
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
A utility that makes reading multipart responses simple
This is free to use software, but if you do like it, consider supporting me ❤️
content-typeVisit /examples for more info!
// Relies on bundler/environment detection
import { meros } from 'meros';
const parts = await fetch('/api').then(meros);
// As a simple Async Generator
for await (const part of parts) {
// Do something with this part
}
// Used with rxjs streams
from(parts).subscribe((part) => {
// Do something with it
});
import { meros } from 'meros/browser';
// import { meros } from 'https://cdn.skypack.dev/meros';
const parts = await fetch('/api').then(meros);
import http from 'http';
import { meros } from 'meros/node';
const response = await new Promise((resolve) => {
const request = http.get(`http://example.com/api`, (response) => {
resolve(response);
});
request.end();
});
const parts = await meros(response);
Meros offers two flavours, both for the browser and for node; but their api's are fundamentally the same.
Note: The type
Responseis used loosely here and simply alludes to Node'sIncomingMessageor the browser'sResponsetype.
meros(response: Response, options?: Options)Returns: Promise<Response | AsyncGenerator<Part | Part[]>>
Meros returns a promise that will resolve to an AsyncGenerator if the response is of multipart/mixed mime, or simply
returns the Response if something else; helpful for middlewares. The idea here being that you run meros as a chain off
fetch.
fetch('/api').then(meros);
If the
content-typeis NOT a multipart, then meros will resolve with the response argument.Example on how to handle this case
import { meros } from 'meros'; const response = await fetch('/api'); // Assume this isnt multipart const parts = await meros(response); if (parts[Symbol.asyncIterator] < 'u') { for await (const part of parts) { // Do something with this part } } else { const data = await parts.json(); }
each Part gives you access to:
json: boolean ~ Tells you the body would be a JavaScript object of your defined generic T.headers: object ~ A key-value pair of all headers discovered from this part.body: T | Fallback ~ Is the body of the part, either as a JavaScript object (noted by json) or the base type
of the environment (Buffer | string, for Node and Browser respectively).options.multiple: booleanDefault: false
Setting this to true will yield once for all available parts of a chunk, rather than yielding once per part. This is
an optimization technique for technologies like GraphQL where rather than commit the payload to the store, to be
added-to in the next process-tick we can simply do that synchronously.
Warning: This will alter the behaviour and yield arrays—than yield payloads.
const chunks = await fetch('/api').then((response) => meros(response, { multiple: true }));
// As a simple Async Generator
for await (const parts of chunks) {
for (const part of parts) {
// Do something with this part, maybe aggregate?
}
}
via the
/benchdirectory with Node v18.0.0
Node
✔ meros ~ 1,271,218 ops/sec ± 0.84%
✘ it-multipart ~ 700,039 ops/sec ± 0.72%
--
it-multipart (FAILED @ "should match reference patch set")
Browser
✔ meros ~ 800,941 ops/sec ± 1.06%
✘ fetch-multipart-graphql ~ 502,175 ops/sec ± 0.75%
--
fetch-multipart-graphql (FAILED @ "should match reference patch set")
Why the name? meros comes from Ancient Greek μέρος méros, meaning "part".
This library aims to implement RFC1341 in its entirety, however we aren't there yet. That being said, you may very well use this library in other scenarios like streaming in file form uploads.
Another goal here is to aide in being the defacto standard transport library to support
@defer and @stream GraphQL directives
/alternative , /digest or /parallel subtype at this time.Special thanks to Luke Edwards for performance guidance and high level api design.
This library is simple, a mere few hundred bytes. It's easy to copy, and easy to alter. If you do, that is fine ❤️ I'm all for the freedom of software. But please give credit where credit is due.
MIT © Marais Rossouw
By default, we'll look for JSON, and parse that for you. If not, we'll give you the body as what was streamed. ↩
GraphQL Helix is a collection of utility functions for building your own GraphQL HTTP server. It supports multipart responses similar to meros but is more focused on the server-side handling of GraphQL requests, including features for query execution and subscription support.
This package is a transport layer for handling GraphQL subscriptions over WebSocket. While it doesn't directly deal with multipart responses, it offers a real-time data fetching capability that can be seen as an alternative approach to handling streaming data, compared to the multipart response handling in meros.
FAQs
A fast 642B utility that makes reading multipart responses simple
We found that meros demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.