
Research
/Security News
Critical Vulnerability in NestJS Devtools: Localhost RCE via Sandbox Escape
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
@cap-js/advanced-event-mesh
Advanced tools
CDS plugin providing integration with SAP Integration Suite, advanced event mesh
CDS plugin providing integration with SAP Integration Suite, advanced event mesh.
See Getting Started on how to jumpstart your development and grow as you go with SAP Cloud Application Programming Model (CAP). To learn about messaging in CAP, please consult the guide on Events & Messaging.
Install the plugin via:
npm add @cap-js/advanced-event-mesh
Then, set the kind
of your messaging service to advanced-event-mesh
:
{
"cds": {
"requires": {
"messaging": {
"kind": "advanced-event-mesh"
}
}
}
}
The broker itself must be created manually in SAP Integration Suite, advanced event mesh and trust must be established to the respective application in SAP Cloud Identity Services, both for the Solace broker and the SEMP API. For details, please consult SAP Integration Suite, advanced event mesh's documentation at help.pubsub.em.services.cloud.sap and help.sap.com.
Specifically, you need to configure SAP Integration Suite, advanced event mesh to allow your CAP application to connect to the broker. For this, follow guide CAP Plugin for SAP Integration Suite, Advanced Event Mesh.
Finally, the broker's credentials must be provided via a user-provided service instance with the name advanced-event-mesh
and credentials in the following format:
{
"authentication-service": {
"tokenendpoint": "https://<ias host>/oauth2/token",
"clientid": "<client id>",
"clientsecret": "<client secret>"
},
"endpoints": {
"advanced-event-mesh": {
"uri": "https://<broker host>:<port>",
"smf_uri": "wss://<broker host>:<port>"
}
},
"vpn": "<vpn>"
}
To troubleshoot connection issues, set log level for component messaging
to DEBUG
.
Check cds.log()
for how to maintain log levels.
Your app must be bound to an instance of service SAP Integration Suite, advanced event mesh
with plan aem-validation-service
.
Please see Validation of VMR Provisioning for more information.
Additional configuration options for the messaging service (i.e., cds.requires.messaging
) are:
Property | Type | Description |
---|---|---|
session | SessionProperties | Used for createSession |
queue | createMsgVpnQueue | The queue object which is created via the SEMP API |
consumer | MessageConsumerProperties | Used for createMessageConsumer |
clientFactory | SolclientFactoryProperties | Used to create the SolclientFactory instance |
The default values can be found in the plugin's package.json.
As always, the effective configuration for your project can be queried via CLI command cds env
.
For more details, please refer to the messaging section of the CAP Node.js documentation.
This project is open to feature requests/suggestions, bug reports etc. via GitHub issues. Contribution and feedback are encouraged and always welcome. For more information about how to contribute, the project structure, as well as additional contribution information, see our Contribution Guidelines.
If you find any bug that may be a security problem, please follow our instructions at in our security policy on how to report it. Please do not create GitHub issues for security-related doubts or problems.
We as members, contributors, and leaders pledge to make participation in our community a harassment-free experience for everyone. By participating in this project, you agree to abide by its Code of Conduct at all times.
Copyright 2024 SAP SE or an SAP affiliate company and advanced-event-mesh contributors. Please see our LICENSE for copyright and license information. Detailed information including third-party components and their licensing/copyright information is available via the REUSE tool.
Version 0.2.0 - 2025-06-05
skipManagement
to skip creation of queue and subscription@sap/cds^9
FAQs
CDS plugin providing integration with SAP Integration Suite, advanced event mesh
The npm package @cap-js/advanced-event-mesh receives a total of 2,114 weekly downloads. As such, @cap-js/advanced-event-mesh popularity was classified as popular.
We found that @cap-js/advanced-event-mesh demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
Product
Customize license detection with Socket’s new license overlays: gain control, reduce noise, and handle edge cases with precision.
Product
Socket now supports Rust and Cargo, offering package search for all users and experimental SBOM generation for enterprise projects.