
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@notiflyio/nextjs
Advanced tools
<Inbox />.Notifly provides the @notiflyio/nextjs library that helps to add a fully functioning <Inbox /> to your web application in minutes.
Full documentation: https://notifly.io.
@notiflyio/nextjs npm package in your nextjs appnpm install @notiflyio/nextjs
import { Inbox } from '@notiflyio/nextjs';
function App() {
return (
<Inbox
subscriber='SUBSCRIBER_ID'
applicationIdentifier='APPLICATION_IDENTIFIER'
/>
);
}
You can use the open prop to manage the Inbox popover open state.
import { Inbox } from '@notiflyio/nextjs';
function App() {
const [open, setOpen] = useState(false);
return (
<div>
<Inbox
subscriber='SUBSCRIBER_ID'
applicationIdentifier='APPLICATION_IDENTIFIER'
open={open}
/>
<button onClick={() => setOpen(true)}>Open Inbox</button>
<button onClick={() => setOpen(false)}>Close Inbox</button>
</div>
);
}
You can pass the localization prop to the Inbox component to change the language of the Inbox.
import { Inbox } from '@notiflyio/nextjs';
function App() {
return (
<Inbox
subscriber='SUBSCRIBER_ID'
applicationIdentifier='APPLICATION_IDENTIFIER'
localization={{
'inbox.status.archived': 'Archived',
'inbox.status.unread': 'Unread',
'inbox.status.options.archived': 'Archived',
'inbox.status.options.unread': 'Unread',
'inbox.status.options.unreadRead': 'Unread/Read',
'inbox.status.unreadRead': 'Unread/Read',
'inbox.title': 'Inbox',
'notifications.emptyNotice': 'No notifications',
locale: 'en-US',
}}
/>
);
}
When you add the Inbox to your application you are required to pass a subscriberId which identifies your end-customer, and the application identifier which acts as a public key to communicate with the notification feed API.
A malicious actor can access the user feed by accessing the API and passing another subscriberId using the public application identifier.
HMAC encryption will make sure that a subscriberId is encrypted using the secret API key, and those will prevent malicious actors from impersonating users.
In order to enable Hash-Based Message Authentication Codes, you need to visit the Notifly dashboard In-App settings page and enable HMAC encryption for your environment.
import { createHmac } from 'crypto';
const subscriberHash = createHmac('sha256', process.env.NOTIFLY_SECRET_KEY).update(subscriberId).digest('hex');
<Inbox
subscriber={'SUBSCRIBER_ID_PLAIN_VALUE'}
subscriberHash={'SUBSCRIBER_ID_HASH_VALUE'}
applicationIdentifier={'APPLICATION_IDENTIFIER'}
/>
Note: If HMAC encryption is active in In-App provider settings and
subscriberHashalong withsubscriberIdis not provided, then Inbox will not load
If you're using the context prop to pass additional data (e.g., tenant information, environment, etc.), you should also generate a contextHash to prevent context tampering:
import { createHmac } from 'crypto';
import { canonicalize } from '@tufjs/canonical-json';
const context = { tenant: 'acme', app: 'dashboard' };
const contextHash = createHmac('sha256', process.env.NOTIFLY_SECRET_KEY)
.update(canonicalize(context))
.digest('hex');
<Inbox
subscriber={'SUBSCRIBER_ID_PLAIN_VALUE'}
subscriberHash={'SUBSCRIBER_ID_HASH_VALUE'}
context={{ tenant: 'acme', app: 'dashboard' }}
contextHash={'CONTEXT_HASH_VALUE'}
applicationIdentifier={'APPLICATION_IDENTIFIER'}
/>
Note: When HMAC encryption is enabled and
contextis provided, thecontextHashis required. The hash is order-independent, so{a:1, b:2}produces the same hash as{b:2, a:1}.
Point the Inbox at your Notifly deployment's API and socket services (for the hosted platform: https://api.notifly.io and its websocket service).
import { Inbox } from '@notiflyio/nextjs';
function App() {
return (
<Inbox
backendUrl='YOUR_BACKEND_URL'
socketUrl='YOUR_SOCKET_URL'
subscriber='SUBSCRIBER_ID'
applicationIdentifier='APPLICATION_IDENTIFIER'
/>
);
}
FAQs
Notifly Next.js SDK
The npm package @notiflyio/nextjs receives a total of 7 weekly downloads. As such, @notiflyio/nextjs popularity was classified as not popular.
We found that @notiflyio/nextjs demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.