Security News
The Risks of Misguided Research in Supply Chain Security
Snyk's use of malicious npm packages for research raises ethical concerns, highlighting risks in public deployment, data exfiltration, and unauthorized testing.
flux-constant
Advanced tools
Unique constants for Flux apps.
$ npm install flux-constant
Create constants individually.
var FluxConstant = require('flux-constant');
var IMPORTANT_THING = new FluxConstant('IMPORTANT_THING');
console.log(IMPORTANT_THING);
// { name: 'IMPORTANT_THING' }
console.log(IMPORTANT_THING.toString());
// IMPORTANT_THING
Create a set of constants.
var FluxConstant = require('flux-constant');
var Set = FluxConstant.set([
'SEND_REQUEST',
'RECEIVE_RESPONSE'
]);
console.log(Set);
/*
{
SEND_REQUEST: { name: 'SEND_REQUEST' },
RECEIVE_RESPONSE: { name: 'RECEIVE_RESPONSE' }
}
*/
console.log(ActionTypes.SEND_REQUEST instanceof FluxConstant);
// true
With a Flux application you may have a set of constants such as:
var ContactConstants = {
ActionTypes: {
SEND_REQUEST: 'SEND_REQUEST',
RECEIVE_RESPONSE: 'RECEIVE_RESPONSE'
}
};
module.exports = ContactConstants;
You may have another set of constants that are really similar, but unreleated.
var SignupConstants = {
ActionTypes: {
SEND_REQUEST: 'SEND_REQUEST',
RECEIVE_RESPONSE: 'RECEIVE_RESPONSE'
}
};
module.exports = SignupConstants;
But we just created action types that could collide. Let's compare a bit:
var ContactConstants = require('./ContactConstants');
var SignupConstants = require('./SignupConstants');
ContactActionTypes = ContactConstants.ActionTypes;
SignupActionTypes = SignupConstants.ActionTypes;
console.log(ContactActionTypes.SEND_REQUEST === SignupActionTypes.SEND_REQUEST);
// true
This could bite us if we use these two sets of constants in the same process. For example if a store was using these action types, it could get confused thinking an action was the one it was listening for, when it really wasn't. This is because we're just comparing simple strings.
One way to fix this is creating longer, more unique names:
var ContactConstants = {
ActionTypes: {
CONTACT_SEND_REQUEST: 'CONTACT_SEND_REQUEST',
CONTACT_RECEIVE_RESPONSE: 'CONTACT_RECEIVE_RESPONSE'
}
};
module.exports = ContactConstants;
This doesn't seem like a great way to move forward though. These names can get out of control as the application grows.
So instead of passing around strings we can create objects that are unique. And best of all we can keep our simple naming conventions.
var FluxConstant = require('flux-constant');
var ContactConstants = {
ActionTypes: {
SEND_REQUEST: new FluxConstant('SEND_REQUEST'),
RECEIVE_RESPONSE: new FluxConstant('RECEIVE_RESPONSE')
}
};
module.exports = ContactConstants;
var FluxConstant = require('flux-constant');
var SignupConstants = {
ActionTypes: {
SEND_REQUEST: new FluxConstant('SEND_REQUEST'),
RECEIVE_RESPONSE: new FluxConstant('RECEIVE_RESPONSE')
}
};
module.exports = SignupConstants;
And now they don't collide.
var ContactConstants = require('./ContactConstants');
var SignupConstants = require('./SignupConstants');
ContactActionsTypes = ContactConstants.ActionTypes;
SignupActionsTypes = SignupConstants.ActionTypes;
console.log(ContactActionTypes.SEND_REQUEST === SignupConstants.SEND_REQUEST);
// false
FAQs
Unique constants for Flux apps.
The npm package flux-constant receives a total of 133 weekly downloads. As such, flux-constant popularity was classified as not popular.
We found that flux-constant demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Snyk's use of malicious npm packages for research raises ethical concerns, highlighting risks in public deployment, data exfiltration, and unauthorized testing.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.