
Security News
PodRocket Podcast: Inside the Recent npm Supply Chain Attacks
Socket CEO Feross Aboukhadijeh discusses the recent npm supply chain attacks on PodRocket, covering novel attack vectors and how developers can protect themselves.
@mojolicious/server-starter
Advanced tools
UNIX superdaemon with support for socket activation.
This module exists to handle socket activation for TCP servers running in separate processes on UNIX. It is capable of assigning random ports to avoid race conditions when there are many services running in parallel on the same machine. As is common with large scale testing.
The superdaemon will create the listen socket and pass it to the managed process as fd=3
, similar to how systemd
handles socket activation. This also avoids any race conditions between spawning the managed process and sending the
first request, since the listen socket is active the whole time.
import http from 'http';
const server = http.createServer((req, res) => {
res.writeHead(200, {'Content-Type': 'text/plain'});
res.end('Hello World!');
});
server.listen({fd: 3});
All the web application has to do is use fd=3
as its listen socket to accept new connections from.
import ServerStarter from '@mojolicious/server-starter';
import fetch from 'node-fetch';
const server = await starter.newServer();
await server.launch('node', ['server.js']);
const url = server.url();
const res = await fetch(url);
const buffer = await res.buffer();
console.log(buffer.toString('utf8'));
await server.close();
The managed TCP server does not need to be a Node application. In fact this module was originally developed to test Mojolicious web applications written in Perl with Playwright. For more details take a look at the blog post.
import t from 'tap';
import ServerStarter from '@mojolicious/server-starter';
import {chromium} from 'playwright';
t.test('Test the WebSocket chat', async t => {
const server = await ServerStarter.newServer();
await server.launch('perl', ['chat.pl', 'daemon', '-l', 'http://*?fd=3']);
const browser = await chromium.launch();
const context = await browser.newContext();
const page = await context.newPage();
const url = server.url();
await page.goto(url);
await page.click('text=Chat');
t.equal(page.url(), url + '/chat');
await page.click('input[type="text"]');
await page.fill('input[type="text"]', 'test');
await page.click('text=Send');
await page.click('input[type="text"]');
await page.fill('input[type="text"]', '123');
await page.press('input[type="text"]', 'Enter');
const firstMessage = await page.innerText('#messages p:nth-of-type(1)');
t.equal(firstMessage, 'test');
const secondMessage = await page.innerText('#messages p:nth-of-type(2)');
t.equal(secondMessage, '123');
await context.close();
await browser.close();
await server.close();
});
$ npm i @mojolicious/server-starter
If you have any questions the documentation might not yet answer, don't hesitate to ask in the Forum, on Matrix, or IRC.
FAQs
UNIX superdaemon with support for socket activation
We found that @mojolicious/server-starter demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Socket CEO Feross Aboukhadijeh discusses the recent npm supply chain attacks on PodRocket, covering novel attack vectors and how developers can protect themselves.
Security News
Maintainers back GitHub’s npm security overhaul but raise concerns about CI/CD workflows, enterprise support, and token management.
Product
Socket Firewall is a free tool that blocks malicious packages at install time, giving developers proactive protection against rising supply chain attacks.