
Security News
Next.js Patches Critical Middleware Vulnerability (CVE-2025-29927)
Next.js has patched a critical vulnerability (CVE-2025-29927) that allowed attackers to bypass middleware-based authorization checks in self-hosted apps.
@saleor/app-bridge
Advanced tools
npm i @saleor/app-bridge
First initialize the package by running createApp()
:
import { createApp } from "@saleor/app-bridge";
const app = createApp();
Access app state:
const { token, domain, ready, id } = app.getState();
Events are messages that originate in Saleor Dashboard.
subscribe(eventType, callback)
- can be used to listen to particular event type. It returns an unsubscribe function, which unregisters the callback.
Example:
const unsubscribe = app.subscribe("handshake", (payload) => {
setToken(payload.token); // do something with event payload
const { token } = app.getState(); // you can also get app's current state here
});
// unsubscribe when callback is no longer needed
unsubscribe();
unsubscribeAll(eventType?)
- unregisters all callbacks of provided type. If no type was provided, it will remove all event callbacks.
Example:
app.unsubscribeAll("handshake"); // unsubscribe from all handshake events
app.unsubscribeAll(); // unsubscribe from all events
Event type | Description |
---|---|
handshake | Fired when iFrame containing the App is initialized or new token is assigned |
response | Fired when Dashboard responds to an Action |
redirect | Fired when Dashboard change a subpath within the app path |
theme | Fired when Dashboard change the theme |
Actions expose a high-level API to communicate with Saleor Dashboard. They're exported under an actions
namespace.
dispatch(action)
- dispatches an Action. Returns a promise which resolves when action is successfully completed.
Example:
import { actions } from "@saleor/app-bridge";
const handleRedirect = async () => {
await app.dispatch(actions.Redirect({ to: "/orders" }));
console.log("Redirect complete!");
};
handleRedirect();
Action | Arguments | Description |
---|---|---|
Redirect | to (string) - relative (inside Dashboard) or absolute URL path | |
newContext (boolean) - should open in a new browsing context |
FAQs
Library for Dashboard <-> Saleor App communication
The npm package @saleor/app-bridge receives a total of 16 weekly downloads. As such, @saleor/app-bridge popularity was classified as not popular.
We found that @saleor/app-bridge demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 7 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Next.js has patched a critical vulnerability (CVE-2025-29927) that allowed attackers to bypass middleware-based authorization checks in self-hosted apps.
Security News
A survey of 500 cybersecurity pros reveals high pay isn't enough—lack of growth and flexibility is driving attrition and risking organizational security.
Product
Socket, the leader in open source security, is now available on Google Cloud Marketplace for simplified procurement and enhanced protection against supply chain attacks.