Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
database-connector-service
Advanced tools
A TypeScript-based service for managing MySQL, MSSQL, and Redis connections.
Esnek ve güçlü bir Node.js veritabanı bağlayıcısı. MySQL ve MSSQL için yerleşik destek, Redis önbellekleme, sorgu oluşturma ve işlem yönetimi özellikleri sunar.
npm install database-connector-service
Proje kök dizininizde bir .env
dosyası oluşturun:
# Veritabanı Yapılandırması
DB_TYPE=mysql # veya mssql
DB_HOST=localhost
DB_USER=your_username
DB_PASSWORD=your_password
DB_DATABASE=your_database
DB_PORT=3306 # MySQL=3306, MSSQL=1433
DB_ENCRYPT=false # MSSQL için
# Redis Yapılandırması (İsteğe bağlı)
REDIS_ENABLED=true
REDIS_HOST=localhost
REDIS_PORT=6379
REDIS_PASSWORD=
REDIS_TTL=3600
import { createQuery, query, execute, transaction } from 'database-connector-service';
// Sorgu Oluşturucu Kullanımı
const users = await createQuery('users')
.select(['id', 'name', 'email'])
.where({ active: true })
.orderBy('name')
.cache('active-users', 3600)
.getAll();
// Önbellekli direkt sorgu
const result = await query(
'SELECT * FROM users WHERE status = ?',
['active'],
{
cache: {
key: 'active-users',
ttl: 3600
}
}
);
// İşlem örneği
await transaction(async (trx) => {
await trx.query('INSERT INTO users (name) VALUES (?)', ['John']);
await trx.query('UPDATE stats SET total = total + 1');
});
// 1. Temel Sorgu
const users = await createQuery('users')
.select(['id', 'name', 'email'])
.where({ active: true })
.orderBy('name')
.getAll();
// 2. Birleştirmeler (Joins)
const orders = await createQuery('orders')
.select([
'orders.id',
'orders.total',
'users.name as user_name'
])
.leftJoin('users', 'users.id = orders.user_id')
.where({ 'orders.status': 'completed' })
.getAll();
// 3. Karmaşık Koşullar
const stats = await createQuery('orders')
.select([
'user_id',
'COUNT(*) as order_count',
'SUM(total) as total_amount'
])
.where({ status: 'completed' })
.andWhere('created_at > ?', ['2024-01-01'])
.groupBy('user_id')
.having('total_amount > ?', [1000])
.orderBy('total_amount', 'DESC')
.getAll();
// 4. Tek Kayıt
const user = await createQuery('users')
.where({ id: 1 })
.getOne();
// 5. Sayfalama
const pagedResults = await createQuery('users')
.where({ active: true })
.orderBy('name')
.limit(10)
.offset(0)
.getAll();
// 1. Basit Sorgu
const users = await query(
'SELECT * FROM users WHERE active = ?',
[true]
);
// 2. Önbellekli
const cachedUsers = await query(
'SELECT * FROM users WHERE active = ?',
[true],
{
cache: {
key: 'active-users',
ttl: 3600
}
}
);
// 3. Sayfalama
const { data, pagination } = await queryWithPagination(
'SELECT * FROM users WHERE active = ?',
[true],
{
page: 1,
pageSize: 10,
orderBy: 'name',
direction: 'ASC'
}
);
// 1. Sorgu Oluşturucu ile Önbellekleme
const users = await createQuery('users')
.where({ active: true })
.cache('active-users', 3600) // anahtar ve TTL (saniye)
.getAll();
// 2. Çoklu Önbellek Desenlerini İnvalidasyon
await invalidateCache(['users', 'orders', 'stats']);
// 3. Otomatik Önbellek İnvalidasyonu
await execute(
'INSERT INTO users (name) VALUES (?)',
['John'],
['users', 'user_stats'] // invalidasyon için önbellek desenleri
);
// İşlem Örneği
await transaction(async (trx) => {
// Kullanıcı ekle
const [user] = await trx.query(
'INSERT INTO users (name) VALUES (?) RETURNING id',
['John']
);
// Kullanıcı ID'sini kullanarak profil ekle
await trx.query(
'INSERT INTO profiles (user_id, bio) VALUES (?, ?)',
[user.id, 'New user bio']
);
// İstatistikleri güncelle
await trx.query(
'UPDATE user_stats SET total = total + 1'
);
});
Katkılarınızı bekliyoruz! Lütfen Pull Request göndermekten çekinmeyin.
MIT
FAQs
A TypeScript-based service for managing MySQL, MSSQL, and Redis connections.
The npm package database-connector-service receives a total of 11 weekly downloads. As such, database-connector-service popularity was classified as not popular.
We found that database-connector-service demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.