New Case Study:See how Anthropic automated 95% of dependency reviews with Socket.Learn More
Socket
Sign inDemoInstall
Socket

aws-sigv4

Package Overview
Dependencies
Maintainers
1
Versions
23
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

aws-sigv4

AWS Signature Version 4

  • 2.0.0
  • Source
  • npm
  • Socket score

Version published
Weekly downloads
45
decreased by-84.43%
Maintainers
1
Weekly downloads
 
Created
Source

aws-sigv4

A dependency-free, test suite-compliant, AWS Signature Version 4 library in ES6

NPM npm version Build Status ESDoc Dependency Status devDependency Status Coverage Status Code Climate Test Coverage Issue Count Codacy Badge Known Vulnerabilities

Example

const sigv4 = require('aws-sigv4');

sigv4.sign(
	secretAccessKey,
	requestDate.slice(0, 8),
	'us-east-1',
	'host',
	stringToSign
);

// Or, more specifically for S3:

const date = sigv4
	.formatDateTime(new Date())
	.slice(0, 8);
const credential = `${process.env.AWS_ACCESS_KEY_ID}/${date}/${process.env.AWS_REGION}/s3/aws4_request`
const policy = new Buffer(
	JSON.stringify({
	    expiration: new Date(Date.now() + 15 * 60000).toISOString(), // 15 minutes from now
	    conditions: [
	        {bucket: 'my-bucket-name'},
	        {key: 'my-s3-key.mov'},
	        {acl: 'private'},
	        ['starts-with', '$Content-Type', 'video/'],
	        ['content-length-range', 0, 10 * 1024 * 1024],
	        {'x-amz-credential': credential},
	        {'x-amz-algorithm': 'AWS4-HMAC-SHA256'},
	        {'x-amz-date': date + 'T000000Z'}
	    ]
	})
)
	.toString('base64');

sigv4.sign(
	process.env.AWS_SECRET_ACCESS_KEY,
	date,
	process.env.AWS_REGION,
	's3',
	policy
);

See Authenticating Requests in Browser-Based Uploads Using POST (AWS Signature Version 4) as the primary use case.

Keywords

FAQs

Package last updated on 01 Apr 2017

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts

SocketSocket SOC 2 Logo

Product

  • Package Alerts
  • Integrations
  • Docs
  • Pricing
  • FAQ
  • Roadmap
  • Changelog

Packages

npm

Stay in touch

Get open source security insights delivered straight into your inbox.


  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc