Research
Security News
Kill Switch Hidden in npm Packages Typosquatting Chalk and Chokidar
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
@justinribeiro/html5-dragdroptouch-shim
Advanced tools
An opinionated shim that polyfills HTML5 drag and drop support on mobile devices with Event.ComposedPath() support
An opinionated shim that polyfills HTML5 drag and drop support on mobile devices with Event.ComposedPath() support
While this is in large part an ES Modules refactor of Bernado's dragdroptouch polyfill (which deserves the bulk of the love by the way), this version differs in two keys areas:
Re: finding the draggable. Uses event.composedPath() to allow use to hunt for draggables within open ShadowRoots
Re: finding the dropzone. Uses event.composedPath() to find the target shadowRoot, then uses DocumentOrShadowRoot.elementFromPoint to locate our dropzone target.
This allows it to be more readily be used with ShadowDOM and web components, which is my primary use case for it to be honest.
Install via yarn or npm:
yarn add @justinribeiro/html5-dragdroptouch-shim
Only load the module if device has touch support.
if ('ontouchstart' in document) {
import('@justinribeiro/html5-dragdroptouch-shim/dist/esm.js').then(module => {
const shim = new module.default();
});
status.textContent = 'TOUCH DETECTED: DragDropTouch shim loaded!';
} else {
status.textContent = 'NATIVE DRAGDROP DETECTED: no shim loaded.';
}
The class constructor can take an array of options if you want more control over the various triggers and delays within the shim:
import { default as DdtShim } from '@justinribeiro/html5-dragdroptouch-shim';
const opts = {
threshold = 5,
opacity = 0.8,
dblClick = 500,
ctxMenu = 900,
isPressHoldMode = 400,
pressHoldAwait = 400,
pressHoldMargin = 25,
pressHoldThreshold = 0
}
const startUpTheShim = new DdtShim(opts);
You can run the examples via the demo site.
There are a host of examples within the demo holder, including a set of example web components that support drag and drop and the shim. To run locally:
yarn dev
FAQs
An opinionated shim that polyfills HTML5 drag and drop support on mobile devices with Event.ComposedPath() support
We found that @justinribeiro/html5-dragdroptouch-shim demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.