
Research
/Security News
Weaponizing Discord for Command and Control Across npm, PyPI, and RubyGems.org
Socket researchers uncover how threat actors weaponize Discord across the npm, PyPI, and RubyGems ecosystems to exfiltrate sensitive data.
passport-pinterest
Advanced tools
Passport strategy for authenticating with Pinterest using the OAuth 2.0 API.
This module lets you authenticate using Pinterest in your Node.js applications. By plugging into Passport, Pinterest authentication can be easily and unobtrusively integrated into any application or framework that supports Connect-style middleware, including Express.
This is a module for node.js and is installed via npm:
npm install passport-pinterest --save
The Pinterest authentication strategy authenticates users using a Pinterest account and OAuth 2.0 tokens. The strategy requires a verify
callback, which accepts these credentials and calls done
providing a user, as well as options
specifying a client ID, client secret, scope, and callback URL.
passport.use(new PinterestStrategy({
clientID: PINTEREST_APP_ID,
clientSecret: PINTEREST_APP_SECRET,
scope: ['read_public', 'read_relationships'],
callbackURL: "https://localhost:3000/auth/pinterest/callback",
state: true
},
function(accessToken, refreshToken, profile, done) {
User.findOrCreate({ pinterestId: profile.id }, function (err, user) {
return done(err, user);
});
}
));
Set the scope parameter according to the list of available scopes.
Pinterest only allows https callback urls. This blog article explains the quickest way to enable https for your Express server.
Use passport.authenticate()
, specifying the 'pinterest'
strategy, to authenticate requests.
For example, as route middleware in an Express application:
app.get('/auth/pinterest',
passport.authenticate('pinterest')
);
app.get('/auth/pinterest/callback',
passport.authenticate('pinterest', { failureRedirect: '/login' }),
function(req, res) {
// Successful authentication, redirect home.
res.redirect('/');
}
);
To set up your development environment for Passport-Pinterest:
cd
to the main folder,npm install
,npm install gulp -g
if you haven't installed gulp globally yet, andgulp dev
. (Or run node ./node_modules/.bin/gulp dev
if you don't want to install gulp globally.)gulp dev
watches all source files and if you save some changes it will lint the code and execute all tests. The test coverage report can be viewed from ./coverage/lcov-report/index.html
.
If you want to debug a test you should use gulp test-without-coverage
to run all tests without obscuring the code by the test coverage instrumentation.
state
values, the default state
handling by Passport is not activated by default anymore. Please use new PinterestStrategy({ state: true, ... })
to get the old behavior.
(Thanks to @somprabhsharma for issue #3 and pull request #4)options.state
string
(Thanks to @cvinson for pull request #2)In case you never heard about the ISC license it is functionally equivalent to the MIT license.
See the LICENSE file for details.
FAQs
Pinterest authentication strategy for Passport.
The npm package passport-pinterest receives a total of 244 weekly downloads. As such, passport-pinterest popularity was classified as not popular.
We found that passport-pinterest demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
Socket researchers uncover how threat actors weaponize Discord across the npm, PyPI, and RubyGems ecosystems to exfiltrate sensitive data.
Security News
Socket now integrates with Bun 1.3’s Security Scanner API to block risky packages at install time and enforce your organization’s policies in local dev and CI.
Research
The Socket Threat Research Team is tracking weekly intrusions into the npm registry that follow a repeatable adversarial playbook used by North Korean state-sponsored actors.