
Research
Security News
Lazarus Strikes npm Again with New Wave of Malicious Packages
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
@toast-ui/editor
Advanced tools
TOAST UI products apply Google Analytics (GA) to collect statistics on the use of open source, in order to identify how widely TOAST UI Editor is used throughout the world. It also serves as important index to determine the future course of projects. location.hostname
(e.g. ui.toast.com) is to be collected and the sole purpose is nothing but to measure statistics on the usage.
To disable GA, use the following usageStatistics
option when creating the instance.
const options = {
// ...
usageStatistics: false
};
const editor = new Editor(options);
You can also see the older versions of API page on the releases page.
TOAST UI products can be used by using the package manager or downloading the source directly. However, we highly recommend using the package manager.
TOAST UI products are registered in two package managers, npm. You can conveniently install it using the commands provided by the package manager. When using npm, be sure to use it in the environment Node.js is installed.
$ npm install --save @toast-ui/editor # Latest Version
$ npm install --save @toast-ui/editor@<version> # Specific Version
TOAST UI products are available over the CDN powered by NHN Cloud.
You can use the CDN as below.
...
<body>
...
<script src="https://uicdn.toast.com/editor/latest/toastui-editor-all.min.js"></script>
</body>
...
If you want to use a specific version, use the tag name instead of latest
in the url's path.
The CDN directory has the following structure:
- uicdn.toast.com/
├─ editor/
│ ├─ latest/
│ │ ├─ toastui-editor-all.js
│ │ ├─ toastui-editor-all.min.js
│ │ ├─ toastui-editor-viewer.js
│ │ ├─ toastui-editor-viewer.min.js
│ │ ├─ toastui-editor.css
│ │ ├─ toastui-editor.min.css
│ │ ├─ toastui-editor-viewer.css
│ │ ├─ toastui-editor-viewer.min.css
│ │ ├─ toastui-editor-only.css
│ │ ├─ toastui-editor-only.min.css
│ │ └─ theme/
│ │ ├─ toastui-editor-dark.css
│ │ └─ toastui-editor-dark.min.css
│ │ └─ i18n/
│ │ └─ ...
│ ├─ 2.0.0/
│ │ └─ ...
First, you need to add the container element where TOAST UI Editor (henceforth referred to as 'Editor') will be created.
...
<body>
<div id="editor"></div>
</body>
...
The editor can be used by creating an instance with the constructor function. To get the constructor function, you should import the module using one of the following ways depending on your environment.
import Editor from '@toast-ui/editor';
const Editor = require('@toast-ui/editor');
const Editor = toastui.Editor;
Then, you need to add the CSS files needed for the Editor. Import CSS files in node environment, and add it to html file when using CDN.
import '@toast-ui/editor/dist/toastui-editor.css'; // Editor's Style
...
<head>
...
<!-- Editor's Style -->
<link rel="stylesheet" href="https://uicdn.toast.com/editor/latest/toastui-editor.min.css" />
</head>
...
Finally you can create an instance with options and call various API after creating an instance.
const editor = new Editor({
el: document.querySelector('#editor'),
height: '500px',
initialEditType: 'markdown',
previewStyle: 'vertical'
});
editor.getMarkdown();
height
: Height in string or auto ex) 300px
| auto
initialEditType
: Initial type to show markdown
| wysiwyg
initialValue
: Initial value. Set Markdown stringpreviewStyle
: Preview style of Markdown mode tab
| vertical
usageStatistics
: Let us know the hostname. We want to learn from you how you are using the Editor. You are free to disable it. true
| false
Find out more options here.
FAQs
GFM Markdown Wysiwyg Editor - Productive and Extensible
The npm package @toast-ui/editor receives a total of 61,722 weekly downloads. As such, @toast-ui/editor popularity was classified as popular.
We found that @toast-ui/editor demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
Security News
Socket CEO Feross Aboukhadijeh discusses the open web, open source security, and how Socket tackles software supply chain attacks on The Pair Program podcast.
Security News
Opengrep continues building momentum with the alpha release of its Playground tool, demonstrating the project's rapid evolution just two months after its initial launch.