
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
babel-plugin-transform-react-flow-handled-props
Advanced tools
Generates handledProps from defaultProps and propTypes during the build
Generates handledProps from defaultProps and propTypes during the build :sparkles:
$ npm install --save-dev babel-plugin-transform-react-flow-handled-props
This plugin was originally created for Semantic React package. It implements useful pattern with handled props by component, using it you can let down unhandled props to child component.
Let's take an example from real life. There are cases when you need to pass some of the props to the child component. The simplest way is to use the destruction of the object.
const Foo = (props) => {
const { className, ...rest } = props
const classes = classNames(className, 'foo')
return <div {...rest} className={classes} />
}
The solution is simple and straightforward, but what if the props that will need to be handled is not used in the method? We still need to specify it explicitly.
class Foo extends React.Component {
handleClick = (e) => this.props.onClick(e)
render() {
const { className, onClick, ...rest } = this.props
const classes = classNames(className, 'foo')
return <div {...rest} className={classes} onClick={this.handleClick} />
}
}
And what if there are a lot of components? Yes, we will come to another solution, it's to rely on the React's propTypes
.
It's a good and logical solution.
class Foo extends React.Component {
static propTypes = {
className: PropTypes.string,
onClick: PropTypes.func,
}
handleClick = (e) => this.props.onClick(e)
render() {
const { className } = this.props
const classes = classNames(className, 'foo')
const rest = _.omit(this.props, _.keys(Foo.propTypes))
return <div {...rest} className={classes} onClick={this.handleClick} />
}
}
Looks pretty good? But, there is only one problem, we don't need propTypes
in the production build.
We can take the plugin to remove them, but then our solution will be broken?
It's possible that you already use this approach, but you can't get rid of propTypes
in the your bundle.
This plugin solves the described problem, so you can rely on propTypes
and at the same time remove them from the production build.
class Foo extends React.Component {
static propTypes = {
className: PropTypes.string,
onClick: PropTypes.func,
}
handleClick = (e) => this.props.onClick(e)
render() {
const { className } = this.props
const classes = classNames(className, 'foo')
const rest = _.omit(this.props, Foo.handledProps)
return <div {...rest} className={classes} onClick={this.handleClick} />
}
}
In
const Baz = (props) => (
<div {...props} />
)
Baz.propTypes = {
children: PropTypes.node,
className: PropTypes.string,
}
Out
const Baz = (props) => (
<div {...props} />
)
Baz.handledProps = ['className', 'children'];
Baz.propTypes = {
children: PropTypes.node,
className: PropTypes.string,
}
In
// @flow
import * as React from 'react';
import PropTypes from 'prop-types';
type Props = {
name?: string,
_text?: string,
'aria-describedby'?: string,
children?: React.Node
}
class Baz extends React.Component<Props> {
render() {
return <div {...this.props} />;
}
}
export default Baz;
Out
// @flow
import * as React from 'react';
type Props = {
name?: string;
_text?: string;
'aria-describedby'?: string;
children?: React.Node;
};
class Baz extends React.Component<Props> {
render() {
return <div {...this.props} />;
}
static handledProps = ['_text', 'aria-describedby', 'children', 'name'];
}
export default Baz;
note:
flow type
must be namedProps
.babelrc
(Recommended).babelrc
{
"plugins": ["transform-react-flow-handled-props"]
}
$ babel --plugins transform-react-flow-handled-props script.js
require("babel-core").transform("code", {
plugins: ["transform-react-flow-handled-props"]
});
ignoredProps
This options allows to ignore some props, this will allow to not add them to handledProps
.
{
"plugins": ["transform-react-flow-handled-props", { "ignoredProps": ["children"] }]
}
In
const Baz = (props) => (
<div {...props} />
)
Baz.propTypes = {
children: PropTypes.node,
className: PropTypes.string,
}
Out
const Baz = (props) => (
<div {...props} />
)
Baz.handledProps = ['className'];
Baz.propTypes = {
children: PropTypes.node,
className: PropTypes.string,
}
Absolutely :sunglasses: You can also use in production with babel-plugin-transform-react-remove-prop-types and it will work perfectly.
const Baz = (props) => {
const rest = _.omit(props, Baz.handledProps)
return (
<div {...props}>
<Foo {...rest} />
</div>
)
}
MIT
FAQs
Generates handledProps from defaultProps and propTypes during the build
The npm package babel-plugin-transform-react-flow-handled-props receives a total of 11 weekly downloads. As such, babel-plugin-transform-react-flow-handled-props popularity was classified as not popular.
We found that babel-plugin-transform-react-flow-handled-props demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.