
Research
/Security News
9 Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.
@oada/oada-lookup
Advanced tools
JavaScript utility library to lookup OADA documents such as Well-Known (RFC 5785) resource, e.g., oada-configuration, openid-configuration, etc, and public OADA client registrations
JavaScript utility library to lookup OADA documents such as Well-Known (RFC 5785) resource, e.g., oada-configuration, openid-configuration, etc, and public OADA client registrations.
The library can be installed with npm using
$ npm install @oada/oada-lookup
The libraries test can be ran with:
$ npm test
The coverage report is generated by:
$ npm run cover
Fetch a Well-Known (RFC 5785) Resource. The hostname will automatically be parsed from any URL.
hostname {String} Hostname (or URL) hosting the Well-Known resource being
requested. Sub-domains and ports are be persevered; Protocol, path, query
parameters, and hash are dropped. It is assumed that the Well-Known resource is
hosted with TLS (https) Pull Request appreciated
suffix {String} Well-Known resource suffix being requested.
options {Object} containing at least the following properties:
timeout {Number} Default: 1000 Timeout before HTTP request fails in ms.cb {Function} Result callback. It takes the form function(err, resource) {}.
var lookup = require('oada-lookup')
var options = {
timeout: 500
}
lookup.wellKnown(
'provider.oada-dev.com',
'oada-configuration',
options,
function (err, resource) {
console.log(err)
console.log(resource)
}
)
Fetch a client registration from an OADA client id.
clientId {String} The OADA client id to lookup the client registration for. It
takes a form similar to email: id@domain.
options {Object} containing at least the following properties:
timeout {Number} Default: 1000 Timeout before HTTP request fails in ms.cb {Function} Result callback. It takes the form function(err, registration){}.
var lookup = require('oada-lookup')
var options = {
timeout: 500
}
lookup.clientRegistration('xJx82s@provider.oada-dev.com', options, function (
err,
registration
) {
console.log(err)
console.log(registration)
})
Fetch a Json Web Key Set (JWKS) from an URI.
uri {String} The URI containing the desired JWKS document. For example, the
value of the OpenID Connect openid-configuration jwks_uri property.
options {Object} containing at least the following properties:
timeout {Number} Default: 1000 Timeout before HTTP request fails in ms.cb {Function} Result callback. It takes the form function(err, jwks){}.
var lookup = require('oada-lookup')
var options = {
timeout: 500
}
lookup.jwks('provider.oada-dev.com/oidc/jwks', options, function (err, jwks) {
console.log(err)
console.log(jwks)
})
FAQs
JavaScript utility library to lookup OADA documents such as Well-Known (RFC 5785) resource, e.g., oada-configuration, openid-configuration, etc, and public OADA client registrations
We found that @oada/oada-lookup demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 7 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.

Security News
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.