
Security News
Node.js Drops Bug Bounty Rewards After Funding Dries Up
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.
yapi-plugin-qsso
Advanced tools
第三方sso登录插件,配置方法如下:
第一步: 在生成的配置文件config.json中加入如下配置:
"plugins": [
{
"name": "qsso",
"options": {
"type": "sso",
"loginUrl": "http://sso.example.com/service/verifytoken.php?token=",
"emailPostfix": "@163.com",
"AUTH_SERVER" : "https://sso.example.com/login.php"
}
}
]
这里面的配置项含义如下:
type 登陆类型,目前只支持sso登陆loginUrl 服务端在获取token之后,可以通过这个url来获取用户的详细信息emailPostfix 登陆邮箱后缀AUTH_SERVER 点击登陆按钮式需要跳转的url,用户通过该页面登录以后会向服务器发送一个token第二步:在config.json 这层目录下运行 yapi plugin --name yapi-plugin-qsso 重新下载插件
第三步: 重启服务器
FAQs
第三方sso登录插件,配置方法如下:
The npm package yapi-plugin-qsso receives a total of 54 weekly downloads. As such, yapi-plugin-qsso popularity was classified as not popular.
We found that yapi-plugin-qsso demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.