Security News
vlt Debuts New JavaScript Package Manager and Serverless Registry at NodeConf EU
vlt introduced its new package manager and a serverless registry this week, innovating in a space where npm has stagnated.
The tedious npm package is a pure JavaScript, non-blocking, TDS (Tabular Data Stream) protocol implementation used to interact with Microsoft SQL Server databases. It allows for the execution of SQL queries, parameterized statements, and stored procedures, making it a versatile tool for database operations within Node.js applications.
Executing SQL Queries
This feature allows for the execution of SQL queries against a SQL Server database. The code sample demonstrates how to connect to a database and execute a simple SELECT query.
const Connection = require('tedious').Connection;
const Request = require('tedious').Request;
const config = {
server: 'your_server.database.windows.net',
authentication: {
type: 'default',
options: {
userName: 'your_username',
password: 'your_password',
}
},
options: {
database: 'your_database',
encrypt: true
}
};
const connection = new Connection(config);
connection.on('connect', function(err) {
if (err) {
console.log('Error:', err);
} else {
console.log('Connected!');
executeStatement();
}
});
function executeStatement() {
const request = new Request(
"SELECT * FROM your_table;",
function(err, rowCount, rows) {
console.log(rowCount + ' row(s) returned');
}
);
request.on('row', function(columns) {
columns.forEach(function(column) {
console.log('%s %s', column.metadata.colName, column.value);
});
});
connection.execSql(request);
}
Parameterized Statements
This feature supports the execution of parameterized statements, enhancing security by preventing SQL injection. The code sample shows how to execute a query with a parameter.
const Request = require('tedious').Request;
const TYPES = require('tedious').TYPES;
function executeParameterizedStatement() {
const request = new Request(
"SELECT * FROM your_table WHERE your_column = @value;",
function(err) {
if (err) {
console.log('Error:', err);
}
}
);
request.addParameter('value', TYPES.Int, 123);
request.on('row', function(columns) {
columns.forEach(function(column) {
console.log('%s %s', column.metadata.colName, column.value);
});
});
connection.execSql(request);
}
Executing Stored Procedures
This feature allows for the execution of stored procedures within the database. The code sample demonstrates calling a stored procedure and retrieving an output parameter.
const Request = require('tedious').Request;
function executeStoredProcedure() {
const request = new Request(
'your_stored_procedure',
function(err) {
if (err) {
console.log('Error:', err);
}
}
);
request.addOutputParameter('output_parameter', TYPES.VarChar);
request.on('returnValue', function(parameterName, value, metadata) {
console.log(parameterName + ' : ' + value);
});
connection.callProcedure(request);
}
The mssql package is another popular choice for interacting with SQL Server databases from Node.js. It provides a higher-level abstraction over tedious, offering a simpler API for executing queries, parameterized statements, and transactions. While tedious offers more direct control over the TDS protocol, mssql simplifies many common tasks, making it a more accessible option for some developers.
node-mssql is an alias or a closely related package to mssql, providing similar functionalities. It's often used interchangeably in discussions and documentation, but primarily, 'mssql' is the package name used for installation and implementation in projects.
Sequelize is a promise-based Node.js ORM for Postgres, MySQL, MariaDB, SQLite, and Microsoft SQL Server. It features solid transaction support, relations, eager and lazy loading, read replication, and more. While tedious is focused on SQL Server and provides a low-level API for database operations, Sequelize offers an ORM layer, making it easier to work with different databases using a unified API. However, this abstraction comes at the cost of direct control over SQL execution.
Tedious is an implementation of the TDS protocol, which is used to interact with instances of Microsoft's SQL Server. It is intended to be a fairly slim implementation of the protocol, with not too much additional functionality.
NOTE: Default login behavior has changed slightly as of version 1.2
See the changelog for version history.
npm install tedious
## Documentation
More documentation is available at [pekim.github.io/tedious/](http://pekim.github.io/tedious/)
## Discussion
Google Group - http://groups.google.com/group/node-tedious
## Name
_Tedious_ is simply derived from a fast, slightly garbled, pronunciation of the letters T, D and S.
## Licence
Copyright (c) 2010-2014 Mike D Pilsbury
The MIT License
Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
FAQs
A TDS driver, for connecting to MS SQLServer databases.
We found that tedious demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 8 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt introduced its new package manager and a serverless registry this week, innovating in a space where npm has stagnated.
Security News
Research
The Socket Research Team uncovered a malicious Python package typosquatting the popular 'fabric' SSH library, silently exfiltrating AWS credentials from unsuspecting developers.
Security News
At its inaugural meeting, the JSR Working Group outlined plans for an open governance model and a roadmap to enhance JavaScript package management.