
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
A node.js script that can fetch and monitor a filtered App.net App Stream
A client object can be constructed from the main stadn object. For convenience, supply your client_id, client_secret and app_token in a configuration file. An example file is provided. Then when creating your client, pass in the path to this configuration file.
var stadn = require('stadn');
var client = stadn.Client('./config');
Or if you prefer not to use a configuration file, use initialize().
var client = stadn.Client();
client.initialize('CLIENT_ID', 'CLIENT_SECRET', 'APP_TOKEN');
Create a new client and authorize it. You must supply a client ID and secret before calling 'authorize()' or an error will be returned in the callback.
var client = stadn.Client('./config');
client.authorize(function(err) {
if (err)
return console.error(err);
var authorized = client.isAuthorized(); // true
});
You need a filter_id to get a specific subset of your App Stream. Fetch a filter and then a stream, both fetchFilter() and fetchStream() search for a pre-existing filter with the same name/key before creating it. If a filter or stream already exist it is returned.
var clauses = [client.createFilterClause('post', 'one_of', '/data/entities/mentions/*/id')];
var JSONFilter = client.createJSONFilter('mentions', clauses, 'include_any');
client.fetchFilter(JSONFilter, function(err, filter) {
if (err)
return console.error(err);
var JSONStream = client.createJSONStream(['post','star','user_follow'], filter.id, JSONStreamKey);
client.fetchStream(JSONStream, function(err, stream) {
if (err)
return console.error(err);
var streamEndpoint = stream.endpoint; // https://stream-channel.app.net/channel/...
});
});
Once you have a stream and an authorized client, you can monitor for notifications by passing in a function. This function will be called for each response envelope the endpoint feeds out.
var client = // Pre-authorized client object
var stream = // Stream object returned in the callback from fetchStream. Not a JSONStream.
client.monitorStream(stream, function(meta, data) {
// handle response envelope
});
Note: meta and data are json objects corresponding to parts of the stream objects outlined here: https://developers.app.net/reference/resources/app-stream/#sample-stream-objects
FAQs
A node.js script that can fetch and monitor a filtered App.net App Stream
We found that stadn demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.