Security News
GitHub Removes Malicious Pull Requests Targeting Open Source Repositories
GitHub removed 27 malicious pull requests attempting to inject harmful code across multiple open source repositories, in another round of low-effort attacks.
@airtasker/form-schema-compiler
Advanced tools
Helps your create a security (sandbox) custom form.
npm install --save @airtasker/form-schema-compiler
This assumes that you’re using npm package manager with a module bundler like Webpack or Browserify to consume CommonJS modules.
If you don’t yet use npm or a modern module bundler, and would rather prefer a single-file UMD build that makes FormSchemaCompiler
available as a global object.
Compile an airtasker form schema to an AST (abstract structure tree).
schema
: Airtaker form schemaoptions
: { typeCompilers
}
typeCompilers
: { [TYPE
]: createCompiler()
:{[before(schema)
], [after(AST)
]}}: you can add custom components compiler. it have high priority than default components compiler.Apply an AST.
ast
: an compiled AST
options
: { variableGetter(name)
, applyComponents
}
variableGetter(name)
(function): if there is a identifier type, will use this function to get variable valueapplyComponents(componentASTs)
(function): components type handler.a const file
export const TYPES = {
Numeric: 'Numeric',
String: 'String',
Boolean: 'Boolean',
Null: 'Null',
RegExp: 'RegExp',
Identifier: 'Identifier',
BinaryExpression: 'BinaryExpression',
UnaryExpression: 'UnaryExpression',
CallExpression: 'CallExpression',
Components: 'Components',
Operator: 'Operator',
Punctuation: 'Punctuation',
Raw: 'Raw',
};
export const PRIMITIVES = [
TYPES.Numeric,
TYPES.String,
TYPES.Boolean,
TYPES.Null,
];
export const OBJECTS = [TYPES.RegExp, TYPES.Identifier, TYPES.Component];
export const EXPRESSIONS = [
TYPES.BinaryExpression,
TYPES.CallExpression,
TYPES.UnaryExpression,
];
export const OPERATORS = {
Add: '+',
Subtract: '-',
Multiply: '*',
Remainder: '%',
Divide: '/',
GreaterThan: '>',
GreaterThanOrEqualTo: '>=',
LessThan: '<',
LessThanOrEqualTo: '<=',
EqualTo: 'is',
NotEqualTo: 'isnt',
And: 'and',
Or: 'or',
Match: 'match',
Not: 'not',
};
export const ANNOTATION_TYPES = {
Expression: 'Expression',
Template: 'Template',
Component: 'Component',
Action: 'Action',
DataBinding: 'DataBinding',
};
export const ANNOTATIONS = {
[ANNOTATION_TYPES.Expression]: ['{', '}'],
[ANNOTATION_TYPES.Template]: ['#', '#'],
[ANNOTATION_TYPES.Component]: ['<', '>'],
[ANNOTATION_TYPES.Action]: ['(', ')'],
[ANNOTATION_TYPES.DataBinding]: ['[', ']'],
};
export const GLOBAL_FUNCTIONS = {
toString: 'toString'
};
Airtasker form schema using JSON schema.
key
: no annotation, compile as json
compile
{
key: "1",
key2: 1,
key3: null,
key4: true,
key5: []
}
to
{
key: {type: "String", value: "1"},
key2: {type: "Number", value: 1},
key3: {type: "Null", value: null},
key4: {type: "Boolean", value: true},
key5: {type: "Raw", value: []},
}
<key>
: component annoation
compile
{"<key>": {/*component schema*/}}
to
{"key": {/*component ast*/}}
[key]
: data binding
compile
{"[key]": "foo"}
to
{"key": { type: "identifier", name: "foo" }
#key#
: template
compile
{"#key#": "foo{"bar"}"}
to
{
"key": {
type: "BinaryExpression",
left: { type: "String", value: "foo" },
operator: "+",
right: {
type: "callExpression",
callee: { type: "identifier", name: "toString" },
arguments: [{ type: "identifier", name: "bar" }]
}
}
}
{key}
: expression
compile
{"{key}": "1 + 2"}
to
{
"key": {
type: "BinaryExpression",
left: { type: "Numeric", value: "1" },
operator: "+",
right: { type: "Numeric", value: "2" },
}
}
(key)
: action, eventValue is a special identifier that's reference the action callback value
compile
{"(click)": "doAction(eventValue)"}
to
{
"onClick": {
type: "callExpression",
callee: { type: "identifier", name: "doAction" },
arguments: [{ type: "identifier", name: "eventValue" }]
}
}
MIT
FAQs
a form schema compiler
The npm package @airtasker/form-schema-compiler receives a total of 985 weekly downloads. As such, @airtasker/form-schema-compiler popularity was classified as not popular.
We found that @airtasker/form-schema-compiler demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
GitHub removed 27 malicious pull requests attempting to inject harmful code across multiple open source repositories, in another round of low-effort attacks.
Security News
RubyGems.org has added a new "maintainer" role that allows for publishing new versions of gems. This new permission type is aimed at improving security for gem owners and the service overall.
Security News
Node.js will be enforcing stricter semver-major PR policies a month before major releases to enhance stability and ensure reliable release candidates.