Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
babel-plugin-transform-react-handled-props
Advanced tools
Generates handledProps from defaultProps and propTypes during the build
Generates handledProps from defaultProps and propTypes during the build :sparkles:
$ yarn add --dev babel-plugin-transform-react-handled-props
This plugin is for Babel 7. If you need to support Babel 6 use the babel6 branch.
This plugin was originally created for Semantic UI React package. It implements useful pattern with handled props by component, using it you can let down unhandled props to child component.
Let's take an example from real life. There are cases when you need to pass some of the props to the child component. The simplest way is to use the destruction of the object.
const Foo = (props) => {
const { className, ...rest } = props
const classes = classNames(className, 'foo')
return <div {...rest} className={classes} />
}
The solution is simple and straightforward, but what if the props that will need to be handled is not used in the method? We still need to specify it explicitly.
class Foo extends React.Component {
handleClick = (e) => this.props.onClick(e)
render() {
const { className, onClick, ...rest } = this.props
const classes = classNames(className, 'foo')
return <div {...rest} className={classes} onClick={this.handleClick} />
}
}
And what if there are a lot of components? Yes, we will come to another solution, it's to rely on the React's propTypes
.
It's a good and logical solution.
class Foo extends React.Component {
static propTypes = {
className: PropTypes.string,
onClick: PropTypes.func,
}
handleClick = (e) => this.props.onClick(e)
render() {
const { className } = this.props
const classes = classNames(className, 'foo')
const rest = _.omit(this.props, _.keys(Foo.propTypes))
return <div {...rest} className={classes} onClick={this.handleClick} />
}
}
Looks pretty good? But, there is only one problem, we don't need propTypes
in the production build.
We can take the plugin to remove them, but then our solution will be broken?
It's possible that you already use this approach, but you can't get rid of propTypes
in the your bundle.
This plugin solves the described problem, so you can rely on propTypes
and at the same time remove them from the production build.
class Foo extends React.Component {
static propTypes = {
className: PropTypes.string,
onClick: PropTypes.func,
}
handleClick = (e) => this.props.onClick(e)
render() {
const { className } = this.props
const classes = classNames(className, 'foo')
const rest = _.omit(this.props, Foo.handledProps)
return <div {...rest} className={classes} onClick={this.handleClick} />
}
}
In
const Baz = (props) => (
<div {...props} />
)
Baz.propTypes = {
children: PropTypes.node,
className: PropTypes.string,
}
Out
const Baz = (props) => (
<div {...props} />
)
Baz.handledProps = ['className', 'children'];
Baz.propTypes = {
children: PropTypes.node,
className: PropTypes.string,
}
.babelrc
(Recommended).babelrc
{
"plugins": ["transform-react-handled-props"]
}
$ babel --plugins transform-react-handled-props script.js
require("babel-core").transform("code", {
plugins: ["transform-react-handled-props"]
});
ignoredProps
This options allows to ignore some props, this will allow to not add them to handledProps
.
{
"plugins": ["transform-react-handled-props", { "ignoredProps": ["children"] }]
}
In
const Baz = (props) => (
<div {...props} />
)
Baz.propTypes = {
children: PropTypes.node,
className: PropTypes.string,
}
Out
const Baz = (props) => (
<div {...props} />
)
Baz.handledProps = ['className'];
Baz.propTypes = {
children: PropTypes.node,
className: PropTypes.string,
}
Absolutely :sunglasses: You can also use in production with babel-plugin-transform-react-remove-prop-types and it will work perfectly.
const Baz = (props) => {
const rest = _.omit(props, Baz.handledProps)
return (
<div {...props}>
<Foo {...rest} />
</div>
)
}
MIT
2.1.0
FAQs
Generates handledProps from defaultProps and propTypes during the build
The npm package babel-plugin-transform-react-handled-props receives a total of 1,006 weekly downloads. As such, babel-plugin-transform-react-handled-props popularity was classified as popular.
We found that babel-plugin-transform-react-handled-props demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.