
Security News
Axios Supply Chain Attack Reaches OpenAI macOS Signing Pipeline, Forces Certificate Rotation
OpenAI rotated macOS signing certificates after a malicious Axios package reached its CI pipeline in a broader software supply chain attack.
hapi-quickthumb
Advanced tools
QuickThumb is an on the fly, thumbnail creation middleware for express. It utilizes the popular *nix image library, ImageMagick. It allows for the automatic creation of thumbnails by adding query parameters onto a standard image url. It's ideal for web developers who would like to easily experiment with different size thumbnails, wihout having to worry about pre-generating an entire library.
QuickThumb also comes with a command line utility to batch create thumbnails. This is more appropriate for production systems where all images should be pre-generated.
server.pack.register([{
plugin: require('hapi-quickthumb'),
options: {
root: path.join(__dirname, config.publicDir),
path: '/files/{subdir*}'
}
}], function(err) {
server.start();
});
<img src="/public/images/red.gif?dim=200x100" />
npm install hapi-quickthumb
ImageMagick is required for this module, so make sure it is installed.
Ubuntu
apt-get install imagemagick
Mac OS X
brew install imagemagick
Fedora/CentOS
yum install imagemagick
Middleware to replace express.static() or connect.static().
path is the base directory where images are located.
options is an object to specify customizations. It currently has the following options:
type The type of imagemagick conversion to take place. There are currently only two options:
crop (default) Crops and zooms images to the exact size specified. Proxy to imagemagick.crop.resize Resizes an image to fit within the specified dimensions, but actual dimensions may not be exactly as specified. Proxy to imagemagick.resize.cacheDir The directory where generated images will be created. If not supplied, images will be created in [path]/.cache/Resizing of images is directed by the query parameter dim. This is in the format [width]x[height]. E.g. red.gif?dim=200x100
Resized images will be created on an as needed basis, and stored in [cacheDir]/[type]/[dim].
If the dim parameter is not present, the original image will be served.
The first argument is an options object. src, dst, and at least one of width and height are required
src (required) Path to source imagedst (required) Path to destination imagewidth Width of resized imageheight Height of resized imageThe callback argument gets 2 arguments. The first is an error object, most likely from imagemagick's convert. The second argument is the path to the created image.
node bin/make-thumb.js src dst [width]x[height] [-p] [-r] [--resize]
src Path to the source image or directorydst Path to the destination image or directory[width]x[height] Dimensions of the resized images-p Create a subdirectory in dst based off of the dimensions-r Process images recursively from src--resize Use resize instead of cropExample
// Resize a single image and write it to /tmp/red.gif
node bin/make-thumb.js public/images/red.gif /tmp/ 200x200
// Resize all images recursively from public/images/* and write them to /tmp/200x200/*
node bin/make-thumb.js public/images/ /tmp/ 200x200 -p -r
FAQs
On the fly, thumbnail creation plugin for hapi.
We found that hapi-quickthumb demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
OpenAI rotated macOS signing certificates after a malicious Axios package reached its CI pipeline in a broader software supply chain attack.

Security News
Open source is under attack because of how much value it creates. It has been the foundation of every major software innovation for the last three decades. This is not the time to walk away from it.

Security News
Socket CEO Feross Aboukhadijeh breaks down how North Korea hijacked Axios and what it means for the future of software supply chain security.