Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
JavaScript url handling for Django that doesn’t hurt.
Original idea from django-js-reverse.
Django Reverse JS is a small django app that makes url handling of named urls in JavaScript easy and confortable for django's users.
For example you can retrieve a named url:
path('/betterliving/<str:category_slug>/<int:entry_pk>/', 'get_house', name='betterliving_get_house')
in JavaScript it can be resolved like:
Urls.betterlivingGetHouse('house', 12)
// '/betterliving/house/12/'
Install using pip
pip install django-reverse-js
… or clone the project from github.
git clone https://github.com/sevdog/django-reverse-js.git
Add 'django_reverse_js'
to your INSTALLED_APPS
setting.
INSTALLED_APPS = (
...
'django_js_reverse',
)
First generate static file with createstatic_reversejs
command
django-admin createstatic_reversejs
NOTE: If you change some urls or add an app and want to update the reverse.js file by running again the command.
After this add the file to your template
<script src="{% static 'django_reverse_js/js/reverse.js' %}"></script>
Include view in your URLCONF (you may also cache this is needed):
urlpatterns = [
...,
path('reverse.js', 'django_reverse_js.views.urls_js', name='reverse_js'),
]
Then include JavaScript in your template
<script src="{% url 'reverse_js' %}" type="text/javascript"></script>
You can place the reverse_js
JavaScript inline into your templates,
however use of inline JavaScript is not recommended, because it
may cause problems with Content Security Policy.
See django-csp for further readings.
{% load reversejs %}
<script type="text/javascript" charset="utf-8">
{% reverse_js %}
</script>
If your url names are valid JavaScript identifiers you can access them by the dot notation:
Urls.betterlivingGetHouse('house', 12)
If the named url contains invalid identifiers use the square-bracket notation instead:
NOTE: ATM namespaced urls must be accessd in this way
Urls['betterliving-get-house']('house', 12)
Urls['namespace:betterliving-get-house']('house', 12)
You can also pass javascript objects to match keyword aguments like the examples bellow:
Urls['betterliving-get-house']({ category_slug: 'house', entry_pk: 12 })
Urls['namespace:betterliving-get-house']({ category_slug: 'house', entry_pk: 12 })
REVERSEJS_VAR_NAME
: name given to JavaScript variable used to access django urls; default Urls
.
REVERSEJS_GLOBAL_OBJECT_NAME
: global JavaScript object to which bound resolver variable; default window
.
REVERSEJS_EXCLUDE_NAMESPACES
: list of url namespaces to be excluded from JavaScript resolver; default []
(aka: all namespaces allowed).
REVERSEJS_INCLUDE_ONLY_NAMESPACES
: list of url namespaces to be included in JavaScript resolver; default []
(aka: all namespaces allowed).
''
(empty string) to allow only url without a namespace'foo\0'
(namespace name terminated with null-char) to include only urls from 'foo'
namespace and prevent any inner namespace to be extracted (ie: 'foo:bar'
)REVERSEJS_SCRIPT_PREFIX
: path of application (when served behing a reverse-proxy), needed to return full-urls; default None
.
REVERSEJS_OUTPUT_PATH
: path where to place file created by createstatic_reversejs
command, if not provided STATIC_ROOT
is used; defatul None
.
REVERSEJS_MINIFY
: flag which indicates if the minified version of JS script should be used; default False
.
NOTE: at the moment only one between
REVERSEJS_INCLUDE_ONLY_NAMESPACES
andREVERSEJS_EXCLUDE_NAMESPACES
may be used.
FAQs
Django URL handling in JavaScript
We found that django-reverse-js demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.