Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
@hammerstone/refine-stimulus
Advanced tools
Refine is a flexible query builder for your apps. It lets your users filter down to exactly what they're looking for. Completely configured on the backend.
source "https://yourKey@gem.fury.io/hammerstonedev" do
gem "refine-rails"
end
$ yarn add @hammerstone/refine-stimulus
bundle
yarn
Import the Stimulus Controllers in your application.
Typically this is in app/javascript/controllers/index.js
import { controllerDefinitions as refineControllers } from "@hammerstone/refine-stimulus"
application.load(refineControllers)
Depending on how you import Stimulus Controllers and define application
it may be Stimulus.load(refineControllers)
To make sure the Stimulus controllers are loaded properly, add window.Stimulus=application
to controllers/index.js
Then in the console inspect the stimulus object:
Stimulus.router.modulesByIdentifier
You should see the refine--....
controllers listed
yarn add jquery
import jquery from 'jquery'
window.jQuery = jquery
window.$ = jquery
app/filters
that inherits from Hammerstone::Refine::Filter
. Use this class to define the conditions that can be filtered.Example (Contacts Filter on a Contact Model)
# app/filters/contacts_filter.rb
class ContactsFilter < Hammerstone::Refine::Filter
@@default_stabilizer = Hammerstone::Refine::Stabilizers::UrlEncodedStabilizer
def initial_query
Contact.all
end
def automatically_stabilize?
true
end
def table
Contact.arel_table
end
def conditions
[
Hammerstone::Refine::Conditions::TextCondition.new("name"),
Hammerstone::Refine::Conditions::DateCondition.new("created_at"),
Hammerstone::Refine::Conditions::DateCondition.new("updated_at"),
]
end
end
include Hammerstone::FilterApplicationController
which is a helper class to get you up and running quickly. You can remove it and use your own apply_filter
method if you want.If you see this error:
NameError (uninitialized constant ApplicationController::Hammerstone
web |
web | include Hammerstone::FilterApplicationController
Please restart your server!
apply_filter
method. For this example we'll use Contacts model and filter.
@refine_filter = apply_filter(ContactsFilter)
This is a helper method you can inspect in Hammerstone::FilterApplicationController
. You probably do not want to use this method but want to implement your own. It will return @refine_filter
which is generated from the stable_id. The stable_id
comes in from the params when the form is submitted or the URL is directly changed.
If using .env, application.yml or another gem set NAMESPACE_REFINE_STABILIZERS=1
<%= render partial: 'hammerstone/filter_builder_dropdown' %>
reveal
controller to your application if using the filter_builder_dropdown
partialyarn add stimulus-reveal
//index.js
import RevealController from 'stimulus-reveal'
application.register('reveal', RevealController)
tmp/gems
and add this to your tailwing config. './tmp/gems/*/app/views/**/*.html.erb',
'./tmp/gems/*/app/helpers/**/*.rb',
'./tmp/gems/*/app/assets/stylesheets/**/*.css',
'./tmp/gems/*/app/javascript/**/*.js',
Run the following rake task:
task :add_temp_gems do
target = `bundle show refine-rails`.chomp
if target.present?
puts "Linking refine-rails to '#{target}'."
`ln -s #{target} tmp/gems/refine-rails`
end
end
Don't forget to restart the server!
_criterion.html.erb
) and daterangepicker
A quick way to load them is in the head
section. Also available as an npm package.<link rel="stylesheet" type="text/css" href="https://cdn.jsdelivr.net/npm/daterangepicker/daterangepicker.css" />
<link rel="stylesheet" href="https://unpkg.com/@icon/themify-icons/themify-icons.css">
The query builder component emits javascript events which give you information about the state of the filter. The filter emits the following events:
This event is emitted when user input has resulted in a change to the blueprint. Refine uses this event internally and you can use it in your own code to listen for changes and get the latest state of the form.
event.detail includes the following properties:
This event is emitted when the filter is validating and fetching a new URL-encoded stable ID from the server. This event signals that the current stable_id is out of date. The stable_id should not be used until a filter-stabilized event is emitted.
When the round-trip to the server completes a filter-stabilized event is emitted if the filter is valid. If the filter is not valid a filter-invalid event will be emitted.
event.detail includes the following properties:
This event is emitted when the filter has been automatically URL encoded and completed the server side calls. At this point it is safe to use the stable_id. The stable_id will look something like H4sIAPJsT2IAAzWNwQoDIQxE%252F2XOHrpX....
The stable_id allows the user to copy, share, refresh, or otherwise store the URL, but does not save it to the database. This stabilizer is a great way to allow users to not lose all of their progress without having to save every filter to the database. Note: All filters in the CF repo are automatically URL encode stabilized unless you have explicitly set it differently in your filter class.
event.detail includes the following properties:
This event is emitted when Refine has attempted to refresh the stable_id for the filter but was unable to do so because the user input is not valid.
event.detail includes the following properties:
event.detail includes the following properties storedFilterId: the primary key of the associated record in the hammerstone_refine_stored_filters_table
To force validations, make a POST request to /hammerstone/refine_blueprints with the following JSON payload:
The server will respond with a JSON payload that either includes the URL-encoded stable_id (if valid) or a JSON payload or HTML markup that can be used to rerender the form including validation messages
Example:
const response = await fetch('/hammerstone/refine_blueprints', {
headers: {
'Accept': 'application/json',
'Content-Type': 'application/json',
'X-CSRF-Token': document.querySelector("meta[name='csrf-token']")?.content
},
method: "POST",
body: JSON.stringify({
filter: 'ContactsFilter',
blueprint: JSON.stringify(blueprint),
id_suffix: 'contacts'
})
})
If you need to get a URL-encoded stable_id for a filter without relying on the filter-stabilized event, you can make a PUT request to /hammerstone/update_stable_id with the following JSON payload:
Example:
const response = await fetch(this.updateStableIdUrlValue, {
method: 'PUT',
headers: {
accept: 'application/json',
'content-type': 'application/json',
'X-CSRF-Token': token,
},
body: JSON.stringify({
filter: 'ContactsFilter',
blueprint: JSON.stringify(blueprint),
})
})
If the filter is valid, the server responds 200 OK with the stable_id in the JSON response If the filter is not valid, the server responds 422 Unprocessable Entity with an errors array in the JSON response
From this repo's directory:
We are using yalc
for local package development.
# Add yalc if you don't have it
# From this repo (refine-rails)
yarn global add yalc
# install dependencies
$ yarn
$ yalc publish
From the directory of the project including this package:
yalc link @hammerstone/refine-stimulus
When you make local updates to the package:
# From this repo (refine-rails)
yarn build
yalc push
Running yarn
again from your project's directory will revert back to the published version of the package on npm.
yarn build
. This will prepare the different javascript outputsyarn pack
. This will create a new .tgz
file for the new versionyarn publish <tgz filename> --new-version <version number in package.json>
*.tgz
fileAdd ruby gem
source "https://yourAPIKey@gem.fury.io/hammerstonedev" do
gem "refine-rails"
end
Installing the JavaScript package:
$ yarn add @hammerstone/refine-stimulus
In app/javascript/controllers/index.js
add
import { controllerDefinitions as refineControllers } from "@hammerstone/refine-stimulus"
application.load(refineControllers)
2.2.4 2022-09-14
FAQs
Refine is a flexible query builder for your apps. It lets your users filter down to exactly what they're looking for. Completely configured on the backend.
The npm package @hammerstone/refine-stimulus receives a total of 78 weekly downloads. As such, @hammerstone/refine-stimulus popularity was classified as not popular.
We found that @hammerstone/refine-stimulus demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 6 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.