
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
pre-release.
requestor is a wrapper around the popular request client that provides the following out-of-the-box:
The requestor returns a promise on the results, using bluebird. Streaming is not available and all results will be buffered resolve the promise once fully loaded. The only way to get result back is to append a .then(..) function to the requestor object.
requestor can initialized with a unique key and caching object (both optional) to cache cookies across different instances of the requestor. The caching object should supply the following promisified functions .get(key) and .set(key,value). The cache is only read upon initilization and a regular cookie jar is used to maintain the cookies after that. After each request, the contents of the jar are saved into the cache.
Prequest is initiated by the following signature (only key is required):
var requestor = require('requestor')([key],[cache])
A custom function can be injected into the requestor options (as property fn) to validate the response (and possible take action) before the results are used to resolve the promise. This function will be called with the res of request as a first variable and a retry function as a second variable, which can be called if/when the original request should be retried. A typical use-case would be to check if we are 'logged in' to the site before returning the results. If the reply indicates we are not logged in, we can execute the requests necessary to log in and subsequently retry our original request - whose results will to resolve the original promise.
If retry fails, the injector function will be called again. By default, retry will only be called twice in a row before erroring. Custom value for maxRetries can be specified in the parameters passed to requestor.
Example:
// We begin by defining the injected function
function validateLogin(res,retry) {
// If we are not unauthorized, we simply pass on the results
if (res.statusCode !== 401) return res;
// otherwise we try to log-in
return requestor({url: 'http://testsite/login', form: {username:'zjonsson',password:'abc123',method:'POST'})
.then(retry);
}
// Now we can send a request knowing we will be logged in, if we aren't already
requestor({url:'http://testsite/myaccount',fn:validateLogin})
.then(console.log);
FAQs
Promisified request with persistant cookies and retry
The npm package requestor receives a total of 2 weekly downloads. As such, requestor popularity was classified as not popular.
We found that requestor demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.