Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
@bucketco/openfeature-node-provider
Advanced tools
The official OpenFeature Node.js provider for [Bucket](https://bucket.co) feature management service.
The official OpenFeature Node.js provider for Bucket feature management service.
$ npm install @bucketco/openfeature-node-provider
The OpenFeature SDK is required as peer dependency.
The minimum required version of @openfeature/server-sdk
currently is 1.13.5
.
The minimum required version of @bucketco/node-sdk
currently is 2.0.0
.
$ npm install @openfeature/server-sdk @bucketco/node-sdk
The provider uses the Bucket Node.js SDK.
The available options can be found in the Bucket Node.js SDK.
import { BucketNodeProvider } from "@bucketco/openfeature-node-provider";
import { OpenFeature } from "@openfeature/server-sdk";
const provider = new BucketNodeProvider({ secretKey });
await OpenFeature.setProviderAndWait(provider);
// set a value to the global context
OpenFeature.setContext({ region: "us-east-1" });
// set a value to the invocation context
// this is merged with the global context
const requestContext = {
targetingKey: req.user.id,
email: req.user.email,
companyPlan: req.locals.plan,
};
const client = OpenFeature.getClient();
const enterpriseFeatureEnabled = await client.getBooleanValue(
"enterpriseFeature",
false,
requestContext,
);
Bucket uses a context object of the following shape:
/**
* Describes the current user context, company context, and other context.
* This is used to determine if feature targeting matches and to track events.
**/
export type BucketContext = {
/**
* The user context. If the user is set, the user ID is required.
*/
user?: { id: string; [k: string]: any };
/**
* The company context. If the company is set, the company ID is required.
*/
company?: { id: string; [k: string]: any };
/**
* The other context. This is used for any additional context that is not related to user or company.
*/
other?: Record<string, any>;
};
To use the Bucket Node.js OpenFeature provider, you must convert your OpenFeature contexts to Bucket contexts. You can achieve this by supplying a context translation function which takes the Open Feature context and returns a corresponding Bucket Context:
import { BucketNodeProvider } from "@openfeature/bucket-node-provider";
const contextTranslator = (context: EvaluationContext): BucketContext => {
return {
user: {
id: context.targetingKey,
name: context["name"]?.toString(),
email: context["email"]?.toString(),
country: context["country"]?.toString(),
},
company: {
id: context["companyId"],
name: context["companyName"],
},
};
};
const provider = new BucketNodeProvider({ secretKey, contextTranslator });
OpenFeature.setProvider(provider);
MIT License
Copyright (c) 2024 Bucket ApS
FAQs
The official OpenFeature Node.js provider for [Bucket](https://bucket.co) feature management service.
We found that @bucketco/openfeature-node-provider demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.