字段过滤中间件 (req, res, next) => { const errors = validationResult(req); if (!errors.isEmpty()) { return res.status(400).json({ errors: errors.array() }); } // 核心配置:仅提取body中符合校验规则的合法字段 // 若需要同时提取params、query中的校验字段,去掉locations配置即可 req.body = matchedData(req, { locations: ['body'] }); next(); }, // 业务逻辑处理 (req, res) => { // 此处req.body仅包含name、email、password三个合法字段 // 未定义校验规则的role、仅用于校验比对的confirm_password都会被自动过滤 console.log(req.body); // 后续注册业务逻辑... res.send('signup success'); } ); app.listen(3000);
配置说明
matchedData默认会收集req所有位置(body、query、路由params、headers等)中匹配校验规则且通过校验的字段,通过locations参数可以指定仅提取对应位置的字段,避免参数污染- 所有未在
checkSchema中定义校验规则的字段,无论是否传入,都不会出现在最终的返回结果中 - 校验不通过的字段也不会被收集到结果中,保证最终拿到的
req.body完全符合你定义的规则要求 - 若使用v6以下版本的express-validator,先升级到v6及以上稳定版即可使用该能力,无需自行编写字段遍历过滤逻辑
内容的提问来源于stack exchange,提问作者Haythem Dridi
相关产品推荐
相关产品推荐

