Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
flux-constant
Advanced tools
Unique constants for Flux apps.
$ npm install flux-constant
Create constants individually.
var FluxConstant = require('flux-constant');
var IMPORTANT_THING = new FluxConstant('IMPORTANT_THING');
console.log(IMPORTANT_THING);
// { name: 'IMPORTANT_THING' }
console.log(IMPORTANT_THING.toString());
// IMPORTANT_THING
Create a set of constants.
var FluxConstant = require('flux-constant');
var Set = FluxConstant.set([
'SEND_REQUEST',
'RECEIVE_RESPONSE'
]);
console.log(Set);
/*
{
SEND_REQUEST: { name: 'SEND_REQUEST' },
RECEIVE_RESPONSE: { name: 'RECEIVE_RESPONSE' }
}
*/
console.log(ActionTypes.SEND_REQUEST instanceof FluxConstant);
// true
With a Flux application you may have a set of constants such as:
var ContactConstants = {
ActionTypes: {
SEND_REQUEST: 'SEND_REQUEST',
RECEIVE_RESPONSE: 'RECEIVE_RESPONSE'
}
};
module.exports = ContactConstants;
You may have another set of constants that are really similar, but unreleated.
var SignupConstants = {
ActionTypes: {
SEND_REQUEST: 'SEND_REQUEST',
RECEIVE_RESPONSE: 'RECEIVE_RESPONSE'
}
};
module.exports = SignupConstants;
But we just created action types that could collide. Let's compare a bit:
var ContactConstants = require('./ContactConstants');
var SignupConstants = require('./SignupConstants');
ContactActionTypes = ContactConstants.ActionTypes;
SignupActionTypes = SignupConstants.ActionTypes;
console.log(ContactActionTypes.SEND_REQUEST === SignupActionTypes.SEND_REQUEST);
// true
This could bite us if we use these two sets of constants in the same process. For example if a store was using these action types, it could get confused thinking an action was the one it was listening for, when it really wasn't. This is because we're just comparing simple strings.
One way to fix this is creating longer, more unique names:
var ContactConstants = {
ActionTypes: {
CONTACT_SEND_REQUEST: 'CONTACT_SEND_REQUEST',
CONTACT_RECEIVE_RESPONSE: 'CONTACT_RECEIVE_RESPONSE'
}
};
module.exports = ContactConstants;
This doesn't seem like a great way to move forward though. These names can get out of control as the application grows.
So instead of passing around strings we can create objects that are unique. And best of all we can keep our simple naming conventions.
var FluxConstant = require('flux-constant');
var ContactConstants = {
ActionTypes: {
SEND_REQUEST: new FluxConstant('SEND_REQUEST'),
RECEIVE_RESPONSE: new FluxConstant('RECEIVE_RESPONSE')
}
};
module.exports = ContactConstants;
var FluxConstant = require('flux-constant');
var SignupConstants = {
ActionTypes: {
SEND_REQUEST: new FluxConstant('SEND_REQUEST'),
RECEIVE_RESPONSE: new FluxConstant('RECEIVE_RESPONSE')
}
};
module.exports = SignupConstants;
And now they don't collide.
var ContactConstants = require('./ContactConstants');
var SignupConstants = require('./SignupConstants');
ContactActionTypes = ContactConstants.ActionTypes;
SignupActionTypes = SignupConstants.ActionTypes;
console.log(ContactActionTypes.SEND_REQUEST === SignupActionTypes.SEND_REQUEST);
// false
FAQs
Unique constants for Flux apps.
The npm package flux-constant receives a total of 12 weekly downloads. As such, flux-constant popularity was classified as not popular.
We found that flux-constant demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.