Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
hexo-disqus-proxy
Advanced tools
[![npm package](https://img.shields.io/npm/v/hexo-disqus-proxy.svg?style=flat)](https://www.npmjs.org/package/hexo-disqus-proxy) ![](https://img.shields.io/badge/node-%3E7.6-brightgreen.svg)
在Hexo
博客目录执行
npm install hexo-disqus-proxy --save
在你的Hexo
博客目录中修改_config.yml
文件
添加如下配置:(注意缩进和空格)
disqus_proxy:
shortname: ciqu
username: ciqu
host: disqus-proxy.ycwalker.com
port: 443
其中:
shortname
是你的website的 shortname 名称 比如在你的disqus安装代码中 有这样一句脚本:
s.src = 'https://test-eo9kkdlcze.disqus.com/embed.js';
那么你的disqus 的shortname 就是 test-eo9kkdlczeusername
是你的disqus用户名,即评论时候留下的名字,用来区别disqus-proxy的评论头像显示host
是你启用disqus代理的VPS的域名port
是VPS服务器启用disqus代理的端口,需要与之后配置的后端一致在disqus
的官方配置中,我们需要在页面合适位置添加一个 <div id="disqus_thread"></div>
作为占位符,
而hexo-disqus-proxy
插件并不能知道在页面的哪个位置插入这个标签比较合适,所以这个需要额外配置一下:
如果你本身用的主题已经支持disqus
的配置,那么灰常爽,你只需要正常启用主题的disqus评论,插件就会自动检测并合适的覆盖,
这是最常见的情况,肯定是最吼的。
在你写的markdown
文件底部插入<div id="disqus_thread"></div>
。这样评论框位置会位于文章的下方,并且大小能被外部元素所约束,不会乱跑。
什么,markdown
也能插入HTML
标签?
嗯是的。
稍微懂一点点hexo
的基本知识,自己改主题。大概的思路是,在Hexo
渲染的过程中,把<div id="disqus_thread"></div>
加在主题目录下的layout目录中
关于博文页面的模板中的合适的位置就行了。
1.3.0
版本之后将后端分离出来,查看这里进行配置
FAQs
[![npm package](https://img.shields.io/npm/v/hexo-disqus-proxy.svg?style=flat)](https://www.npmjs.org/package/hexo-disqus-proxy) ![](https://img.shields.io/badge/node-%3E7.6-brightgreen.svg)
The npm package hexo-disqus-proxy receives a total of 1 weekly downloads. As such, hexo-disqus-proxy popularity was classified as not popular.
We found that hexo-disqus-proxy demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.