From c83f08515a56f2a40816a970967fd352801c5b19 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Ricardo=20Tom=C3=A9=20Gon=C3=A7alves?= Date: Mon, 31 Aug 2026 16:30:11 +0100 Subject: [PATCH] Replace `@randyd45/curp-validation` with `validate-curp` The curp lib validated the CURP check digit, but its replacement @randyd45/curp-validation only checks the format regex, so 9 out of 10 possible check digits on any structurally-valid CURP were accepted. validate-curp (MIT, same author as validate-rfc) restores check-digit validation and additionally validates the state code and RENAPO's forbidden-word list, matching the original curp lib's behavior. --- README.md | 4 ++-- package.json | 12 ++++++------ src/asserts/curp-number-assert.js | 10 +++++----- src/types/index.d.ts | 2 +- test/asserts/curp-number-assert.test.js | 12 ++++++++++++ yarn.lock | 10 +++++----- 6 files changed, 31 insertions(+), 19 deletions(-) diff --git a/README.md b/README.md index 121d0de..fff26d1 100644 --- a/README.md +++ b/README.md @@ -42,7 +42,7 @@ The following set of extra asserts are provided by this package: | [CaZipCode](#cazipcode) | | | [CpfNumber](#cpfnumber) | [`cpf`][cpf-url] | | [CreditCard](#creditcard) | [`creditcard`][creditcard-url] | -| [CurpNumber](#curpnumber) | [`@randyd45/curp-validation`][curp-url] | +| [CurpNumber](#curpnumber) | [`validate-curp`][validate-curp-url] | | [Date](#date) | [`moment`][moment-url] | | [DateDiffGreaterThan](#datediffgreaterthan) | [`moment`][moment-url] | | [DateDiffGreaterThanOrEqualTo](#datediffgreaterthanorequalto) | [`moment`][moment-url] | @@ -407,7 +407,6 @@ MIT [callback-url]: https://www.npmjs.com/package/callback [cpf-url]: https://www.npmjs.com/package/cpf [creditcard-url]: https://www.npmjs.com/package/creditcard -[curp-url]: https://www.npmjs.com/package/@randyd45/curp-validation [google-libphonenumber-url]: https://www.npmjs.com/package/google-libphonenumber [iban-url]: https://www.npmjs.com/package/iban [isoc-url]: https://www.npmjs.com/package/isoc @@ -415,5 +414,6 @@ MIT [tin-validator-url]: https://www.npmjs.com/package/tin-validator [uk-modulus-checking-url]: https://www.npmjs.com/package/uk-modulus-checking [urijs-url]: https://www.npmjs.com/package/urijs +[validate-curp-url]: https://www.npmjs.com/package/validate-curp [validate-rfc-url]: https://www.npmjs.com/package/validate-rfc [validator-url]: https://www.npmjs.com/package/validator diff --git a/package.json b/package.json index 447ed35..7342575 100644 --- a/package.json +++ b/package.json @@ -51,7 +51,6 @@ }, "devDependencies": { "@fastify/pre-commit": "^2.2.1", - "@randyd45/curp-validation": "1.0.4", "@uphold/github-changelog-generator": "^4.0.2", "abavalidator": "^3.1.2", "bignumber.js": "^9.3.1", @@ -68,12 +67,12 @@ "tin-validator": "^1.1.0", "uk-modulus-checking": "0.0.3", "urijs": "^1.17.1", + "validate-curp": "^1.0.0", "validate-rfc": "^2.0.3", "validator": "^13.15.35", "validator.js": "^2.0.0" }, "peerDependencies": { - "@randyd45/curp-validation": "1.0.4", "abavalidator": "^2.0.0", "bignumber.js": ">=7 || <=9.3.1", "cpf": "^2.0.1", @@ -85,14 +84,12 @@ "tin-validator": "^1.0.0", "uk-modulus-checking": "^0.0.2", "urijs": "^1.0.0", + "validate-curp": "^1.0.0", "validate-rfc": "^2.0.3", "validator": ">=3 <14", "validator.js": "^2.0.0" }, "peerDependenciesMeta": { - "@randyd45/curp-validation": { - "optional": true - }, "abavalidator": { "optional": true }, @@ -126,6 +123,9 @@ "urijs": { "optional": true }, + "validate-curp": { + "optional": true + }, "validate-rfc": { "optional": true }, @@ -143,7 +143,6 @@ } }, "optionalPeerDependencies": { - "@randyd45/curp-validation": "1.0.4", "abavalidator": ">=2 <3", "bignumber.js": ">=7 <=9.3.0", "cpf": "^2.0.1", @@ -155,6 +154,7 @@ "tin-validator": ">=1.0.0 <2.0.0", "uk-modulus-checking": "0.0.2", "urijs": ">=1 <2", + "validate-curp": "^1.0.0", "validate-rfc": "^2.0.3", "validator": ">=3 <14" }, diff --git a/src/asserts/curp-number-assert.js b/src/asserts/curp-number-assert.js index e335b6a..e658c8e 100644 --- a/src/asserts/curp-number-assert.js +++ b/src/asserts/curp-number-assert.js @@ -6,14 +6,14 @@ const { Validator, Violation } = require('validator.js'); const _ = require('lodash'); -let CURP; +let validateCurp; /** * Optional peer dependencies. */ try { - ({ CURP } = require('@randyd45/curp-validation')); + validateCurp = require('validate-curp'); // eslint-disable-next-line no-empty } catch {} @@ -22,8 +22,8 @@ try { */ module.exports = function curpNumberAssert() { - if (!CURP) { - throw new Error('@randyd45/curp-validation is not installed'); + if (!validateCurp) { + throw new Error('validate-curp is not installed'); } /** @@ -41,7 +41,7 @@ module.exports = function curpNumberAssert() { throw new Violation(this, value, { value: Validator.errorCode.must_be_a_string }); } - if (!new CURP(value).isFormatValid()) { + if (!validateCurp(value).isValid) { throw new Violation(this, value, { value: 'must_be_a_valid_curp_number' }); } diff --git a/src/types/index.d.ts b/src/types/index.d.ts index c9e3e0e..4d31049 100644 --- a/src/types/index.d.ts +++ b/src/types/index.d.ts @@ -74,7 +74,7 @@ export interface ValidatorJSAsserts { /** * Valid Mexican CURP number. - * @requires @randyd45/curp-validation + * @requires validate-curp */ curpNumber(): AssertInstance; diff --git a/test/asserts/curp-number-assert.test.js b/test/asserts/curp-number-assert.test.js index 27b9317..d49c535 100644 --- a/test/asserts/curp-number-assert.test.js +++ b/test/asserts/curp-number-assert.test.js @@ -46,6 +46,18 @@ describe('CurpNumberAssert', () => { } }); + it('should throw an error if the check digit of `curp` is invalid', ({ assert }) => { + try { + Assert.curpNumber().validate('LOOA531113HTCPBN08'); + + assert.fail(); + } catch (e) { + assert.ok(e instanceof Violation); + assert.equal(e.value, 'LOOA531113HTCPBN08'); + assert.equal(e.violation.value, 'must_be_a_valid_curp_number'); + } + }); + it('should accept a valid `curp`', ({ assert }) => { assert.doesNotThrow(() => { Assert.curpNumber().validate('LOOA531113HTCPBN07'); diff --git a/yarn.lock b/yarn.lock index 45bc6fe..9e535a4 100644 --- a/yarn.lock +++ b/yarn.lock @@ -407,11 +407,6 @@ resolved "https://registry.yarnpkg.com/@pkgr/core/-/core-0.3.6.tgz#3569708bd4be4d8870ba32bf1c456dac81600d97" integrity sha512-SEeaJLb3qBNF/OaXnaR1NmmBbFYk1zC0ZH/52fATcRPLFg/p791YrcyFFy44Bo9sLaGuSuLp5Q6axbb/O+v/RA== -"@randyd45/curp-validation@1.0.4": - version "1.0.4" - resolved "https://registry.yarnpkg.com/@randyd45/curp-validation/-/curp-validation-1.0.4.tgz#61212285894f772821ef1685fd22514150896839" - integrity sha512-UcmKskORce983tbpoS9bUESBUIYRjBPZ9bWPpY5S2fkXX0ImkVKCzSvWaqIfS6DPphmNtHyF+ifT9srqzs0EvA== - "@sindresorhus/base62@^1.0.0": version "1.0.0" resolved "https://registry.yarnpkg.com/@sindresorhus/base62/-/base62-1.0.0.tgz#c47c42410e5212e4fa4657670e118ddfba39acd6" @@ -1938,6 +1933,11 @@ url-join@5.0.0: resolved "https://registry.yarnpkg.com/url-join/-/url-join-5.0.0.tgz#c2f1e5cbd95fa91082a93b58a1f42fecb4bdbcf1" integrity sha512-n2huDr9h9yzd6exQVnH/jU5mr+Pfx08LRXXZhkLLetAMESRj+anQsTAh940iMrIetKAmry9coFuZQ2jY8/p3WA== +validate-curp@^1.0.0: + version "1.0.0" + resolved "https://registry.yarnpkg.com/validate-curp/-/validate-curp-1.0.0.tgz#bd087155d01b5e046032d31a179926d3c74ad1d4" + integrity sha512-jk+mGpPMW9jNz6N901t3p9YDyfOk3Yq2va2TAU2L7h40w5VzJopytG/uDrZ5EFGa+IXEqrhZ2LXj3XDA6pHQoQ== + validate-rfc@^2.0.3: version "2.0.3" resolved "https://registry.yarnpkg.com/validate-rfc/-/validate-rfc-2.0.3.tgz#fc91a02ab0d7f513a25ed4f53d9d6a69a38ad04f"