
Research
Security News
Malicious PyPI Package Exploits Deezer API for Coordinated Music Piracy
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
@collboard/modules-sdk
Advanced tools
Modules SDK toolkit for Collboard.com. Here is the sample of very simple module. And here you can read full manual.
npm install @collboard/modules-sdk
{
"version": "1.0.0",
"main": "./src/sampleButtonModule.tsx",
"scripts": {
"start": "colldev"
},
"dependencies": {
"@collboard/modules-sdk": "^11.2.2-1"
}
}
It can be either TypeScript or JavaScript. It can import other files or node modules (colldev internally uses webpack with ts-loader).
import { declareModule, ExtraJsxPlace, makeExtrajsxModule } from '@collboard/modules-sdk';
import * as React from 'react';
declareModule(
makeExtrajsxModule({
manifest: {
name: 'MyFirstModule',
},
place: ExtraJsxPlace.EdgeRight,
createExtraJsx({
routingSystem,
translationsSystem,
apiClient,
materialArtVersioningSystem: { cornerstoneArts },
}) {
return (
<button
onClick={async () => {
alert(`Hello from Collboard modules!`);
}}
className="button button-primary button-vertical"
>
<span>Hello World!</span>
</button>
);
},
}),
);
# Linux, WSL
colldev
# Windows, PowerShell
npx colldev
# Or by NPM
npm start
# You can also run full command
# Note: "colldev" is just shortcut for "colldev develop"
colldev develop
# And disable to open browser on dev.collboard.com
colldev develop --open false
Create file .gitignore and ignore temporary files and modules.
.colldev
node_modules
Colldev will automatically look into your package.json, finds main entry (it can be typescript or javascript file). And watch, build and serve changes to Collboard in development mode.
Then you open Collboard in developer mode - dev.collboard.com and there you will see modules that you are working on.
Most of the modules make sense on the board (not the homepage) so you will probably need to create a new board.
These modules will be automatically installed & hot reloaded (uninstalled+installed) as you go.
Notice that boards+its contents created under development mode will be automatically erased after some time.
Run colldev commant with publish modifier. This will send module to Collboard server as a release candidate to authorize. Please provide contact to author in package.json if there is some problem with the module to contact you and solve it.
When you are updating, please provide new version in package json.
# Linux, WSL
colldev publish
# Windows, PowerShell
npx colldev publish
Tip: You can also setup postversion command to publish automatically.
In setup function you are interacting with Collboard systems. Theese are something like APIs each controlling some part of collboard app.
Typically you are registering something under theese sytems. This will returns you destroyable which you can directly return from your setup function.
ApiClient provides API calls to the remote server.
AppState is not quite a system but an object representing the state of the Collboard app.
ArtVersionSystem synchronizes the arts with the remote server.
AttributesSystem manages shared art attributes and modules capable of selecting from them. It auto-install/uninstall attribute modules.
CollSpace manages 3D objects rendered by WebGL (BABYLON JS) and provides all the tooling around the 3D scene, positioning, textures, materials, etc.
CreateSystem allows importing which allows to import/create arts from other sources. Note: CreateSystem - for individual arts, GenerateSystem - for whole board Note: CreateSystem+GenerateSystem and ExportSystem are in some kind opposites.
ExportSystem creates other files from the board or the part of it. Note: CreateSystem+GenerateSystem and ExportSystem are in some kind opposites. Note: This system is not just for exporting but also saves to native format.
Import system makes support for files which are dragged onto board, imporded or pasted It auto-install/uninstall file support modules.
ExtraJsxSystem can register and manage additional JSX Note: ExtraJSXSystem is for JSX (HTML) vs. StyleSystem is for CSS styles
FocusSystem can register and manage unique focuses and icons which there are.
IdentitySystem identifies the User by a pseudonym.
ModuleStore unites all module store connectors into one API, so consumer have same way how to get internal or external module
RoutingSystem provides for core, other systems and modules registration of routes and hashtag routes. @see https://github.com/collboard/collboard/issues/97
Serializer can serialize/deserialize objects. Primarily it is serialized arts.
ShortcutsSystem can register and manage keyboard shortcuts like Ctrl + C by modules (or maybe other systems).
StyleSystem can register and manage additional CSS styles for modules. It can scope CSS so it will do not affect others.
Note: ExtraJSXSystem is for JSX (HTML) vs. StyleSystem is for CSS styles
ToolbarSystem can register and manage toolbars and icons which there are.
TranslationsSystem manages messages across core, systems and modules.
Makers are helpers which helps to create an module. Maker is a pure function that transforms a simpler form of module definition to module definition which will be accepted by declareModule. So you still need to call declareModule.
FAQs
Modules SDK toolkit for collaborative whiteboard platform Collboard.com.
The npm package @collboard/modules-sdk receives a total of 536 weekly downloads. As such, @collboard/modules-sdk popularity was classified as not popular.
We found that @collboard/modules-sdk demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.
Security News
Newly introduced telemetry in devenv 1.4 sparked a backlash over privacy concerns, leading to the removal of its AI-powered feature after strong community pushback.