
Security News
Next.js Patches Critical Middleware Vulnerability (CVE-2025-29927)
Next.js has patched a critical vulnerability (CVE-2025-29927) that allowed attackers to bypass middleware-based authorization checks in self-hosted apps.
terrain-keypath
Advanced tools
A tiny class that defines a key path type for e.g. traversing deep objects, along with some related utilities
An opinionated keypath type
A natural task in JS is to query or modify an element of a deeply-nested JSON object. However, if you're doing operations like that frequently and involving dynamic, different elements, it becomes a pain to describe where all those elements are located within the deep object.
terrain-keypath
provides a standard format for specifying elements of, among other
possible use cases, deep JSON objects. A KeyPath
is an array of WayPoint
s, each
of which is a string
or number
. For example, for the document
doc = {
a: {
b: {
c: [
{ d: 'e' },
{ f: 'g' },
]
}
}
}
you would use e.g. const kp = new KeyPath(['a', 'b', 'c', '1', 'f'])
to obtain
a reference to the object whose value is 'g'
.
KeyPath
makes the design decision that every WayPoint
should be a string
unless you are indicating the unique numeric wildcard token -1
. The
semantic intention of the wildcard token is to denote "all children" of an element,
e.g. all entries of an array. For example,
const kp = new KeyPath(['a', 'b', 'c', -1])
is meant to mean "all children of a.b.c".
It's worth emphasizing that any string is a valid JSON field name, including
field names with special characters like .
, *
, etc. Thus, if you get a deep
JSON document "from the wild," there's no guarantee that other existing keypath
libraries (which typically use such special tokens as wildcards or waypoint
delimiters) will work.
Particularly in conjunction with yadeep,
we have tested terrain-keypath
against a broad variety of wild JSON documents
and have successfully deployed enterprise applications using this keypath type.
TypeScript definitions included!
npm install terrain-keypath
FAQs
A tiny class that defines a key path type for e.g. traversing deep objects, along with some related utilities
The npm package terrain-keypath receives a total of 10 weekly downloads. As such, terrain-keypath popularity was classified as not popular.
We found that terrain-keypath demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Next.js has patched a critical vulnerability (CVE-2025-29927) that allowed attackers to bypass middleware-based authorization checks in self-hosted apps.
Security News
A survey of 500 cybersecurity pros reveals high pay isn't enough—lack of growth and flexibility is driving attrition and risking organizational security.
Product
Socket, the leader in open source security, is now available on Google Cloud Marketplace for simplified procurement and enhanced protection against supply chain attacks.