Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
djangorestframework-reactive
Advanced tools
|build| |docs| |pypi_version| |pypi_pyversions| |pypi_downloads| |code_style|
.. |build| image:: https://travis-ci.org/genialis/django-rest-framework-reactive.svg?branch=master :target: https://travis-ci.org/genialis/django-rest-framework-reactive :alt: Build Status
.. |docs| image:: https://readthedocs.org/projects/djangorestframework-reactive/badge/?version=latest :target: http://djangorestframework-reactive.readthedocs.io/ :alt: Documentation Status
.. |pypi_version| image:: https://img.shields.io/pypi/v/djangorestframework-reactive.svg :target: https://pypi.org/project/djangorestframework-reactive :alt: Version on PyPI
.. |pypi_pyversions| image:: https://img.shields.io/pypi/pyversions/djangorestframework-reactive.svg :target: https://pypi.org/project/djangorestframework-reactive :alt: Supported Python versions
.. |pypi_downloads| image:: https://pepy.tech/badge/djangorestframework-reactive :target: https://pepy.tech/project/djangorestframework-reactive :alt: Number of downloads from PyPI
.. |code_style| image:: https://img.shields.io/badge/code%20style-black-black.svg :target: https://black.readthedocs.io/ :alt: Code style: black
This package enables regular Django REST Framework views to become reactive, that is so that client-side applications may get notified of changes to the underlying data as soon as they happen, without the need to poll the API again. While the initial request is done as a regular HTTP request, all the update notifications come through WebSockets.
The reactive extensions for Django REST Framework require the use of Django Channels
_
for push notifications via WebSockets.
.. _Django Channels
: https://channels.readthedocs.io
.. code::
pip install djangorestframework-reactive
.. code::
pip install https://github.com/genialis/django-rest-framework-reactive/archive/.tar.gz
where <git-tree-ish>
can represent any commit SHA, branch name, tag name,
etc. in DRF Reactive's GitHub repository
_. For example, to install the latest
version from the master
branch, use:
.. code::
pip install https://github.com/genialis/django-rest-framework-reactive/archive/master.tar.gz
.. _DRF Reactive's GitHub repository
: https://github.com/genialis/django-rest-framework-reactive/
First, add rest_framework_reactive
to INSTALLED_APPS
.
Configure your Django Channels routing.py
to include the required paths:
.. code::
from django.urls import path
from channels.routing import ChannelNameRouter, ProtocolTypeRouter, URLRouter
from rest_framework_reactive.consumers import ClientConsumer, MainConsumer, WorkerConsumer
from rest_framework_reactive.protocol import CHANNEL_MAIN, CHANNEL_WORKER
application = ProtocolTypeRouter({
# Client-facing consumers.
'websocket': URLRouter([
# To change the prefix, you can import ClientConsumer in your custom
# Channels routing definitions instead of using these defaults.
path('ws/<slug:subscriber_id>', ClientConsumer),
]),
# Background worker consumers.
'channel': ChannelNameRouter({
CHANNEL_MAIN: MainConsumer,
CHANNEL_WORKER: WorkerConsumer,
})
})
Also, urls.py
need to be updated to include some additional paths:
.. code::
urlpatterns = [ # ... url(r'^api/queryobserver/', include('rest_framework_reactive.api_urls')), # ... ]
In addition to running a Django application server instance, you need to also run a separate observer worker process (or multiple of them). You may start it by running:
.. code::
python manage.py runworker rest_framework_reactive.main rest_framework_reactive.worker
FAQs
Making Django REST Framework reactive
We found that djangorestframework-reactive demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.