
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
axios-phraseapp
Advanced tools
Axios package to provide useful information and functionality about interactions with the PhraseApp API
Axios middleware/interceptor that helps to guard a bit against PhraseApp rate limiting. Highly configurable
npm install axios-phraseapp
Not working with axios 0.19.0
(As most other libraries). For details see the bug. axios 0.19.1
has fixed this bug.
The simple, no configuration behaviour of axios-phraseapp
is to add a phraseApp
property on the request/response configuration of axios requests.
const { config } = await axios.get(PHRASEAPP_REQUEST);
console.log(config.phraseApp); /** Access to the phraseApp property */
This phraseApp
property has following structure that you can extract information returned from the PhraseApp API calls and even add your own logic on top of them.
{
moduleConfig : {}, /** Module configuration */
state: {
/** Number of in-flight requests */
inFlightRequests: 0,
/** Remaining requests until limit is reached for this time slice */
remaining: null,
/** Unix Epoch value to time reset */
reset: null,
/** PhraseApp request limit */
limit: null,
/** JavaScript Date object from the `reset` time */
resetDate: null,
/** Signifies if the `axios-phraseapp` functions are active */
started: false
}
}
// CommonJS
const { attach, detach } = require("axios-phraseapp");
// ESM
import { attach, detach } from "axios-phraseapp";
// You can also consider renaming, something like:
import {
attach as phraseAppAttach,
detach as phraseAppDetach
} from "axios-phraseapp";
attach( [ AxiosInstance|AxiosStatic ], [ AxiosPhraseAppConfig ] ) : Array<InterceptorId, InterceptorId>
The attach
method, registers the request interceptors on either an axios
instance or the main imported axios
object by default.
/** Implicit */
import axios from "axios";
attach(axios);
/** Explicit */
import axios from "axios";
attach(); // Assumes axios peer dependency
/** Specific instance */
import axios from "axios";
const axiosInstance = axios.create({});
attach(axiosInstance);
* The return value of the attach
method, is an array <InterceptorId, InterceptorId>
that can be then passed as it is to detach
and remove the interceptors.
To remove the axios-phraseapp
interceptors you can use the detach
method.
/** Implicit */
import axios from "axios";
const interceptorIds = attach(axios);
detach(axios, interceptorIds);
/** Specific instance */
import axios from "axios";
const axiosInstance = axios.create({});
const interceptorIds = attach(axiosInstance);
detach(axiosInstance, interceptorIds);
The second argument to the attach
method, can take a custom configuration object, or uses some non-intrusive defaults.
{
/**
* Will cancel with Axios.Cancel() when no more quota are available
* until the next reset time.
*
* Defaults to false
*/
cancelOnQuota?: boolean;
/**
* Will log when in the zone of either a percentage or
* limit number of remaining requests.
*
* You can either pass a number e.g. 200 or certain percentage
* e.g. 1 / 5 which is the same as 0.2 .
*
* Every time that a request is in this zone, the `logFunction`
* will be triggered on request. Logging will be done
* using `logFunction` parameter.
*
* Defaults to -1, which means it will not log.
*/
logOnLimit?: number;
/**
* Method to log `logOnLimit` with.
* Defaults to `console.log`.
*/
logFunction?: function;
}
refer to LICENSE
file in this repository.
:exclamation: This repository is in no way affiliated with PhraseApp
FAQs
Axios package to provide useful information and functionality about interactions with the PhraseApp API
The npm package axios-phraseapp receives a total of 1 weekly downloads. As such, axios-phraseapp popularity was classified as not popular.
We found that axios-phraseapp demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.