
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
@cube0/middleware
Advanced tools
Shared middleware for Cube0 MCP servers (built with Hono) to handle authentication, context injection, and secure secret retrieval.
Shared middleware for Cube0 MCP servers (built with Hono) to handle authentication, context injection, and secure secret retrieval.
npm install @cube0/middleware
Authorization: Bearer <API_KEY> headers against the Cube0 platform.AsyncLocalStorage with the request context for safe global access within the request scope.getSecret() helper to securely fetch user-specific credentials (e.g., Twitter access tokens) from the Cube0 platform at runtime.Apply the cube0 middleware to your Hono application. This ensures all requests are authenticated and the context is initialized.
import { Hono } from "hono";
import { cube0 } from "@cube0/middleware";
const app = new Hono<{ Bindings: { CUBE0_URL: string } }>();
// Register middleware globally
app.use("*", cube0());
app.post("/mcp", async (c) => {
// Your MCP server logic here
return c.json({ message: "Authenticated request" });
});
export default app;
Use the getSecret helper to retrieve credentials for connected providers. This function uses the authenticated user's context to fetch the correct secrets from the Cube0 platform.
import { getSecret } from "@cube0/middleware";
// Inside your tool handler
async function postTweet(content: string) {
// Fetch secrets for the 'twitter' provider
const secrets = await getSecret("twitter");
// Use the access token
const accessToken = secrets.accessToken;
// Call Twitter API...
}
The middleware requires the CUBE0_URL environment variable to be set in your Cloudflare Worker configuration (wrangler.json or wrangler.jsonc).
// wrangler.jsonc
{
"vars": {
"CUBE0_URL": "https://cube0.ai"
}
}
cube0()Hono middleware factory. Returns a middleware function that:
Authorization header.getSecret(provider: string): Promise<any>Fetches secrets for the specified provider (e.g., "twitter", "github").
FAQs
Shared middleware for Cube0 MCP servers (built with Hono) to handle authentication, context injection, and secure secret retrieval.
We found that @cube0/middleware demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.