express.json() parse Content-Type: application/json thành object req.body — có sẵn từ Express 4.16+, không cần cài body-parser nữa.
express.urlencoded({ extended: true })parse form HTML (application/x-www-form-urlencoded).extended: truedùng thư việnqsnên nhận được object lồng nhau;extended: falsedùngquerystring, chỉ phẳng.- Giới hạn kích thước mặc định là 100kb, đổi bằng
express.json({ limit: '10mb' }). Payload lớn là một hướng tấn công DoS, nên luôn đặt limit hợp lý và đừng để mặc định ở endpoint upload. - Content type riêng:
express.json({ type: 'application/vnd.api+json' }). - Binary thì
express.raw({ type: 'application/octet-stream' }); webhook dạng text thuần thìexpress.text().
Lưu ý: express.json() KHÔNG parse multipart/form-data (upload file) — chỗ đó cần multer. Nếu req.body ra undefined, kiểm tra middleware đã đăng ký chưa và có đúng thứ tự không.