Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
alipay-webpay-sdk
Advanced tools
支付宝nodejs版网页扫码sdk
npm install alipay-webpay-sdk --save
// ES6
import AliPayClient from "alipay-webpay-sdk";
// ES5
const AliPayClient = require("alipay-webpay-sdk");
// 实例化
const alipay = new AliPayClient({见实例化参数列表});
参数名 | 意义/类型 | 必须 | 默认值 |
---|---|---|---|
appId | 应用id/String | 是 | N/A |
url | 支付宝网关地址/String | 是 | N/A |
notifyUri | 同异步通知地址, 包含async(异步)和sync(两个属性)/Object | 是 | N/A |
publicKey | 支付宝公钥/String | 是 | N/A |
privatekey | 支付宝私钥/String | 是 | N/A |
signType | 签名类型, RSA类型的还没做支持/String | 否 | RSA2 |
charset | 提交字符集 | 否 | utf-8 |
方法名 | 意义 |
---|---|
alipay.pay({见apipay.pay参数}) | 创建网页扫码支付的表单 |
alipay.verifySign(支付宝返回的请求主体) | 验证支付宝签名 |
参数名 | 意义/类型 | 必须 | 默认值 |
---|---|---|---|
outTradeNo | 内部订单号, 请求支付宝网页支付之前, 应该自己先生成一个内部订单号/String | 是 | N/A |
subject | 订单标题/String | 是 | N/A |
body | 订单描述/String | 否 | "" |
productCode | 产品编码/String | 否 | FAST_INSTANT_TRADE_PAY |
totalAmount | 订单总价, 分为单位/Number | 是 | N/A |
FAQs
nodejs alipay 'alipay.trade.page.pay' sdk
The npm package alipay-webpay-sdk receives a total of 0 weekly downloads. As such, alipay-webpay-sdk popularity was classified as not popular.
We found that alipay-webpay-sdk demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.