
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
该插件基于 Vue2.X 通过对 axios 、 vant-loading 二次封装,每次HTTP请求自动拉起/隐藏 vant-loading
从性能优化角度考虑,vant-loading 为按需加载,只有当第一次发送请求时加载。同时对 vant-loading 单例化,每次加载、生成、渲染组件都会使用缓存。
安装
npm i axios Vue@2 va-load
注册依赖
import Vue from 'vue'
import axios from 'axios'
import httpReq from 'va-load'
// 注册
httpReq.install(Vue,axios)
接口模块
// src/api/index.js
import Vue from 'vue'
import axios from 'axios'
import httpReq from 'va-load'
// 注册
httpReq.install(Vue,axios)
let BASEURL = "http://localhost:3005/"
const homeInit = (params = {}) => {
return httpReq({
url: `${BASEURL}init.do`,
params
})
}
const pageApi = { homeInit }
// 将页面的所有接口挂载到Vue原型上
export default {
install(Vue) {
Vue.prototype.$API = pageApi
}
}
项目入口
// src/main.js
import api from './api/index.js'
// 安装api模块
Vue.use(api)
使用插件
// src/views/home.vue
export default {
name: 'Home',
mounted() {
this.init()
},
methods:{
init() {
this.$API.homeInit().then(res=>{
...
})
}
}
}
FAQs
它是基于axios插件,对axios进行二次封装,自动拉起/隐藏loading;通过loading组件支持配置
We found that va-load demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.