
Security News
The Code You Didn't Write Is Still Yours to Defend
AI agents are pulling packages into environments no scanner is watching, creating exposure before security teams can see it.
@geeboo/epub
Advanced tools
本epubjs是定制版,添加了在jszip解析的时候进行解密。
v1.0.10
v1.0.6 v1.0.5 v1.0.4file1-src
|-book 解析的入口
|-cliff 解析 cliff文件
|-archive jszip 文件读取模块
|-container 解析container.xml文件
|-section 生成内容请求队列
|-spine 生成地址队列
|-packaging packaging(路由)解析 `linear no` 表示不显示
var book = ePub({
// 解析书本时的前置构造,files 为文件列表包含所以的文件,bookObject为 book.js 实例 ,cb 为解释回掉要求使用return 返回
openBefore: function (files, bookObject, cb) {
// 如果你想在书之前访问一个文件可以 return Promise
// 如 return bookObj.load("META-INF/cliff-support.xml", type) type :u8 、blob、text
return cb()
},
// 返回一个异步方法,并且必须return 明文内容 return Promise 并在方法内容return 内容了
contentBefore: function (entry, cb2) {
console.log("2")
// 为文件内容解析 entry 为jsZip 对象 entry cb2为默认请求
// 如 return return entry.async("string").then(function (text) {
// return text;
// });
return cb2()
}
});
获得.epub地址 -> book.open(打开图书,"binary") -> book.openEpub() 初始化epub -> book.openCliff() 获得书籍信息「新增」-> book.openContainer() 获得内容路径地址,并返回 -> book.openPackaging() 格式化包的xml-> book.unpack() 拆解包的内容
以上openCliff、openContainer、openPackaging都是基于book.load对包的内容进行提取而后分享,而book.load是基于archive 提供的jszip的能力。

Epub.js is a JavaScript library for rendering ePub documents in the browser, across many devices.
Epub.js provides an interface for common ebook functions (such as rendering, persistence and pagination) without the need to develop a dedicated application or plugin. Importantly, it has an incredibly permissive Free BSD license.
Try it while reading Moby Dick

The EPUB standard is a widely used and easily convertible format. Many books are currently in this format, and it is convertible to many other formats (such as PDF, Mobi and iBooks).
An unzipped EPUB3 is a collection of HTML5 files, CSS, images and other media – just like any other website. However, it enforces a schema of book components, which allows us to render a book and its parts based on a controlled vocabulary.
More specifically, the EPUB schema standardizes the table of contents, provides a manifest that enables the caching of the entire book, and separates the storage of the content from how it’s displayed.
Get the minified code from the build folder:
<script src="../dist/epub.min.js"></script>
If using archived .epub files include JSZip:
<script src="https://cdnjs.cloudflare.com/ajax/libs/jszip/3.1.5/jszip.min.js"></script>
Set up a element to render to:
<div id="area"></div>
Create the new ePub, and then render it to that element:
<script>
var book = ePub("url/to/book/package.opf");
var rendition = book.renderTo("area", {width: 600, height: 400});
var displayed = rendition.display();
</script>
book.renderTo("area", { method: "default", width: "100%", height: "100%" });
The default manager only displays a single section at a time.
book.renderTo("area", { method: "continuous", width: "100%", height: "100%" });
The continuous manager will display as many sections as need to fill the screen, and preload the next section offscreen. This enables seamless swiping / scrolling between pages on mobile and desktop, but is less performant than the default method.
book.renderTo("area", { flow: "auto", width: "900", height: "600" });
Flow will be based on the settings in the OPF, defaults to paginated.
book.renderTo("area", { flow: "paginated", width: "900", height: "600" });
Scrolled: book.renderTo("area", { flow: "scrolled-doc" });
Scripted content, JavasScript the ePub HTML content, is disabled by default due to the potential for executing malicious content.
This is done by sandboxing the iframe the content is rendered into, though it is still recommended to sanitize the ePub content server-side as well.
If a trusted ePub contains interactivity, it can be enabled by passing allowScriptedContent: true to the Rendition settings.
<script>
var rendition = book.renderTo("area", {
width: 600,
height: 400,
allowScriptedContent: true
});
</script>
This will allow the sandboxed content to run scripts, but currently makes the sandbox insecure.
API documentation is available at epubjs.org/documentation/0.3/
A Markdown version is included in the repo at documentation/API.md
install node.js
Then install the project dependences with npm
npm install
You can run the reader locally with the command
npm start
Test can be run by Karma from NPM
npm test
Builds are concatenated and minified using webpack and babel
To generate a new build run
npm run prepare
or to continuously build run
npm run watch
Similar to a plugins, Epub.js implements events that can be "hooked" into. Thus you can interact with and manipulate the contents of the book.
Examples of this functionality is loading videos from YouTube links before displaying a chapter's contents or implementing annotation.
Hooks require an event to register to and a can return a promise to block until they are finished.
Example hook:
rendition.hooks.content.register(function(contents, view) {
var elements = contents.document.querySelectorAll('[video]');
var items = Array.prototype.slice.call(elements);
items.forEach(function(item){
// do something with the video item
});
})
The parts of the rendering process that can be hooked into are below.
book.spine.hooks.serialize // Section is being converted to text
book.spine.hooks.content // Section has been loaded and parsed
rendition.hooks.render // Section is rendered to the screen
rendition.hooks.content // Section contents have been loaded
rendition.hooks.unloaded // Section contents are being unloaded
The reader has moved to its own repo at: https://github.com/futurepress/epubjs-reader/
Epub.js Developer Mailing List
IRC Server: freenode.net Channel: #epub.js
Follow us on twitter: @Epubjs
EPUB is a registered trademark of the IDPF.
FAQs
geeboo 定制版,添加了解密模块,基于epubjs 0.3.93
We found that @geeboo/epub demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
AI agents are pulling packages into environments no scanner is watching, creating exposure before security teams can see it.

Security News
GitHub Actions checkout now blocks risky pull_request_target checkouts by default to help prevent pwn request supply chain attacks.

Product
Socket now supports Custom Roles and Repository Access Permissions so organizations can control who can access specific repositories and actions.