Git Product home page Git Product logo

authing-js-sdk's Issues

่ฟ”ๅ›žerrors็š„็ป“ๆž„ไฝ“ๅคšๅ˜

Messageๆœ‰็š„ๆ—ถๅ€™ๆ˜ฏstructure๏ผŒๆœ‰็š„ๆ—ถๅ€™ๆ˜ฏstring๏ผŒ่ง„่Œƒๆ ผๅผๆฏ”่พƒ็ปŸไธ€็š„่ฏไผšๆ›ดๅฎนๆ˜“่งฃๆžใ€‚

ไธ‹้ข่ฟ”ๅ›ž็š„ไพ‹ๅญ้‡Œmessageๅฐฑๆ˜ฏstring๏ผŒไฝ†ๆ˜ฏๅคงๅคšๆ•ฐๆƒ…ๅ†ตไธ‹้ƒฝๆ˜ฏstructure

{  
   "data":{  
      "removeUsers":null
   },
   "errors":[  
      {  
         "message":"Cast to ObjectId failed for value \"111\" at path \"_id\" for model \"User\"",
         "name":"CastError",
         "stringValue":"\"111\"",
         "kind":"ObjectId",
         "value":"111",
         "path":"_id"
      }
   ]
}

navigator้—ฎ้ข˜ๅปบ่ฎฎ

่ฟ™ไธชๆไบค ไธญ็š„ๅฆ‚ไธ‹ไปฃ็ ๆ˜ฏๆœ‰้—ฎ้ข˜็š„๏ผš

้”™่ฏฏ็š„ๅ…ผๅฎนๅค„็†

่ฎฟ้—ฎๅ…ผๅฎนAPI

ๅฏ้€‰่ฟ็ฎ—็ฌฆ navigator?.userAgent ๅฏ็”จ็š„ๅ‰ๆๆ˜ฏ navigator ๅ˜้‡ๅทฒ็ป่ขซๅฎšไน‰ไบ†๏ผŒๅฆ‚ๆžœ navigator ๆฒกๅฎšไน‰๏ผŒๆ‰ง่กŒ่ฟ™่กŒไปฃ็ ๆ—ถไป็„ถไผš ReferenceError ้”™่ฏฏ๏ผŒๅ› ไธบๅฏๅ…ˆ่ฟ็ฎ—็ฌฆ็š„ ็ญ‰ๆ•ˆ js ไปฃ็ ๆ˜ฏ navigator === null || navigator === void 0 ? void 0 : navigator.userAgent

ๅฏนไบŽ่ฟ™็งๅ…ผๅฎน nodeใ€Webใ€worker ็Žฏๅขƒ็š„ไปฃ็ ็š„ๆญฃ็กฎๅค„็†ๆ–นๅผๅบ”ๆ˜ฏ๏ผš

  1. ๅฎ‰่ฃ… conf-global ๅŒ…๏ผˆ่ฏฅๅŒ…้žๅธธๅฐ๏ผŒ้›ถไพ่ต–๏ผŒไธไผšๅขžๅŠ ้กน็›ฎ่ดŸๆ‹…๏ผ‰ npm i conf-global
  2. ๅœจๅบ”็”จๅ…ฅๅฃๆ–‡ไปถๆœ€ๅ‰้ขๆทปๅŠ  import "conf-global"
  3. ๅ‡กๆ˜ฏ่ฎฟ้—ฎๅ…จๅฑ€ๆ€งๆœ‰ๅ…ผๅฎน็š„API ้ƒฝๆ”นๆˆ้€š่ฟ‡ globalThis ๅ…จๅฑ€ๅฏน่ฑก่ฎฟ้—ฎ็š„ๆ–นๅผ๏ผŒๅฆ‚๏ผš globalThis. navigator?. userAgent

Issue: Module not found: Error: Can't resolve 'jsbn'

  • Version:

"authing-js-sdk": "4.23.35",

โ””โ”€โ”ฌ [email protected]
โ””โ”€โ”ฌ [email protected]
โ””โ”€โ”€ [email protected]

  • Platform:

MacOS

Severity: Medium

Description:

Module not found: Error: Can't resolve 'jsbn' in '/Users/linonetwo/xxx/TiddlyGit-Desktop/node_modules/authing-js-sdk/build/module/lib/sm-crypto/sm2'

ERROR in ./node_modules/authing-js-sdk/build/module/lib/sm-crypto/sm2/index.js 6:0-34
Module not found: Error: Can't resolve 'jsbn' in '/Users/linonetwo/Desktop/repo/TiddlyGit-Desktop/node_modules/authing-js-sdk/build/module/lib/sm-crypto/sm2'
 @ ./node_modules/authing-js-sdk/build/module/lib/utils.js 39:0-50 48:38-47
 @ ./node_modules/authing-js-sdk/build/module/lib/management/ManagementClient.js 53:0-35 67:21-28
 @ ./node_modules/authing-js-sdk/build/module/index.js 1:0-50 1:0-50
 @ ./src/components/TokenForm/gitTokenHooks.ts 3:0-54 6:38-58

ๅœจไปŠๅคฉๅ‡็บงไพ่ต–ๆ—ถ้‡ๅˆฐ่ฟ™ไธช้—ฎ้ข˜ใ€‚ๅฏ่ƒฝๆ˜ฏๅ› ไธบไฝ ไปฌไพ่ต– jsbn ็š„ๅบ“ๅ‡็บงไบ†ใ€‚

Steps to reproduce the error:

ๆˆชๅฑ2022-09-25 02 50 39

ๅคšๆฌกๅˆ ้™คๅŒไธ€ไธช็”จๆˆทๆˆ–่€…ๅˆ ้™คไธ€ไธชไธๅญ˜ๅœจ็š„็”จๆˆท

Log

2018/05/01 17:52:24 >>>>>>>>>request body
2018/05/01 17:52:24 {"query":"mutation($ids:[String!]!$operator:String!$registerInClient:String!){removeUsers(ids: $ids, registerInClient: $registerInClient, operator: $operator){_id,email,unionid}}","variables":{"ids":["5ae3d830f0db4b000117a95f"],"operator":"","registerInClient":"5adb75e03055230001023b26"}}

2018/05/01 17:52:24 >>>>>>>>>response body
2018/05/01 17:52:24 {"data":{"removeUsers":[]}}

ๆ€ปๆ˜ฏ่ฟ”ๅ›žๆˆๅŠŸ๏ผŒๆฒกๆœ‰errors๏ผŸ

Identities ๆœช่ฟ”ๅ›ž

https://github.com/Authing/authing.js/blob/354968962ad217289c39b6a699adaee090254937/src/types/graphql.v2.ts#L545

่ฟ™ไธช่ฆๆ”นๅ“ช้‡Œ๏ผŒๆ”น https://github.com/Authing/authing.js/blob/master/src/lib/authentication/AuthenticationClient.ts ๅ—


็œ‹ๆ ทๅญๅบ”่ฏฅๆ˜ฏ่ฆๅŠ ๅœจ https://github.com/Authing/authing.js/blob/354968962ad217289c39b6a699adaee090254937/src/lib/authentication/SocialAuthenticationClient.ts#L32 ้‡Œ๏ผŒ่ฟ™้‡Œ็š„ https://github.com/Authing/authing.js/blob/354968962ad217289c39b6a699adaee090254937/src/lib/authentication/SocialAuthenticationClient.ts#L144 ้‡Œๆฒกๆœ‰ identities ๏ผŒ้œ€่ฆๅ† await ไธ€ๆฌก graphql ่ฏทๆฑ‚ๆฅ่Žทๅ– identities

ๆ‰ง่กŒ้”™่ฏฏ

ๆˆ‘ๅœจๅฐ†Web SDK้›†ๆˆๅˆฐๆˆ‘็š„ๅบ”็”จ็จ‹ๅบไธญ๏ผŒ้‡ๅˆฐไบ†ไธ€ไธช้—ฎ้ข˜ใ€‚ ๆˆ‘่ƒฝๆญฃ็กฎๆณจๅ†Œใ€็™ปๅฝ•ใ€ๆณจ้”€๏ผŒไฝ†ๆˆ‘ๅœจ้ชŒ่ฏ็”จๆˆท้‚ฎ็ฎฑ็š„ๆ—ถๅ€™ไธ€็›ด้‡ๅˆฐ้—ฎ้ข˜ใ€‚ ๆˆ‘ๅœจAuthingๆŽงๅˆถๅฐๅทฒ็ป่ฎพ็ฝฎๅฅฝไธบ็”ตๅญ้‚ฎไปถ็š„ๆจกๆฟใ€‚
ๅฝ“ๆˆ‘ๆ”ถๅˆฐๆฅ่‡ชAuthing็š„็”ตๅญ้‚ฎไปถๆ—ถ๏ผŒๆฏๆฌก็‚นๅ‡ปๆ‰€ๆไพ›็š„้“พๆŽฅๅŽ้ชŒ่ฏ้ƒฝๅคฑ่ดฅ๏ผŒ็„ถๅŽ้ƒฝไผšๆ”ถๅˆฐไปฅไธ‹็š„ไฟกๆฏ๏ผš

้ชŒ่ฏๅคฑ่ดฅ๏ผŒ่Žทๅ–้‚ฎไปถๆจกๆฟๅคฑ่ดฅ, ้กต้ขๅฐ†ๅœจ5็ง’ๅŽๅ…ณ้—ญโ€ฆ

'connect-src' was not explicitly set , so Refused to connect to 'https://tiddlygit-desktop.authing.cn

  • I'm submitting a ...
    [x] bug report
    [ ] feature request
    [ ] question about the decisions made in the repository
    [ ] question about how to use this project

  • Summary

 Refused to connect to 'https://tiddlygit-desktop.authing.cn/oidc/.well-known/jwks.json' because it violates the following Content Security Policy directive: "default-src 'self' 'unsafe-inline' data:". Note that 'connect-src' was not explicitly set, so 'default-src' is used as a fallback.

dispatchXhrRequest @ xhr.js?9eca:178
KeyManager.js?450b:141 ๆœๅŠกๅ™จ JWKS ็ซฏ็‚น่ฏทๆฑ‚ๅคฑ่ดฅ
eval @ KeyManager.js?450b:141
KeyManager.js?450b:142 Error: Network Error
    at createError (webpack-internal:///./node_modules/authing-js-sdk/node_modules/axios/lib/core/createError.js:16)
    at XMLHttpRequest.handleError (webpack-internal:///./node_modules/authing-js-sdk/node_modules/axios/lib/adapters/xhr.js:83)

My code:

/* eslint-disable @typescript-eslint/strict-boolean-expressions */
import { useCallback, useMemo } from 'react';
import { AuthenticationClient } from 'authing-js-sdk';
import { SupportedStorageServices } from '@services/types';
import { APP_ID, APP_DOMAIN } from '@/constants/auth';

export function useAuth(storageService: SupportedStorageServices): [() => Promise<void>, () => Promise<void>] {
  const authing = useMemo(
    () =>
      new AuthenticationClient({
        appId: APP_ID,
        appHost: APP_DOMAIN,
      }),
    [],
  );

  const onFailure = useCallback((error: Error) => {
    console.error(error);
  }, []);
  const onClickLogout = useCallback(async () => {
    await authing.logout();
    await window.service.window.clearStorageData();
  }, [authing]);

  const onClickLogin = useCallback(async () => {
    // clear token first, otherwise github login window won't give us a chance to see the form
    // void this.auth.logout();
    // window.remote.clearStorageData();
    try {
      await authing.social.authorize(storageService, {
        onSuccess: async (user) => {
          const thirdPartyIdentity = user.identities?.find((identity) => identity?.provider === storageService);
          if (thirdPartyIdentity) {
            if (thirdPartyIdentity.accessToken) {
              await window.service.auth.set(`${storageService}-token`, thirdPartyIdentity.accessToken);
            }
            if (user.username) {
              await window.service.auth.set(`${storageService}-userName`, user.username);
            }
            if (user.email) {
              await window.service.auth.set(`${storageService}-email`, user.email);
            }
          }
        },
        onError: (code, message) => onFailure(new Error(message + String(code))),
      });
    } catch (error) {
      onFailure(error);
    }
  }, [authing.social, onFailure, storageService]);

  return [onClickLogin, onClickLogout];
}
  • Other information (e.g. detailed explanation, stacktraces, related issues, suggestions how to fix, links for us to have context, eg. StackOverflow, personal fork, etc.)

High vulnerabilities need to be resolved into dependant packages

  • Version: 4.23.29

  • Platform: Authing JS-SDK (Node)

Severity: high

Description:

                   === npm audit security report ===                        

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ Manual Review โ”‚
โ”‚ Some vulnerabilities require your attention to resolve โ”‚
โ”‚ โ”‚
โ”‚ Visit https://go.npm.me/audit-guide for additional guidance โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ High โ”‚ Incorrect Comparison in axios โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ Package โ”‚ axios โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ Patched in โ”‚ >=0.21.2 โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ Dependency of โ”‚ authing-js-sdk โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ Path โ”‚ authing-js-sdk > axios โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ More info โ”‚ GHSA-cph5-m8f7-6c5x โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ High โ”‚ Server-Side Request Forgery in Axios โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ Package โ”‚ axios โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ Patched in โ”‚ >=0.21.1 โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ Dependency of โ”‚ authing-js-sdk โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ Path โ”‚ authing-js-sdk > axios โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ More info โ”‚ GHSA-4w2v-q235-vp99 โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ Moderate โ”‚ Exposure of Sensitive Information to an Unauthorized Actor โ”‚
โ”‚ โ”‚ in follow-redirects โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ Package โ”‚ follow-redirects โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ Patched in โ”‚ >=1.14.8 โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ Dependency of โ”‚ authing-js-sdk โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ Path โ”‚ authing-js-sdk > axios > follow-redirects โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ More info โ”‚ GHSA-pw2r-vq6v-hr8c โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ High โ”‚ Exposure of sensitive information in follow-redirects โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ Package โ”‚ follow-redirects โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ Patched in โ”‚ >=1.14.7 โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ Dependency of โ”‚ authing-js-sdk โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ Path โ”‚ authing-js-sdk > axios > follow-redirects โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ More info โ”‚ GHSA-74fj-2j2h-c42q โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

Steps to reproduce the error:

npm install authing-js-sdk
do -> npm audit
-->

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.