
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Highly opinionated session management tool for NextJS Frontends
Add environment vars (dont expose them publically!!)
//.env
CELESTYA_SECRET=XXXXXX // AT_LEAST_32_CHARACTERS
CELESTYA_COOKIE_NAME=XXXX // COOKIE_NAME
CELESTYA_SECURE=true // true / false
Configure the api endpoints
// /src/app/api/[[...endpoint]]
import { API_URL, HOST } from "@/config/env";
import { IConfig, IRequestOptions, Proxy } from "celestya";
const config: IConfig = {
host: HOST || "missing-host",
route: "/api",
apiUrl: API_URL || "missing-api-url",
userEndpoint: "/user",
};
export const POST = (req: any, opt: IRequestOptions) => Proxy("POST", req, opt, config);
export const GET = (req: any, opt: IRequestOptions) => Proxy("GET", req, opt, config);
export const DELETE = (req: any, opt: IRequestOptions) => Proxy("DELETE", req, opt, config);
Configure the provider
// /src/app/layout.tsx
import { AuthProvider, Logout } from "celestya/client";
export default function RootLayout({
children,
}: {
children: React.ReactNode,
}) {
return (
<html lang="en">
<body>
<AuthProvider>{children}</AuthProvider>
</body>
</html>
);
}
Use the getSession function in server components (keep in mind they dont revalidate often!)
// /src/app/navbar.tsx
import { getSession, /* Session */ } from "celestya";
// Optionally provide a user object
interface User {
email: string
name: string
}
const Navbar = async () => {
// const session: Session<User> = await getSession(); <- optional
const session = await getSession<User>();
return <div>Welcome: {session.user?.name}</div>;
};
export default Navbar;
Use the apiFetch function in server components
// /src/app/navbar.tsx
import { apiFetch } from "celestya";
import { config } from "@/app/api/[[...endpoint]]/route"
// Optionally provide a user object
interface User {
email: string
name: string
}
const Navbar = async () => {
const user = await apiFetch("/user", {}, config)
return <div>Welcome: {session.user?.name}</div>;
};
export default Navbar;
Use the other functions in client components
// /src/app/page.tsx
import { useAuth } from 'celestya/client'
// Optionally provide a user object
interface User {
email: string
name: string
}
const Home = async () => {
const { ready, get } = useAuth()
const handleClick = () => {
try {
if (!ready) throw new Error('Not ready')
const res = await get('/user/billing')
console.log(res)
} catch (e) {
console.log(e)
}
}
return <Button onClick={handleClick}>Welcome: {session.user?.name}</div>;
};
export default Navbar;
FAQs
Highly opinionated session management tool for NextJS
The npm package celestya receives a total of 0 weekly downloads. As such, celestya popularity was classified as not popular.
We found that celestya demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.