
Security News
Axios Maintainer Confirms Social Engineering Attack Behind npm Compromise
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.
rxdb-orion
Advanced tools
The Orion replication provides handlers for run replication with Orion REST API as the transportation layer.
npm i rxdb-orion
The package usage is simple, but there are some important rules to follow
sync routeimport { replicateOrion } from 'rxdb-orion';
import { userSchema } from './schemas/user';
import { roleSchema } from './schemas/role';
const database = await createRxDatabase({
name: 'mydb',
storage: getRxStorageDexie(),
});
await database.addCollections({
users: {
schema: userSchema,
},
roles: {
schema: roleSchema,
},
});
const replicationState = replicateOrion({
url: 'http://my.fake.api/users',
params: { include: 'roles' },
collection: users,
batchSize: 3,
});
await replicationState.start();
It is common for an application to require handling multiple replications.
For this reason, the package includes the Manager class to assist in such situations.
As Laravel Orion backend is unable to send events to the client,
the manager executes reSync() every 10000ms by default.
You can customize the interval as you see fit.
import { replicateOrion, Manager } from 'rxdb-orion';
const manager = new Manager([
replicateOrion({
url: 'http://my.fake.api/users',
params: { include: 'roles' },
collection: users,
batchSize: 3,
}),
replicateOrion({
url: 'http://my.fake.api/categories',
collection: categories,
batchSize: 3,
}),
], 5000);
await manager.start();
Important: To ensure correct replication, define your
created_at,updated_at, anddeleted_atfields astimestamp(6)in your database migrations. This allows storage of milliseconds, which is required for accurate checkpointing and synchronization.
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\Schema;
class CreateCategoriesTable extends Migration
{
public function up()
{
Schema::create('categories', function (Blueprint $table) {
$table->uuid('id')->primary();
$table->string('name');
$table->timestamps(6);
$table->softDeletes(precision: 6);
});
}
public function down()
{
Schema::dropIfExists('categories');
}
}
The package uses a Scope to request all documents that have been written after the given checkpoint.
Therefore, it is recommended to create a trait for making the necessary model customizations.
<?php
namespace App\Traits;
trait Syncable {
/**
* Initialize the trait
*
* @return void
*/
protected function initializeSyncable()
{
$this->append('_deleted');
}
/**
* Prepare a date for array / JSON serialization.
*
* @param \DateTimeInterface $date
* @return string
*/
protected function serializeDate(DateTimeInterface $date)
{
$instance = $date instanceof DateTimeImmutable
? CarbonImmutable::instance($date)
: Carbon::instance($date);
return $instance->toDateTimeString('millisecond');
}
/**
* Determine if model is deleted
*
* @return boolean
*/
protected function getDeletedAttribute()
{
return $this->deleted_at !== null;
}
/**
* Scope a query to only include models changed after given value.
*
* @param \Illuminate\Database\Eloquent\Builder $query
* @param int $updatedAt
* @param string $id
* @return \Illuminate\Database\Eloquent\Builder
*/
public function scopeMinUpdatedAt(Builder $query, string $updatedAt, ?string $id = null): Builder
{
return $query->where('updated_at', '>', $updatedAt)
->when($id, fn($query) =>
$query->orWhere(function($query) use ($updatedAt, $id) {
$query->where('updated_at', $updatedAt)->where('id', '>', $id);
})
)
->orderBy('updated_at');
}
}
<?php
namespace App\Models;
use Illuminate\Database\Eloquent\Model;
class User extends Model {
use Syncable;
....
}
FAQs
RxDB replication for Laravel Orion
We found that rxdb-orion demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.