
Research
Security News
Lazarus Strikes npm Again with New Wave of Malicious Packages
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
auth0-webtask-widget
Advanced tools
// Get a reference to an existing HTMLElement instance
var containerEl = document.getElementById('container');
// Create a webtask widget in the element with id `container`.
// The webtask widget will prompt the user for their phone # or email address
// the first time they visit the page. Because `storeProfile` is enabled,
// the user's credentials will be saved locally for the next time they visit.
var editor = webtaskWidget.createEditor({
mount: containerEl,
storeProfile: true,
});
// The returned editor object is an instance of an A0EditorWidget class that
// emits certain events and gives programmatic access to some of the underlying
// functionality of the widget.
editor.on('save', function (webtask) {
console.log('I just saved a webtask that can be accessed at', webtask.url);
});
Create a widget that lists cron jobs associated with the active profile
Create a widget that lets users create or edit Webtasks and Cron Jobs
Create a widget that allows users to obtain Sandbox credentials
Create a widget that streams logs for a container
Create a widget that lists cron jobs associated with the active profile
Kind: global function
Param | Type | Description |
---|---|---|
[options] | Object | Customize the behaviour and appearance of the widget |
[options.mount] | HTMLElement | Indicate where the widget should be mounted. If not specified the widget will be shown as a modal dialog. |
[options.url] | String | The url of the Webtask cluster to be used. Defaults to https://webtask.it.auth0.com. |
[options.token] | String | The webtask token of the current user. If missing, and no {@see options.readProfile} profided, the SMS/email login flow will be triggered. |
[options.container] | String | The webtask container of the current user. If missing, will be derived from {@see options.token}, from the result of {@see options.readProfile}, or finally from the result of the SMS/email login flow. |
[options.readProfile] | function | A function that should return a Object or a Promise for an object with url , token and container properties. |
[options.writeProfile] | function | A function that will be called with the resolved Profile that should return a Promise that resolves once the profile has been written. |
[options.storageKey] | function | A key that will be used by localStorage to read/write the resolved Profile when you do not use pass in custom {@see options.readProfile} and {@see options.writeProfile} functions. |
Create a widget that lets users create or edit Webtasks and Cron Jobs
Kind: global function
Param | Type | Description |
---|---|---|
[options] | Object | Customize the behaviour and appearance of the widget |
[options.mount] | HTMLElement | Indicate where the widget should be mounted. If not specified the widget will be shown as a modal dialog. |
[options.url] | String | The url of the Webtask cluster to be used. Defaults to https://webtask.it.auth0.com. |
[options.token] | String | The webtask token of the current user. If missing, and no {@see options.readProfile} profided, the SMS/email login flow will be triggered. |
[options.container] | String | The webtask container of the current user. If missing, will be derived from {@see options.token}, from the result of {@see options.readProfile}, or finally from the result of the SMS/email login flow. |
[options.readProfile] | function | A function that should return a Object or a Promise for an object with url , token and container properties. |
[options.writeProfile] | function | A function that will be called with the resolved Profile that should return a Promise that resolves once the profile has been written. |
[options.storageKey] | function | A key that will be used by localStorage to read/write the resolved Profile when you do not use pass in custom {@see options.readProfile} and {@see options.writeProfile} functions. |
Create a widget that allows users to obtain Sandbox credentials
Kind: global function
Param | Type | Description |
---|---|---|
[options] | Object | Customize the behaviour and appearance of the widget |
[options.mount] | HTMLElement | Indicate where the widget should be mounted. If not specified the widget will be shown as a modal dialog. |
[options.url] | String | The url of the Webtask cluster to be used. Defaults to https://webtask.it.auth0.com. |
[options.token] | String | The webtask token of the current user. If missing, and no {@see options.readProfile} profided, the SMS/email login flow will be triggered. |
[options.container] | String | The webtask container of the current user. If missing, will be derived from {@see options.token}, from the result of {@see options.readProfile}, or finally from the result of the SMS/email login flow. |
Create a widget that streams logs for a container
Kind: global function
Param | Type | Description |
---|---|---|
[options] | Object | Customize the behaviour and appearance of the widget |
[options.mount] | HTMLElement | Indicate where the widget should be mounted. If not specified the widget will be shown as a modal dialog. |
[options.url] | String | The url of the Webtask cluster to be used. Defaults to https://webtask.it.auth0.com. |
[options.token] | String | The webtask token of the current user. If missing, and no {@see options.readProfile} profided, the SMS/email login flow will be triggered. |
[options.container] | String | The webtask container of the current user. If missing, will be derived from {@see options.token}, from the result of {@see options.readProfile}, or finally from the result of the SMS/email login flow. |
[options.readProfile] | function | A function that should return a Object or a Promise for an object with url , token and container properties. |
[options.writeProfile] | function | A function that will be called with the resolved Profile that should return a Promise that resolves once the profile has been written. |
[options.storageKey] | function | A key that will be used by localStorage to read/write the resolved Profile when you do not use pass in custom {@see options.readProfile} and {@see options.writeProfile} functions. |
git clone git@github.com:auth0/auth0-webtask-widget.git
cd auth0-webtask-widget
npm install
npm run develop
This starts webpack-dev-server
at http://localhost:8080.
The script will watch all dependencies and recompile on changes. Everything is
served from memory with source-maps.
npm run build
This creates builds in the ./dist
folder.
Two builds are created:
webtask.js
- Production bundle.webtask.min.js
- Development bundle.A profile represents a user's claim to create and run webtasks on a webtask cluster as defined by sandboxjs:
Profiles are the combination of:
url
- The url of the webtask clustercontainer
- The container in which the webtask will be runtoken
- The user's webtask TokenA webtask token is a JSON Web Token that encodes a user's claims to perform actions on a webtask cluster. See: the webtask documentation for details on how this works.
A webtask is a claim to run code at a url where that code will have access to any secrets embedded in the webtask. Webtask objects expose several properties and methods.
If you have found a bug or if you have a feature request, please report them at this repository issues section. Please do not report security vulnerabilities on the public GitHub issue tracker. The Responsible Disclosure Program details the procedure for disclosing security issues.
This project is licensed under the MIT license. See the LICENSE file for more info.
FAQs
Embeddable webtask toolkit
The npm package auth0-webtask-widget receives a total of 1 weekly downloads. As such, auth0-webtask-widget popularity was classified as not popular.
We found that auth0-webtask-widget demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
Security News
Socket CEO Feross Aboukhadijeh discusses the open web, open source security, and how Socket tackles software supply chain attacks on The Pair Program podcast.
Security News
Opengrep continues building momentum with the alpha release of its Playground tool, demonstrating the project's rapid evolution just two months after its initial launch.