
Research
/Security News
Critical Vulnerability in NestJS Devtools: Localhost RCE via Sandbox Escape
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
@paypal/messaging-components
Advanced tools
PayPal messaging library for integrating PayPal Credit messaging on merchant websites
A messaging component allowing easy integration of PayPal Credit Messages onto your site.
See developer.paypal.com/docs/business/pay-later/integrate/
Please feel free to follow the Contribution Guidelines to contribute to this repository. PRs are welcome, but for major changes please raise an issue first.
Set up your env:
npm install
Run tests:
npm test
Run in dev mode:
npm start
npm run build
Options
-v
- version, optional-e
- environment, one of production
, sandbox
or stage
-m
- module, optional, one of library
, components
, or render
-t
- tag, optional, name of the stage tag-s
- testEnv, optional, link to a test environmentThe command you'll most likely need to use is
npm run build -- -t stage-tag-name -s test-environment-link
build
dist/
build:<env>
where <env>
is stage
, sandbox
, or production
NODE_ENV=<env>
build:analyze
build:demo
env.demo
setdev
TARGET=sdk
, NODE_ENV=local
, STAGE_TAG=local
dev:<target>
where <target>
is standalone
, modal
, or lander
TARGET=<target>
, NODE_ENV=local
, STAGE_TAG=local
modal
uses TARGET=standalone-modal
dev:<env>
where <env>
is stage
, sandbox
, or production
TARGET=standalone
and NODE_ENV=<env>
lint
preinstall
npm install
and removes node_modules/
start
npm run dev
test
test:<type>
where <type>
is func
, func:nosnaps
or func:ciupdate
func
runs all snapshot functional testsfunc:nosnaps
runs all non-snapshot functional testsfunc:ciupdate
updates all snapshots generated by functional testsnpm run dev:ci
in one command line instanceintegrationType
integrationType
is one of: api
, sdk
, standalone
, or webpage
CONFIG_PATH={locale}/{account} npm run test:func:snapshots -- --testPathPattern {integrationType}
Example
CONFIG_PATH=US/DEV_US_MULTI npm run test:func:snapshots -- --testPathPattern sdk
Alternatively, you can remove -- --testPathPattern {integrationType}
and just run the following to run tests on an account for all integration types.
CONFIG_PATH={locale}/{account} npm run test:func:snapshots
To test against PayPal's standard stage url, ensure that the demo page contains the following script, then run npm run dev:stage
:
//Change the value of the url and add the script to the demo page (i.e. standalone.html)
<script>window.__TEST_ENV__ = "https://www.{PAYPAL_STAGE_URL_HERE}.com"</script>
If you are looking to run against an alternative environment, set the window.__TEST_ENV__
global to override the environment. Please note, this is only available in development environments.
//Change the value of the test environment
<script>window.__TEST_ENV__ = "https://www.te-test-env.com"</script>
This package is published weekly, Every Wednesday. Please view our Changelog to stay updated with bug fixes and new features.
FAQs
PayPal messaging library for integrating PayPal Credit messaging on merchant websites
The npm package @paypal/messaging-components receives a total of 106 weekly downloads. As such, @paypal/messaging-components popularity was classified as not popular.
We found that @paypal/messaging-components demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
Product
Customize license detection with Socket’s new license overlays: gain control, reduce noise, and handle edge cases with precision.
Product
Socket now supports Rust and Cargo, offering package search for all users and experimental SBOM generation for enterprise projects.