New:Microsoft Teams Notifications Are Now Available in Socket.Learn more →
Get Started

@xiboplayer/proxy

Package Overview
Dependencies
Maintainers
1
Versions
74
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@xiboplayer/proxy

CORS proxy and static server for xiboplayer (serves PWA + proxies CMS)

latest
Source
npmnpm
Version
0.7.23
Version published
Weekly downloads
17
-88.89%
Maintainers
1
Weekly downloads
 
Created
Source

@xiboplayer/proxy

CORS proxy and static server for xiboplayer shells.

Overview

Shared Express server used by all XiboPlayer shells (Electron, Chromium kiosk, standalone):

  • XMDS Proxy — forwards SOAP/XML requests to the CMS (/xmds-proxy)
  • REST Proxy — forwards REST API requests (/rest-proxy)
  • File Proxy — downloads media files with Range support (/file-proxy)
  • PWA Server — serves the PWA player as static files (/player/pwa/)

Installation

npm install @xiboplayer/proxy

Usage

As a library

import { createProxyApp, startServer } from '@xiboplayer/proxy';

// Option 1: get the Express app (for embedding in Electron, etc.)
const app = createProxyApp({
  pwaPath: '/path/to/pwa/dist',
  appVersion: '1.0.0',
});
app.listen(8765, 'localhost');

// Option 2: start a standalone server
const { server, port } = await startServer({
  port: 8765,
  pwaPath: '/path/to/pwa/dist',
  appVersion: '1.0.0',
});

As a CLI

npx xiboplayer-proxy --pwa-path=../xiboplayer-pwa/dist --port=8765

API Reference

createProxyApp({ pwaPath, appVersion })

Returns a configured Express app with all proxy routes and static PWA serving.

ParameterTypeDefaultDescription
pwaPathstring(required)Absolute path to PWA dist directory
appVersionstring'0.0.0'Version for User-Agent header

startServer({ port, pwaPath, appVersion })

Creates the app and starts listening. Returns Promise<{ server, port }>.

ParameterTypeDefaultDescription
portnumber8765Port to listen on
pwaPathstring(required)Absolute path to PWA dist directory
appVersionstring'0.0.0'Version for User-Agent header
syncGroupIdstring—Sync group ID for mDNS advertisement (lead only)
isLeadboolean—Whether to advertise via mDNS on startup
displayIdstring—Display hardware key for mDNS TXT record
syncSecretstring—Shared secret for WebSocket relay auth

Proxy Routes

RouteMethodDescription
/xmds-proxy?cms=URLALLProxies XMDS SOAP requests to URL/xmds.php
/api/*ALLForward proxy to CMS REST API (injects JWT Bearer token)
/player/GETServes PWA index.html with config injection

System Routes (v0.7.1)

RouteMethodDescription
/system/lan-ipGETReturns { ip } — machine's LAN IPv4 address
/system/discover-leadGETmDNS browse for sync lead. Query: syncGroupId. Returns { host, port } or 404
/system/advertise-syncPOSTStart mDNS advertisement. Body: { syncGroupId, port, displayId }

ContentStore Routes

RouteMethodDescription
/store/:type/*HEADExistence + size check (404 for incomplete chunked files)
/store/:type/*GETServe stored file with Range support
/store/:type/*PUTStore file content
/store/deletePOSTDelete files from store
/store/mark-completePOSTMark chunked download as complete
/store/unmark-completePOSTUnmark chunked file (keeps chunks on disk for partial re-download)
/store/missing-chunks/:type/*GETReturn { missing: number[], numChunks: number } for a chunked file
/store/listGETList all stored files with metadata

Cache-Through Mirror Routes

RouteMethodDescription
/api/v2/player/media/:idGET/HEADMedia files (images, video, audio, XLF)
/api/v2/player/layouts/:idGET/HEADLayout XLF files
/api/v2/player/widgets/:l/:r/:mGET/HEADWidget HTML
/api/v2/player/dependencies/*GET/HEADStatic resources (CSS, fonts, JS)
/api/v2/player/datasets/:id/dataGETDataset data (JSON, no caching)

Dependencies

  • express — HTTP server
  • cors — CORS middleware
  • bonjour-service — mDNS/DNS-SD for sync discovery
  • ws — WebSocket server for sync relay

xiboplayer.org · Part of the XiboPlayer SDK

Keywords

xibo

FAQs

Package last updated on 16 Apr 2026

Related posts