
Research
/Security News
Critical Vulnerability in NestJS Devtools: Localhost RCE via Sandbox Escape
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
ssl-forceserver
Advanced tools
SSL ForceServer is a server to be used with CORS that allow to use SSL certificates. It was designed to connect applications that use Salesforce OAuth and REST services. The original force-server was created by Christophe Coenraets and extended after need to connect to SalesForce REST API without use the SalesForce MobileSDK for to get access in special by User-Password Flow.
SSL ForceServer allow to use SSL certificate and send requests in JSON, instead x-www-form-urlencoded, beyond provide two main features:
Proxy server to avoid cross-domain policy issues when invoking Salesforce REST services.
Local web-server to (1) serve the OAuth callback URL defined in your Connected App, and (2) serve the whole app during development and avoid cross-domain policy issues when loading files (for example, templates) from the local file system.
Open a command prompt and type:
npm install -g ssl-forceserver
or (Unix-based systems)
sudo npm install -g ssl-forceserver
Navigate to the directory where you created index.html, and type:
ssl-forceserver
This command will start the server on port 8200, and automatically load your app (http://localhost:8200) in a browser window. You'll see the Salesforce login window, and the list of contacts will appear after you log in.
You can change the port number and the web root. Type the following command for more info:
ssl-forceserver --help
To uninstall the CLI:
npm -g rm ssl-forceserver
or
sudo npm -g rm ssl-forceserver
SSL ForceServer is CORS-enabled. Instead of running it locally as a development server, you can deploy it to Heroku as your Proxy Server. Click the button below to deploy SSL ForceServer to Heroku:
FAQs
Development server for Force.com with SSL
The npm package ssl-forceserver receives a total of 0 weekly downloads. As such, ssl-forceserver popularity was classified as not popular.
We found that ssl-forceserver demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
Product
Customize license detection with Socket’s new license overlays: gain control, reduce noise, and handle edge cases with precision.
Product
Socket now supports Rust and Cargo, offering package search for all users and experimental SBOM generation for enterprise projects.