Sample
Express defaults the application `query parser` setting to `'extended'`, parsing bracketed query string keys into nested objects and arrays.
sha256:58c08df4e2e12d0989f56f61a509551f26f9a7c7fce4300a49d1d6aa357a209c
PUBLISHED
L3_CONTRACT_PASS
MIT-0
Execution evidence
Declared environment and signed verification runs are separated so you can see exactly what this sample proves.
Evidence basisSigned contract pass
Verification receipts1
Verification levelL3_CONTRACT_PASS
Declared environment
- Execution context
- node
- Operating system
- linux
- Architecture
- x64
- Runtime
- node
- Language
- node
- Package manager
- npm
Verification-run environments
- Execution context
- node 22
- Operating system
- linux alpine · musl
- Architecture
- x64
- Runtime
- node 22
- Language
- javascript
- Package manager
- npm
- Execution
- container · docker
CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · node-typescript@1 · 2026-08-17
Case
- Goal
- Express defaults the application `query parser` setting to `'extended'`, parsing bracketed query string keys into nested objects and arrays. HOW
- Packages
-
express 4.18.2
- Environment
- node
- Created
- 2026-08-17T06:38:17Z
Commonly assumed
Leaving the query parser unconfigured in Express parses query string parameters into flat key-value pairs without constructing nested objects.
The sample's author recorded this as what a developer or model would expect here. The contract below is what actually ran.
Contract
- When the `query parser` setting is left unset on an Express application, Express defaults `app.get('query parser')` to `'extended'` and uses `qs` to parse bracketed keys like `filter[status]=active` into nested objects rather than flat string keys.
- assert.strictEqual(app.get('query parser'), 'extended')
- assert.strictEqual(app.get('etag'), 'weak')
- assert.strictEqual(app.get('subdomain offset'), 2)
- assert.strictEqual(app.get('x-powered-by'), true)
- assert.strictEqual(app.get('trust proxy'), false)
- assert.deepStrictEqual(req.query, { filter: { status: 'active', limit: '10' }, tags: ['backend', 'express'] })
- assert(res.headers['etag'].startsWith('W/"'))
- assert.strictEqual(res.headers['x-powered-by'], 'Express')
- assert.deepStrictEqual(req.subdomains, ['v1', 'api'])
- assert.deepStrictEqual(req.ips, [])
Files
- NOTES.md
- csx.json
- package-lock.json
- package.json
- test/contract.mjs
Download the source artifact (tar.gz)
Origin Seeder
csx-seed
Verification receipts
- node 22 · linux alpine/x64 · docker · CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · node-typescript@1 · 2026-08-17 · ed25519:d91480838ac982c9