Research
Security News
Threat Actor Exposes Playbook for Exploiting npm to Build Blockchain-Powered Botnets
A threat actor's playbook for exploiting the npm ecosystem was exposed on the dark web, detailing how to build a blockchain-powered botnet.
autobind-decorator
Advanced tools
The `autobind-decorator` npm package provides a decorator for automatically binding methods to their class instance. This is particularly useful in JavaScript and TypeScript classes where you want to ensure that methods retain the correct `this` context, especially when passing them as callbacks.
Automatic Method Binding
This feature allows you to automatically bind class methods to the instance of the class. In the example, the `getValue` method is bound to the instance of `MyClass`, ensuring that `this.value` correctly refers to the instance's `value` property even when the method is called as a standalone function.
class MyClass {
constructor() {
this.value = 42;
}
@autobind
getValue() {
return this.value;
}
}
const instance = new MyClass();
const getValue = instance.getValue;
console.log(getValue()); // 42
The `core-decorators` package provides a collection of decorators, including an `autobind` decorator. It offers a broader set of decorators for various use cases, such as `@debounce`, `@memoize`, and `@readonly`, making it a more versatile choice if you need multiple types of decorators.
The `lodash-decorators` package offers a set of decorators based on lodash functions, including an `autobind` decorator. It is useful if you are already using lodash in your project and want to leverage its utility functions in a decorator form.
The `typescript-decorators` package provides a set of decorators specifically designed for TypeScript. It includes an `autobind` decorator and other useful decorators for TypeScript development, making it a good choice for TypeScript projects.
A class or method decorator which binds methods to the instance so this
is always correct, even when the method is detached.
This is particularly useful for situations like React components, where you often pass methods as event handlers and would otherwise need to .bind(this)
.
// Before:
<button onClick={ this.handleClick.bind(this) }></button>
// After:
<button onClick={ this.handleClick }></button>
As decorators are a part of future ECMAScript standard they can only be used with transpilers such as Babel.
Note Babel 6 users:
The implementation of the decorator transform is currently on hold as the syntax is not final. If you would like to use this project with Babel 6.0, you may use babel-plugin-transform-decorators-legacy which implement Babel 5 decorator transform for Babel 6.
npm install autobind-decorator
import autobind from 'autobind-decorator'
class Component {
constructor(value) {
this.value = value
}
@autobind
method() {
return this.value
}
}
let component = new Component(42)
let method = component.method // .bind(component) isn't needed!
method() // returns 42
// Also usable on the class to bind all methods
@autobind
class Component { }
You might want to look at Class instance properties.
FAQs
Decorator for binding method to an object
The npm package autobind-decorator receives a total of 152,624 weekly downloads. As such, autobind-decorator popularity was classified as popular.
We found that autobind-decorator demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A threat actor's playbook for exploiting the npm ecosystem was exposed on the dark web, detailing how to build a blockchain-powered botnet.
Security News
NVD’s backlog surpasses 20,000 CVEs as analysis slows and NIST announces new system updates to address ongoing delays.
Security News
Research
A malicious npm package disguised as a WhatsApp client is exploiting authentication flows with a remote kill switch to exfiltrate data and destroy files.