
Product
PHP and Composer Support Is Now in Beta
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.
@hellocoop/api
Advanced tools
This npm package is a TypeScript implementation of the Hellō Web Client API that is used by:
The API is a single route, that by default is /api/hellocoop. Having a single route simplifies integration into an application. The endpoint handles the API as well as being the protocol endpoint for the OpenID Connect redirect_uri and third party initiated login.
The web client calls the API by passing the op query command set to one of the operations (auth|login|logout|invite)
router.ts routes the commands to the different modules
authReturns the auth object:
{
"isLoggedIn": false
}
{
"isLoggedIn": true,
"sub": "sub_vvCgtpv35lDgQpHtxmpvmnxK_2nZ",
"iat": 1699234659,
"name": "Dick Hardt",
"picture": "https://pictures.hello.coop/r/7a160eed-46bf-48e2-a909-161745535895.png",
"email": "dick.hardt@hello.coop"
}
Implemented in auth.ts
loginThe client loads /api/hellocoop?op=login to start a login flow.
Optional parameters described in Web Client API
This will:
redirect_uri if not configured by bouncing a page to the browser to learn the full URL for the endpointcode_verifier and code_challengenonceredirect_uri, code_verifier, and nonce in the hello_oidc cookieImplemented in login.ts
logoutThe client loads /api/hellocoop?op=logout to clear the auth cookie and log the user out.
Optional parameters described in Web Client API
Implemented in logout.ts
inviteThe client loads /api/hellocoop?op=invite to start the invite flow.
See the Invite API for details.
Implemented in invite.ts
The API endpoint is the redirect_uri and is where the user is redirected after interacting with their Hellō Wallet.
If a successful login at Hellō, the endpoint receives an authorization code query parameter (code). It then will:
redirect_uri, code_verifier, and nonce from the hello_oidc cookiecode, redirect_uri, code_verifier for the id_token at the Hellō token endpoint (`https://wallet.hello.coop/)id_token contains the nonce and perform standard id_token verificationloginSync function if configuredhellocoop_auth cookietarget_uriIf the user is an administrator of the Hellō application and it is running at a dynamic endpoint and the wildcard_console parameter is returned,
an intermediate page is generated by wildcard.ts and presented to the developer to simplify configuration of their application.
If the log in was unsuccessful or canceled, the endpoint receives an error query parameter and the user is redirected to an error page.
Implemented in callback.ts
This allows a user to log in to an application by clicking a link in a dashboard or loading a bookmark. The endpoint is passed the iss query parameter, which must be the Hellō issuer, https://issuer.hello.coop. login_hint or domain_hint can optionally be provided.
Implemented in initiateLogin.ts
FAQs
Client API for Hellō https://hello.dev
The npm package @hellocoop/api receives a total of 158 weekly downloads. As such, @hellocoop/api popularity was classified as not popular.
We found that @hellocoop/api demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Product
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.

Product
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.

Research
/Security News
Three compromised Rust crates pulled in a malicious dependency that downloaded and executed cross-platform malware during Cargo builds.