Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
@tweedegolf/sab-adapter-azure-blob
Advanced tools
Provides an abstraction layer for interacting with Microsoft Azure Blob Storage cloud service.
An adapter that provides an abstraction layer over the API of the Microsoft Azure Blob cloud storage service.
This adapter is one of the adapters that is meant to be used as a plugin of the Storage Abstraction package. However it can be used standalone as well, see below.
The API of the adapter abstracts away the differences between the API's of cloud storage services. The API only supports the basic, most commonly used cloud service operations such as creating a bucket, storing files and so on.
It is also possible to access all the specific functionality of the cloud service API through the service client of the adapter, see here.
If you are new to the Storage Abstraction library you may want to read this first.
import { Storage, StorageType } from "@tweedegolf/storage-abstraction";
const configuration = {
type: StorageType.AZURE,
accountName: "yourAccount",
accountKey: "yourKey",
};
const storage = new Storage(configuration);
const result = await storage.listBuckets();
console.log(result);
The Storage class is cloud service agnostic and doesn't know anything about the adapter it uses and adapters are completely interchangeable. It only expects the adapter to have implemented all methods of the IAdapter
interface, see the API.
When you create a Storage instance it checks the mandatory type
key in the configuration object and then loads the appropriate adapter module automatically from your node_modules folder using require()
. For more information please read this.
The configuration object that you pass to the Storage constructor is forwarded to the constructor of the adapter.
The Storage constructor is only interested in the type
key of the configuration object, all other keys are necessary for configuring the adapter.
The Storage constructor expects the configuration to be of type StorageAdapterConfig
.
The adapter expects the configuration to be of type AdapterConfig
or a type that extends this type.
export interface AdapterConfig {
bucketName?: string;
[id: string]: any; // any mandatory or optional key
}
export interface StorageAdapterConfig extends AdapterConfig {
type: string;
}
The type of the configuration object for this adapter:
export interface AdapterConfigAzure extends AdapterConfig {
accountName?: string;
connectionString?: string;
accountKey?: string;
sasToken?: string;
blobDomain?: string;
}
Examples with configuration object:
const s = new Storage({
type: StorageType.AZURE,
accountName: "your-account-name",
accountKey: "your-account-key",
});
const s = new Storage({
type: StorageType.AZURE,
accountName: "your-account-name",
accountKey: "your-account-key",
bucketName: "the-buck"
maxTries: 3
});
const s = new Storage({
type: StorageType.AZURE,
accountName: "your-account-name",
sasToken: "your-sas-token",
blobDomain: "your-blob-domain", // Defaults to blob.core.windows.net
bucketName: "the-buck"
});
Same examples with configuration url:
const s = new Storage("azure://your-account-name:your-account-key");
const s = new Storage("azure://your-account-name:your-account-key@the-buck?maxTries=3");
For more information about configuration urls please read this.
There are multiple ways to login to Azure Blob Storage. Microsoft recommends to use passwordless authorization, for this you need to provide a value for accountName
which is the name of your storage account. Then you can either login using the Azure CLI command az login
or by setting the following environment variables:
AZURE_TENANT_ID
AZURE_CLIENT_ID
AZURE_CLIENT_SECRET
You can find these values in the Azure Portal
Alternately you can login by:
connectionString
accountName
and accountKey
accountName
and sasToken
Note that if you don't use the accountKey
for authorization and you add files to a bucket you will get this error message:
'Can only generate the SAS when the client is initialized with a shared key credential'
This does not mean that the file hasn't been uploaded, it simply means that no public url can been generated for this file.
You can also use the adapter standalone, without the need to create a Storage instance:
import { AdapterAzureBlob } from "@tweedegolf/sab-adapter-azure-blob";
const a = new AdapterAzureBlob({
accountName: "yourAccount",
});
const r = await a.listBuckets();
console.log(r);
For a complete description of the Adapter API see this part documentation of the Storage Abstraction package readme.
FAQs
Provides an abstraction layer for interacting with Microsoft Azure Blob Storage cloud service.
The npm package @tweedegolf/sab-adapter-azure-blob receives a total of 155 weekly downloads. As such, @tweedegolf/sab-adapter-azure-blob popularity was classified as not popular.
We found that @tweedegolf/sab-adapter-azure-blob demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.