Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Asynchronous Python client for the Syncthing REST API.
Inspired by python-syncthing, some snippets were copied from python-fumis
NOTE: The package is in active development. Not all features of the API are implemented.
pip install aiosyncthing
import asyncio
from aiosyncthing import Syncthing
async def main():
async with Syncthing("API Key") as client:
# interact with the client here
pass
if __name__ == "__main__":
asyncio.run(main())
Syncthing is the entrypoint class, it acts as an async context manager and provides access to endpoint namespaces.
def __init__(
self,
api_key, # your API Key
url="http://127.0.0.1:8384", # A base URL of the server, https://syncthing.example.com:443/something is also possible
timeout=DEFAULT_TIMEOUT, # Timeout in seconds
verify_ssl=True, # Perform SSL verification
loop=None, # event loop
session=None # client session,
)...
In case if the api_key is invalid, aiosyncthing.exceptions.SyncthingError
will be raised on attempt to perform any request except client.system.ping()
, this one only raises aiosyncthing.exceptions.PingError
.
Provides access to the System Endpoints
Returns none if ping is successful or raises syncthing.exceptions.PingError
await client.system.ping()
Returns a dict with the server config or raises syncthing.exceptions.SyncthingError
await client.system.config()
Returns a dict with the server status or raises syncthing.exceptions.SyncthingError
await client.system.status()
Returns a dict with the server version or raises syncthing.exceptions.SyncthingError
await client.system.version()
Pauses synchronization with all devices or with the selected device or raises syncthing.exceptions.SyncthingError
,
in case if passed devices is unknown to the server, syncthing.exceptions.UnknownDeviceError
will be raised. Always returns None
await client.system.pause() # pause all
await client.system.pause(device_id) # eg: 'MTLMICV-YE72URC-NF4LBO3-2LVPTFZ-LLCZHEZ-2F3OEJS-R6CWZVE-7VXHFQA"
Resumes synchronization with all devices or with a selected device or raises syncthing.exceptions.SyncthingError
,
in case if passed devices is unknown to the server, syncthing.exceptions.UnknownDeviceError
will be raised. Always returns None
await client.system.resume() # resume all
await client.system.resume(device_id) # eg: 'MTLMICV-YE72URC-NF4LBO3-2LVPTFZ-LLCZHEZ-2F3OEJS-R6CWZVE-7VXHFQA"
Provides access to the Database Endpoints
Returns a dict with the folder status or raises syncthing.exceptions.SyncthingError
. If the folder id is unknown to
the server, syncthing.exceptions.UnknownFolderError
will be raised.
await client.database.status(folder_id) # eg: 'GXWxf-3zgnU'
Provides access to the Events Endpoints
Is an async generator function that listens to the Event API, yields events one by one and hides the complexity of long polling.
Raises syncthing.exceptions.SyncthingError
in case of error, handles timeouts internally and reconnects to the
endpoint.
async for event in client.events.listen():
print(event)
Returns the id of the last received event of the previous batch.
async for event in client.events.listen():
if events.last_seen_id == 0:
continue # skip first batch because it's historical data
MIT License
Copyright (c) 2020 Gleb Sinyavskiy
Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
FAQs
Asynchronous Python client for the Syncthing REST API
We found that aiosyncthing demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.