Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
@api-platform/mercure
Advanced tools
@api-platform/mercure
is an EventSource wrapper that discovers a Mercure Hub according to the Link headers and handles subscriptions for you.
import mercure, { close } from "@api-platform/mercure";
const res = await mercure('https://localhost/authors/1', {
onUpdate: (author) => console.log(author)
})
const author = res.then(res => res.json())
// Close if you need to
history.onpushstate = function(e) {
close('https://localhost/authors/1')
}
Assuming /authors/1
returned:
Link: <https://localhost/authors/1>; rel="self"
Link: <https://localhost/.well-known/mercure>; rel="mercure"
A new EventSource
is created by subscribing to the topic https://localhost/authors/1
on the Hub https://localhost/.well-known/mercure
.
npm install @api-platform/mercure
Use mercure
like fetch
:
import mercure, { close } from "@api-platform/mercure";
const res = await mercure('https://localhost/authors/1', {
onUpdate: (author) => console.log(author)
})
const author = res.then(res => res.json())
Available options:
onError
on EventSource error callbackEventSource
to provide your own EventSource
constructorfetchFn
to provide your own fetch function, it needs to return a response so that we can read headersThis can be used in conjunction with @api-platform/ld as the fetchFn
.
See our Tanstack query example or the source code of our home page.
FAQs
Mercure handler
We found that @api-platform/mercure demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.