
Research
/Security News
Critical Vulnerability in NestJS Devtools: Localhost RCE via Sandbox Escape
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
glossarizer
Advanced tools
A small jquery plugin that automatically marks up glossary terms on a page. The glossary terms can be read from an external json file. When users hover over the link (dashed line), they get to see the glossary definition as a tooltip.
A small jquery plugin that automatically marks up glossary terms on a page. The glossary terms can be read from an external json file. When users hover over the link (dashed line), they get to see the glossary definition as a tooltip.
Tooltips are optional, you can use any third-party tooltips.
If you are writing content that uses specialist vocabulary or many acronyms you need to mark up content with tags so that the definitions can show up as a tooltip. But as authors you really should focus on the writing and not on the marking up content. This is where Glossarizer can help. It automatically marks up the glossary terms on a page by reading off a glossary list.
[
{
"term": "death, !death star",
"description": "Cessation of all biological functions"
},
{
"term": "genetic, !genetic testing, genes, DNA",
"description": "relating to genes or heredity: genetic abnormalities."
},
{
"term" : "creature",
"description" : "A living being, especially an animal"
},
{
"term" : "subdue",
"description" : "To conquer and subjugate; vanquish"
},
{
"term" : "replenish",
"description" : "To fill or make complete again; add a new stock or supply to"
},
{
"term" : "whales",
"description" : "An inlet of the Ross Sea in the Ross Ice Shelf of Antarctica. It has been used as a base for Antarctic expeditions since 1911."
}
]
<script src="//ajax.googleapis.com/ajax/libs/jquery/1/jquery.min.js"></script>
<script src="tooltip/tooltip.js"></script>
<script src="jquery.glossarize.js"></script>
<script>
$(function(){
$('.content').glossarizer({
sourceURL: 'glossary.json',
callback: function(){
// Callback fired after glossarizer finishes its job
new tooltip();
}
});
});
</script>
defaults = {
sourceURL : '',
replaceTag : 'abbr',
lookupTagName : 'p, ul, a',
callback : null,
replaceOnce : true,
replaceClass : glossarizer_replaced,
caseSensitive : false
}
Attribute | Options | Default | Description |
---|---|---|---|
sourceURL | string | `` | JSON file url |
replaceTag | string | abbr | html tag used to replace the matching term |
lookupTagName | string | p, ul, a | Which nodes to search |
replaceOnce | boolean | true | Replace once in a textnode? |
replaceClass | string | glossarizer_replaced | Class name of the replaceTag |
callback | method | null | Completed callback |
caseSensitive | boolean | false | Match case sensitive |
Attribute | Options | Example |
---|---|---|
destroy | method | $('.content').glossarizer('destroy'); |
FAQs
A small jquery plugin that automatically marks up glossary terms on a page. The glossary terms can be read from an external json file. When users hover over the link (dashed line), they get to see the glossary definition as a tooltip.
The npm package glossarizer receives a total of 11 weekly downloads. As such, glossarizer popularity was classified as not popular.
We found that glossarizer demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
Product
Customize license detection with Socket’s new license overlays: gain control, reduce noise, and handle edge cases with precision.
Product
Socket now supports Rust and Cargo, offering package search for all users and experimental SBOM generation for enterprise projects.