data:image/s3,"s3://crabby-images/7e228/7e2287ba60e21dee87416ea9983ec241b5307ec2" alt="vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance"
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
A JavaScript Hierarchical Role Based Access Control library.
Install the package
npm i crab-rbac --save
You can use the library with require
const {rbac} = require('crab-rbac')
or import it if you are using TypeScript
import {rbac} from 'crab-rbac'
Then to initialize rbac, just build an array where every single object contains the name of the role, relative permissions and if it inherits all the permissions from a previously defined role.
For instance:
const rolesData = [
{
name: 'DISABLED',
capabilities: [],
inherits: []
},
{
name: 'VIEWER',
capabilities: ['post:read', 'comment:read'],
inherits: []
},
{
name: 'EDITOR',
capabilities: ['comment:read', 'post:edit', 'comment:edit'],
inherits: ['VIEWER']
},
{
name: 'USER_MANAGER',
capabilities: ['user:read', 'user:edit'],
inherits: []
}
]
rbac.init(rolesData)
can(capability: string, ...roles: string[]): boolean
Returns a boolean that states if the required capability can be performed by the role(s) supplied in the arguments.
capabilitiesOf(role: string): string[]
Returns all the capabilities (also the inherited ones) that a role can perform.
listRoles(): string[]
Returns all the role names loaded by the rbac library.
init(roles: Role[]): boolean
Initializes the rbac library with the list of roles provided as argument.
isInitialized(): boolean Tells if the library has been initialized
To run the tests using
npm test
is necessary to install
npm i -g ts-node
I highly suggest to install something like faucet
(npm i -g faucet
) and then pipe the output of npm test into it, in order to get an even more readable output. So the command is npm test | faucet
.
FAQs
A Hierarchical Role Based Access library. Role, not Rule!
The npm package crab-rbac receives a total of 2 weekly downloads. As such, crab-rbac popularity was classified as not popular.
We found that crab-rbac demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.