Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
koa2-connect
Advanced tools
Base on koa-connect, improve to support webpack-dev-middleware and webpack-hot-middleware. Use Express/Connect middleware with Koa.
It is highly recommended to use a Koa-specific middleware instead of trying to convert an Express version when they're available. There is a non-trivial difference in the Koa and Express designs and you will inevitably run into some issues. This module is a workaround for the specific cases where the differences can be ignored. Additionally, it also enables library authors to write 1 version of their HTTP middleware.
next
Express middlewares need to declare and invoke the next
callback appropriately for the koa-connect integration to work correctly.
If you're attempting to write a framework-agnostic middleware library, be sure to use only core HTTP methods and not any Express-dependent APIs like res.send
.
npm install koa2-connect
See examples/
for more real-world examples.
const Koa = require('koa')
const c2k = require('koa2-connect')
// A generic Express-style middleware function
function connectMiddlware (req, res, next) {
res.writeHead(200, {'Content-Type': 'text/plain'})
res.end('From the Connect middleware')
next()
}
// A generic Koa v2 middlware, without async/await
function koaMiddlware(ctx, next) {
return next()
.then(() => {
// The control flow will bubble back to here, like usual
})
.catch((err) => {
// Error handling from downstream middleware, like usual
})
}
// A generic Koa v2 middlware with async/await
async function koaMiddleware(ctx, next) {
try {
await next();
} catch (e) {
// Normal error handling
}
// Normal control flow
}
const app = new Koa()
app.use(koaMiddlware)
app.use(c2k(connectMiddlware))
app.use((ctx, next) => {
console.log('It will continue on to here')
})
app.listen(3000)
Tests are in tests.js
and are made with the Mocha framework. You can run them with npm test
or npm run test:watch
MIT
FAQs
Use Connect/Express middleware in Koa2
We found that koa2-connect demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.