Skip to content

Replace direct body-parser dependency with Express built-in parser - #5995

Merged
tdonohue merged 1 commit into
DSpace:mainfrom
MMilosz:refactor/package-json-dependency-replace-body-parser
Jul 31, 2026
Merged

Replace direct body-parser dependency with Express built-in parser#5995
tdonohue merged 1 commit into
DSpace:mainfrom
MMilosz:refactor/package-json-dependency-replace-body-parser

Conversation

@MMilosz

@MMilosz MMilosz commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

References

none

Description

Before Express 4.16 (released in 2017), applications needed to add the separate body-parser dependency. Express now provides built-in body parsing middleware, so there is no need to add the dependency directly, especially since we rely on the default configuration.

This PR:

  • removes the direct body-parser dependency
  • changes server.ts to use Express's built-in parser

No functional changes intended

Instructions for Reviewers

List of changes in this PR:

  • package.json: removed the direct body-parser dependency
  • server.ts: uses server.use(express.json()) instead of server.use(json())

Before:

$ npm ls body-parser --depth=0
dspace-angular@11.0.0-next /tmp/dspace-angular
└── body-parser@1.20.5

After:

$ npm ls body-parser --depth=0
dspace-angular@11.0.0-next /tmp/dspace-angular
└── (empty)

(Note that --depth=0 checks direct dependencies only. body-parser will still appear as a transitive dependency of other packages e.g. Express, Karma)

To review:

  • Verify that the frontend builds and starts successfully.
  • Verify that frontend<>API communication works as before.

Checklist

  • My PR is created against the main branch of code (unless it is a backport or is fixing an issue specific to an older branch).
  • My PR is small in size (e.g. less than 1,000 lines of code, not including comments & specs/tests), or I have provided reasons as to why that's not possible.
  • My PR passes ESLint validation using npm run lint
  • My PR doesn't introduce circular dependencies (verified via npm run check-circ-deps)
  • My PR includes TypeDoc comments for all new (or modified) public methods and classes. It also includes TypeDoc for large or complex private methods.
  • My PR passes all specs/tests and includes new/updated specs or tests based on the Code Testing Guide.
  • My PR aligns with Accessibility guidelines if it makes changes to the user interface.
  • My PR uses i18n (internationalization) keys instead of hardcoded English text, to allow for translations.
  • My PR includes details on how to test it. I've provided clear instructions to reviewers on how to successfully test this fix or feature.
  • If my PR includes new libraries/dependencies (in package.json), I've made sure their licenses align with the DSpace BSD License based on the Licensing of Contributions documentation.
  • If my PR includes new features or configurations, I've provided basic technical documentation in the PR itself.
  • If my PR fixes an issue ticket, I've linked them together.

@MMilosz MMilosz added the quick win Pull request is small in size & should be easy to review and/or merge label Jul 24, 2026
@MMilosz
MMilosz marked this pull request as ready for review July 24, 2026 15:11
@alanorth alanorth added dependencies Pull requests that update a dependency file 1 APPROVAL pull request only requires a single approval to merge port to dspace-8_x This PR needs to be ported to `dspace-8_x` branch for next bug-fix release port to dspace-9_x This PR needs to be ported to `dspace-9_x` branch for next bug-fix release port to dspace-10_x This PR needs to be ported to `dspace-10_x` branch for next bug-fix release labels Jul 25, 2026
Replace the external body-parser dependency with Express's built-in parser for one less dependency

No functional changes intended
@MMilosz
MMilosz force-pushed the refactor/package-json-dependency-replace-body-parser branch from 62fc1c7 to 217d9cf Compare July 28, 2026 15:46
@MMilosz MMilosz mentioned this pull request Jul 29, 2026

@tdonohue tdonohue left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍 Thanks @MMilosz ! Code looks good & I tested it. Couldn't find any differences in behavior.

@tdonohue tdonohue added this to the 11.0 milestone Jul 31, 2026
@github-project-automation github-project-automation Bot moved this to 👍 Reviewer Approved in DSpace 11.0 Release Jul 31, 2026
@tdonohue
tdonohue merged commit a2c5e0c into DSpace:main Jul 31, 2026
18 of 20 checks passed
@github-project-automation github-project-automation Bot moved this from 👍 Reviewer Approved to ✅ Done in DSpace 11.0 Release Jul 31, 2026
@dspace-bot

Copy link
Copy Markdown
Contributor

Backport failed for dspace-8_x, because it was unable to cherry-pick the commit(s).

Please cherry-pick the changes locally and resolve any conflicts.

git fetch origin dspace-8_x
git worktree add -d .worktree/backport-5995-to-dspace-8_x origin/dspace-8_x
cd .worktree/backport-5995-to-dspace-8_x
git switch --create backport-5995-to-dspace-8_x
git cherry-pick -x 217d9cf84910ec88c6af24402ee86caff122a0d5

@dspace-bot

Copy link
Copy Markdown
Contributor

Backport failed for dspace-9_x, because it was unable to cherry-pick the commit(s).

Please cherry-pick the changes locally and resolve any conflicts.

git fetch origin dspace-9_x
git worktree add -d .worktree/backport-5995-to-dspace-9_x origin/dspace-9_x
cd .worktree/backport-5995-to-dspace-9_x
git switch --create backport-5995-to-dspace-9_x
git cherry-pick -x 217d9cf84910ec88c6af24402ee86caff122a0d5

@dspace-bot

Copy link
Copy Markdown
Contributor

Successfully created backport PR for dspace-10_x:

@tdonohue

Copy link
Copy Markdown
Member

@MMilosz : It looks like this will need to be manually backported to 9.x and 8.x. The automated backport was only able to port this back to 10.x

@tdonohue tdonohue removed the port to dspace-10_x This PR needs to be ported to `dspace-10_x` branch for next bug-fix release label Jul 31, 2026
@MMilosz
MMilosz deleted the refactor/package-json-dependency-replace-body-parser branch August 3, 2026 07:47
@tdonohue tdonohue removed the port to dspace-9_x This PR needs to be ported to `dspace-9_x` branch for next bug-fix release label Aug 28, 2026
@tdonohue

Copy link
Copy Markdown
Member

I backported this to 9.x in #6121. Also verified it does NOT need backporting to dspace-8_x because this dependency isn't in the package.json for 8.x

@tdonohue tdonohue removed the port to dspace-8_x This PR needs to be ported to `dspace-8_x` branch for next bug-fix release label Aug 28, 2026
Comment thread server.ts
@@ -134,7 +133,7 @@ export function app() {
* Add JSON parser for request bodies
* See [body-parser](https://github.com/expressjs/body-parser)

@alanorth alanorth Aug 29, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@MMilosz this comment should be updated (or simply remove the second line?) to avoid confusion. If you can make a quick PR I will merge it ASAP. Thank you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

1 APPROVAL pull request only requires a single approval to merge dependencies Pull requests that update a dependency file quick win Pull request is small in size & should be easy to review and/or merge

Projects

Status: ✅ Done

Development

Successfully merging this pull request may close these issues.

4 participants