Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
@perfood/capacitor-healthkit
Advanced tools
Capacitor plugin to read data from and write data to Apple Health
:heart: Capacitor plugin to retrieve data from HealthKit :heart:
Disclaimer : for now only some of the HK data base, in the future the retrieve base will be bigger !
You can simply put this into the info.plist
file
<key>NSHealthShareUsageDescription</key>
<string>Read Health Data</string>
<key>NSHealthUpdateUsageDescription</key>
<string>Read Health Data</string>
Do
npm i --save @perfood/capacitor-healthkit
Then
npx cap update
And if you use Ionic or Angular, here a example setup:
in your .ts file add this:
import {
ActivityData,
CapacitorHealthkit,
OtherData,
QueryOutput,
SampleNames,
SleepData,
} from '@perfood/capacitor-healthkit';
const READ_PERMISSIONS = ['calories', 'stairs', 'activity', 'steps', 'distance', 'duration', 'weight'];
and then you can create async functions like this:
public async requestAuthorization(): Promise<void> {
try {
await CapacitorHealthkit.requestAuthorization({
all: [''],
read: READ_PERMISSIONS,
write: [''],
});
} catch (error) {
console.error('[HealthKitService] Error getting Authorization:', error);
}
}
private async getActivityData(
startDate: Date,
endDate: Date = new Date(),
): Promise<QueryOutput<ActivityData>> | undefined {
try {
const queryOptions = {
sampleName: SampleNames.WORKOUT_TYPE,
startDate: startDate.toISOString(),
endDate: endDate.toISOString(),
limit: 0,
};
return await CapacitorHealthkit.queryHKitSampleType<ActivityData>(queryOptions);
} catch (error) {
console.error(error);
return undefined;
}
}
so you can use the plugin for example with the call CapacitorHealthkit.queryHKitSampleType(...
And you're all set ! :+1:
requestAuthorization(...)
queryHKitSampleType(...)
isAvailable()
multipleQueryHKitSampleType(...)
isEditionAuthorized(...)
multipleIsEditionAuthorized(...)
requestAuthorization(authOptions: AuthorizationQueryOptions) => Promise<void>
This functions will open the iOS Screen to let users choose their permissions. Keep in mind as developers, if the access has been denied by the user we will have no way of knowing - the query results will instead just be empty arrays.
Param | Type | Description |
---|---|---|
authOptions | AuthorizationQueryOptions | These define which access we need. Possible Options include ['calories', 'stairs', 'activity', 'steps', 'distance', 'duration', 'weight']. |
queryHKitSampleType<T>(queryOptions: SingleQueryOptions) => Promise<QueryOutput<T>>
This defines a query to the Healthkit for a single type of data.
Param | Type | Description |
---|---|---|
queryOptions | SingleQueryOptions | defines the type of data and the timeframe which shall be queried, a limit can be set to reduce the number of results. |
Returns: Promise<QueryOutput<T>>
isAvailable() => Promise<void>
This functions resolves if HealthKitData is available it uses the native HKHealthStore.isHealthDataAvailable() funtion of the HealthKit .
multipleQueryHKitSampleType(queryOptions: MultipleQueryOptions) => Promise<any>
This defines a query to the Healthkit for a single type of data. This function has not been tested.
Param | Type | Description |
---|---|---|
queryOptions | MultipleQueryOptions | defines the sample types which can be queried for |
Returns: Promise<any>
isEditionAuthorized(queryOptions: EditionQuery) => Promise<void>
Checks if there is writing permission for one specific sample type. This function has not been tested.
Param | Type | Description |
---|---|---|
queryOptions | EditionQuery | defines the sampletype for which you need to check for writing permission. |
multipleIsEditionAuthorized(queryOptions: MultipleEditionQuery) => Promise<void>
Checks if there is writing permission for multiple sample types. This function has not been tested.
Param | Type | Description |
---|---|---|
queryOptions | MultipleEditionQuery | defines the sampletypes for which you need to check for writing permission. |
Used for authorization of reading and writing access.
Prop | Type |
---|---|
read | string[] |
write | string[] |
all | string[] |
This interface is used for any results coming from HealthKit. It always has a count and the actual results.
Prop | Type |
---|---|
countReturn | number |
resultData | T[] |
This extends the Basequeryoptions for a single sample type.
Prop | Type |
---|---|
sampleName | string |
This extends the Basequeryoptions for a multiple sample types.
Prop | Type |
---|---|
sampleNames | string[] |
This is used for checking writing permissions.
Prop | Type |
---|---|
sampleName | string |
This is used for checking writing permissions.
Prop | Type |
---|---|
sampleNames | string[] |
This project is licensed under the MIT License
FAQs
Capacitor plugin to read data from and write data to Apple Health
The npm package @perfood/capacitor-healthkit receives a total of 60 weekly downloads. As such, @perfood/capacitor-healthkit popularity was classified as not popular.
We found that @perfood/capacitor-healthkit demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.