Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Simple BLiP SDK for JavaScript
This is a work in progress
See more about BLiP here
If you are using node.js
(or webpack
), it's necessary to install blip-sdk
package (via npm) to access the BLiP server.
npm install --save blip-sdk lime-transport-websocket
If you are using a web application (on browser) with "pure" Javascript is possible to install the package via npm
using the <script>
tag. For this case beyond blip-sdk
package it's necessary install others dependences as the lime-js
and lime-transport-websocket
packages:
<script src="./node_modules/lime-js/dist/lime.js" type="text/javascript"></script>
<script src="./node_modules/lime-transport-websocket/dist/WebSocketTransport.js" type="text/javascript"></script>
<script src="./node_modules/blip-sdk/dist/blip-sdk.js" type="text/javascript"></script>
You can also use unpkg to get the packages if you are not using npm
on development:
<script src="https://unpkg.com/lime-js" type="text/javascript"></script>
<script src="https://unpkg.com/lime-transport-websocket" type="text/javascript"></script>
<script src="https://unpkg.com/blip-sdk" type="text/javascript"></script>
You will need an identifier
and a access key
to connect a chatbot to BLiP. To get them:
Chatbots
and then click on Create chatbot
;SDK
model option;identifier
and access key
will be displayed.In order to instantiate the client use ClientBuilder
class informing the identifier
and access key
:
import * as BlipSdk from 'blip-sdk';
import * as WebSocketTransport from 'lime-transport-websocket'
// Create a client instance passing the identifier and accessKey of your chatbot
let client = new BlipSdk.ClientBuilder()
.withIdentifier(IDENTIFIER)
.withAccessKey(ACCESS_KEY)
.withTransportFactory(() => new WebSocketTransport())
.build();
// Connect with server asynchronously
// Connection will occurr via websocket on 8081 port.
client.connect() // This method return a 'promise'.
.then(function(session) {
// Connection success. Now is possible send and receive envelopes from server. */
})
.catch(function(err) { /* Connection failed. */ });
Each client
instance represent a server connection and can be reused. To close a connection use:
client.close()
.then(function() { /* Disconnection success */ })
.catch(function(err) { /* Disconnection failed */ });
All messages sent to the chatbot are redirected to registered receivers
of messages and notifications. You also can define filters to each receiver
.
The following example show how to add a simple message receiver:
client.addMessageReceiver(true, function(message) {
// Process received message
});
The next sample show how to add notification receiver with filter to received
event type:
client.addNotificationReceiver("received", function(notification) {
// Process received notifications
});
It's also possible use a custom function as receiver filter:
Example of message receiver with filter of originator:
client.addMessageReceiver(function(message) { message.from === "553199990000@0mn.io" }, function(message) {
// Process received message
});
// Using expression lambda
client.addNotificationReceiver(() => true, function(message) {
// Process received notifications
});
Each registration of receivers return a handler
that can be used to cancel the registration:
var removeJsonReceiver = client.addMessageReceiver("application/json", handleJson);
// ...
removeJsonReceiver();
It's possible send notifications and messages only after sessions has been stablished.
The following sample show how to send a message after connection has been stablished:
client.connect()
.then(function(session) {
// After connection is possible send messages
var msg = { type: "text/plain", content: "Hello, world", to: "553199990000@0mn.io" };
client.sendMessage(msg);
});
The following sample show how to send a notification after connection has been stablished:
client.connect()
.then(function(session) {
// Sending "received" notification
var notification = { id: "ef16284d-09b2-4d91-8220-74008f3a5788", to: "553199990000@0mn.io", event: Lime.NotificationEvent.RECEIVED };
client.sendNotification(notification);
});
For information on how to contribute to this package, please refer to our Contribution guidelines.
FAQs
BLiP SDK JavaScript
We found that blip-sdk demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.