
Research
/Security News
Critical Vulnerability in NestJS Devtools: Localhost RCE via Sandbox Escape
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
node-json-db
Advanced tools
A simple "database" that use JSON file for Node.JS.
Add node-json-db
to your existing Node.js project.
npm install node-json-db --save
###Data The module store the data using JavaScript Object directly into a JSON file. You can easily traverse the data to reach directly the interesting property using the DataPath. The principle of DataPath is the same as XMLPath.
###Example
{
test: {
data1 : {
array : ['test','array']
},
data2 : 5
}
}
If you want to fet the value of array, the DataPath is /test/data1/array To reach the value of data2 : /test/data2 You can of course get also the full object test : /test Or even the root : /
See test for more usage details.
var JsonDB = require('node-json-db');
//The second argument is used to tell the DB to save after each push
//If you put false, you'll have to call the save() method.
var db = new JsonDB("myDataBase", true);
//Pushing the data into the database
//With the wanted DataPath
//By default the push will override the old value
db.push("/test1","super test");
//It also create automatically the hierarchy when pushing new data for a DataPath that doesn't exists
db.push("/test2/my/test/",5);
//You can also push directly objects
db.push("/test3", {test:"test", json: {test:["test"]}});
//If you don't want to override the data but to merge them
//The merge is recursive and work with Object and Array.
db.push("/test3", {new:"cool", json: {important : 5}}, false);
/*
This give you this results :
{
"test":"test",
"json":{
"test":[
"test"
],
"important":5
},
"new":"cool"
}
*/
//You can't merge primitive.
//If you do this:
db.push("/test2/my/test/",10,false);
//the data will be overriden
//Get the data from the root
var data = db.getData("/");
//From a particular DataPath
var data = db.getData("/test1");
//If you try to get some data from a DataPath that doesn't exists
//You'll get an Error
try {
var data = db.getData("/test1/test/dont/work");
} catch(error) {
//The error will tell you where the DataPath stopped. In this case test1
//Since /test1/test does't exist.
console.error(error);
}
//Deleting data
db.delete("/test1");
//Save the data (useful if you disable the saveOnPush)
db.save();
JsonDB use 2 type of Error/Exception :
Error | Explanation |
---|---|
DataError | When the error is linked to the Data Given |
DatabaseError | Linked to a problem with the loading or saving of the Database. |
####"The Data Path can't be empty" (DataError) The Database expect to minimum receive the root / as DataPath.
####"Can't find dataPath: /" + dataPath.join("/") + ". Stopped at " + property (DataError) When the full hierarchy of the DataPath given is not present in the Database. It tells you until where it's valid. This error can happen when using getData and delete
####"Can't merge another type of data with an Array" (DataError) If you chose to not override the data (merging) when pushing and the new data is an array but the current data isn't an array (an Object by example).
####"Can't merge an Array with an Object" (DataError) Same idea as the previous message. You have an array as current data and ask to merge it with an Object.
####"Can't Load Database: " + err (DatabaseError) JsonDB can't load the database for "err" reason. You can find the nested error in error.inner
####"Can't save the database: " + err (DatabaseError) JsonDB can't save the database for "err" reason. You can find the nested error in error.inner
####"DataBase not loaded. Can't write" (DatabaseError) Since the database hasn't been loaded correctly, the module won't let you save the data to avoid erasing your database.
FAQs
Database using JSON file as storage for Node.JS
The npm package node-json-db receives a total of 18,607 weekly downloads. As such, node-json-db popularity was classified as popular.
We found that node-json-db demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
Product
Customize license detection with Socket’s new license overlays: gain control, reduce noise, and handle edge cases with precision.
Product
Socket now supports Rust and Cargo, offering package search for all users and experimental SBOM generation for enterprise projects.