Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
mysql-validator
Advanced tools
#MySql Validator
Validates web forms input against mysql database.
##Installation
$ npm install mysql-validator
##API
var validator = require('mysql-validator');
var err = validator.check('doh winning!', 'varchar(45)');
if (err) {
console.log(err.message);
}
The first parameter is the posted input data and the second is the mysql data type of the field in your database.
##Obtaining data types
The best way to pass the corresponding data type for your input field is to query the database for it.
describe `table-name`;
All you need to look for is the Type
column. This is the string that the validator expects to see as a second parameter.
This will give you an idea of what object is constructed after the data type string have been parsed. This object is used internally by the validator.
$ mocha test/data-type.js
You can type in your data types manually without querying the database, just make sure you don't mess them up.
##Express 3.x example
Suppose you have a form like this.
<form method="post" action="/save">
<input type="text" name="name" />
<input type="text" name="cache" />
<input type="text" name="date" />
<input type="submit" value="Save" />
</form>
Then your router may look like this.
app.post('/save', function (req, res) {
// we'll store all validation errors here
var errors = [];
// field-type mapping (this may be the result of 'describe table')
var types = {
name: 'varchar(10)',
cache: 'decimal(6,2) unsigned',
date: 'datetime'
}
// loop through the submitted fields and validate them
for (var key in req.body) {
var err = validator.check(req.body[key], types[key]);
// store the error's message and the field name
if (err) errors.push({ name: key, error: err.message });
}
if (errors.length) {
// notify the user about the errors
res.render('template', { err: errors, other: 'params...' });
} else {
// safely store the user's input into the database
}
});
##Tests
Before you can run the tests you must create the test user and give him rights to the test database.
create user 'liolio'@'localhost' identified by 'karamba';
grant all on `mysql-validator`.* to 'liolio'@'localhost';
Then run this test.
$ mocha test/mysql.js
If it pass then you're good to go.
There are a various tests for each data type.
$ mocha test/index.js
The output is pretty verbose. The yellow column show what the test input is. The left column show what mysql store in it's database for this input. The right column show whether the validator think it should be valid or not.
FAQs
MySql data type validation.
The npm package mysql-validator receives a total of 194 weekly downloads. As such, mysql-validator popularity was classified as not popular.
We found that mysql-validator demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.