
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
@sanalabs/y-redux
Advanced tools
@sanalabs/y-redux
This package exports two React components:
SyncYJson
: Two-way synchronization of a deep YMap/YArray and a Redux state.SyncYAwareness
: Synchronization of YDoc awareness states (remote and local) and a Redux state.SyncYJson
This is a two-way synchronization of a Redux state and a YMap/YArray. When SyncYJson
is mounted it keeps the state in sync by:
The YType can be a deep structure containing YMaps, YArrays and JSON primitives.
The Yjs mutations are batched into a transaction.
Retaining object references for parts of the state that didn't change is important for performance and allows the caching mechanism of Redux selectors to function correctly.
SyncYJson
uses patchYJson
which creates Yjs operations only for the part of the state that changed.@sanalabs/json
) in the reducer that applies the Redux updates. See example (TODO).export const App = () => {
const { yMap, yProvider } = useMemo(() => {
const yProvider = new YjsProvider() // Eg. HocuspocusProvider or WebrtcProvider
const yMap = yProvider.document.getMap('data')
return { yMap, yProvider }
}, [])
useEffect(
() => () => {
yProvider.destroy()
},
[yProvider]
)
return (
<SyncYJson
yMap={yMap} // YMap to be observed for remote changes by yMap.observeDeep
setData={setData} // Action creator to be called as dispatch(setData(data))
selectData={selectData} // Selector to be used as useSelector(selectData)
/>
// Inside other components you can interact with the synced data as with any normal
// Redux state by using dispatch and useSelector and it will be seamlessly kept in sync.
<OtherComponent />
)
}
SyncYAwareness
Very similar to SyncYJson
SyncYJson
a component and not a hook?For performance and convenience. It makes no difference to the consumer of this API since
SyncYJson
doesn't return anything. Think of the component as a provider component.
The performance issue with hooks is that any time an effect within a hook runs, that triggers a re-render of
the surrounding component. Since the hooks within SyncYJson
may trigger very often due to remote changes we
noticed that it was not convenient to have the functionality as a hook.
SyncYJson
a React component and not a more generic Redux integration?Having this logic as a first class citizen in React makes it easy to control when to use SyncYJson and to have multiple instances for different parts of your application.
FAQs
Redux state synced with Yjs
The npm package @sanalabs/y-redux receives a total of 1,373 weekly downloads. As such, @sanalabs/y-redux popularity was classified as popular.
We found that @sanalabs/y-redux demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.