Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
single-page
Advanced tools
write single-page apps with a single callback to handle pushState events
write single-page apps with a single callback to handle pushState events
Given some html with elements #foo
, #bar
, and #baz
:
<html>
<style>
</style>
<body>
<div id="foo">
foo foO fOo fOO Foo FoO FOo FOO
<div><a href="/bar">bar</a></div>
</div>
<div id="bar">
bar baR bAr bAR Bar BaR BAr BAR
<div><a href="/baz">baz</a></div>
</div>
<div id="baz">
baz baZ bAz bAZ Baz BaZ BAz BAZ
<div><a href="/foo">foo</a></div>
</div>
<script src="bundle.js"></script>
</body>
</html>
Now turn each of the divs into pages with their own routes. Note that this module doesn't update the link callbacks for you. You'll need to handle that for yourself.
var divs = {
foo: document.querySelector('#foo'),
bar: document.querySelector('#bar'),
baz: document.querySelector('#baz')
};
var singlePage = require('single-page');
var showPage = singlePage(function (href) {
Object.keys(divs).forEach(function (key) {
hide(divs[key]);
});
var div = divs[href.replace(/^\//, '')];
if (div) show(div)
else show(divs.foo)
function hide (e) { e.style.display = 'none' }
function show (e) { e.style.display = 'block' }
});
var links = document.querySelectorAll('a[href]');
for (var i = 0; i < links.length; i++) {
links[i].addEventListener('click', function (ev) {
ev.preventDefault();
showPage(this.getAttribute('href'));
});
}
You'll need to have a server that will serve up the same static content for each of the pushState routes. Something like this will work:
var http = require('http');
var ecstatic = require('ecstatic')(__dirname);
var server = http.createServer(function (req, res) {
if (/^\/[^\/.]+$/.test(req.url)) {
req.url = '/';
}
ecstatic(req, res);
});
server.listen(5000);
Now when you go to http://localhost:5000
and click around, you'll see /foo
,
/bar
and /baz
in the address bar when you click links, even though you're
not reloading the page.
var singlePage = require('single-page')
Fire cb(href, page)
at the start and whenever the page navigation changes so
you can update the page contents accordingly.
If opts.saveScroll
is !== false
, page.scrollX
and page.scrollY
are saved
for every unique href
so that you can jump back to the same scroll position
that the user left off at.
Navigate to href
, firing the callback passed to singlePage.
Update the location href in the address bar without firing any callbacks.
With npm
do:
npm install single-page
Use browserify do bundle this module into your application.
MIT
FAQs
write single-page apps with a single callback to handle pushState events
The npm package single-page receives a total of 3 weekly downloads. As such, single-page popularity was classified as not popular.
We found that single-page demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.