From 2b70ceee639b9ebbde5c31b42d10f5a13af83a05 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 16 Feb 2022 21:58:23 +0100 Subject: [PATCH 1/7] chore: bump ajv from 6.12.2 to 6.12.6 (#126) Bumps [ajv](https://github.com/ajv-validator/ajv) from 6.12.2 to 6.12.6. - [Release notes](https://github.com/ajv-validator/ajv/releases) - [Commits](https://github.com/ajv-validator/ajv/compare/v6.12.2...v6.12.6) --- updated-dependencies: - dependency-name: ajv dependency-type: indirect ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- package-lock.json | 18 +++++++++++------- 1 file changed, 11 insertions(+), 7 deletions(-) diff --git a/package-lock.json b/package-lock.json index 301625a..c1e6455 100644 --- a/package-lock.json +++ b/package-lock.json @@ -6,7 +6,7 @@ "packages": { "": { "name": "engine.io-parser", - "version": "5.0.2", + "version": "5.0.3", "license": "MIT", "dependencies": { "@socket.io/base64-arraybuffer": "~1.0.2" @@ -1543,15 +1543,19 @@ } }, "node_modules/ajv": { - "version": "6.12.2", - "resolved": "https://registry.npmjs.org/ajv/-/ajv-6.12.2.tgz", - "integrity": "sha512-k+V+hzjm5q/Mr8ef/1Y9goCmlsK4I6Sm74teeyGvFk1XrOsbsKLjEdrvny42CZ+a8sXbk8KWpY/bDwS+FLL2UQ==", + "version": "6.12.6", + "resolved": "https://registry.npmjs.org/ajv/-/ajv-6.12.6.tgz", + "integrity": "sha512-j3fVLgvTo527anyYyJOGTYJbG+vnnQYvE0m5mmkc1TK+nxAppkCLMIL0aZ4dblVCNoGShhm+kzE4ZUykBoMg4g==", "dev": true, "dependencies": { "fast-deep-equal": "^3.1.1", "fast-json-stable-stringify": "^2.0.0", "json-schema-traverse": "^0.4.1", "uri-js": "^4.2.2" + }, + "funding": { + "type": "github", + "url": "https://github.com/sponsors/epoberezkin" } }, "node_modules/amdefine": { @@ -12755,9 +12759,9 @@ } }, "ajv": { - "version": "6.12.2", - "resolved": "https://registry.npmjs.org/ajv/-/ajv-6.12.2.tgz", - "integrity": "sha512-k+V+hzjm5q/Mr8ef/1Y9goCmlsK4I6Sm74teeyGvFk1XrOsbsKLjEdrvny42CZ+a8sXbk8KWpY/bDwS+FLL2UQ==", + "version": "6.12.6", + "resolved": "https://registry.npmjs.org/ajv/-/ajv-6.12.6.tgz", + "integrity": "sha512-j3fVLgvTo527anyYyJOGTYJbG+vnnQYvE0m5mmkc1TK+nxAppkCLMIL0aZ4dblVCNoGShhm+kzE4ZUykBoMg4g==", "dev": true, "requires": { "fast-deep-equal": "^3.1.1", From 4952193c0444f554489650725ae90ca4586298c5 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 17 Feb 2022 07:48:15 +0100 Subject: [PATCH 2/7] chore: bump cached-path-relative from 1.0.2 to 1.1.0 (#125) Bumps [cached-path-relative](https://github.com/ashaffer/cached-path-relative) from 1.0.2 to 1.1.0. - [Release notes](https://github.com/ashaffer/cached-path-relative/releases) - [Commits](https://github.com/ashaffer/cached-path-relative/commits) --- updated-dependencies: - dependency-name: cached-path-relative dependency-type: indirect ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- package-lock.json | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/package-lock.json b/package-lock.json index c1e6455..b977e41 100644 --- a/package-lock.json +++ b/package-lock.json @@ -2631,9 +2631,9 @@ } }, "node_modules/cached-path-relative": { - "version": "1.0.2", - "resolved": "https://registry.npmjs.org/cached-path-relative/-/cached-path-relative-1.0.2.tgz", - "integrity": "sha512-5r2GqsoEb4qMTTN9J+WzXfjov+hjxT+j3u5K+kIVNIwAd99DLCJE9pBIMP1qVeybV6JiijL385Oz0DcYxfbOIg==", + "version": "1.1.0", + "resolved": "https://registry.npmjs.org/cached-path-relative/-/cached-path-relative-1.1.0.tgz", + "integrity": "sha512-WF0LihfemtesFcJgO7xfOoOcnWzY/QHR4qeDqV44jPU3HTI54+LnfXK3SA27AVVGCdZFgjjFFaqUA9Jx7dMJZA==", "dev": true }, "node_modules/caching-transform": { @@ -13695,9 +13695,9 @@ } }, "cached-path-relative": { - "version": "1.0.2", - "resolved": "https://registry.npmjs.org/cached-path-relative/-/cached-path-relative-1.0.2.tgz", - "integrity": "sha512-5r2GqsoEb4qMTTN9J+WzXfjov+hjxT+j3u5K+kIVNIwAd99DLCJE9pBIMP1qVeybV6JiijL385Oz0DcYxfbOIg==", + "version": "1.1.0", + "resolved": "https://registry.npmjs.org/cached-path-relative/-/cached-path-relative-1.1.0.tgz", + "integrity": "sha512-WF0LihfemtesFcJgO7xfOoOcnWzY/QHR4qeDqV44jPU3HTI54+LnfXK3SA27AVVGCdZFgjjFFaqUA9Jx7dMJZA==", "dev": true }, "caching-transform": { From 039b45cc65b50acc1f9da42ad605eaccb8ccbcde Mon Sep 17 00:00:00 2001 From: Damien Arrachequesne Date: Sat, 30 Apr 2022 12:36:57 +0200 Subject: [PATCH 3/7] fix(typings): update the type of RawData We could also split the declaration of RawData with the "browser" field: ``` // for Node.js export type RawData = string | Buffer | ArrayBuffer | ArrayBufferView; // no Blob // for the browser export type RawData = string | ArrayBuffer | ArrayBufferView | Blob; // no Buffer ``` But it does not seem supported by the TypeScript compiler, so we'll revert to just using "any" for now. Related: https://github.com/socketio/engine.io-parser/issues/128 --- lib/commons.ts | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/lib/commons.ts b/lib/commons.ts index aaf5fba..9156e36 100644 --- a/lib/commons.ts +++ b/lib/commons.ts @@ -26,7 +26,9 @@ export type PacketType = | "noop" | "error"; -export type RawData = string | Buffer | ArrayBuffer | ArrayBufferView | Blob; +// RawData should be "string | Buffer | ArrayBuffer | ArrayBufferView | Blob", but Blob does not exist in Node.js and +// requires to add the dom lib in tsconfig.json +export type RawData = any; export interface Packet { type: PacketType; From a421bbec7bf43c567c49c608dee604872f6db823 Mon Sep 17 00:00:00 2001 From: Damien Arrachequesne Date: Sat, 30 Apr 2022 12:42:03 +0200 Subject: [PATCH 4/7] fix: add missing file extension for ESM import Related: https://github.com/socketio/engine.io-parser/issues/127 --- lib/index.ts | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/index.ts b/lib/index.ts index 9280541..4acacde 100644 --- a/lib/index.ts +++ b/lib/index.ts @@ -1,6 +1,6 @@ import encodePacket from "./encodePacket.js"; import decodePacket from "./decodePacket.js"; -import { Packet, PacketType, RawData, BinaryType } from "./commons"; +import { Packet, PacketType, RawData, BinaryType } from "./commons.js"; const SEPARATOR = String.fromCharCode(30); // see https://en.wikipedia.org/wiki/Delimiter#ASCII_delimited_text From da182cba3ed98681cc892d52a444f473a2d8bd10 Mon Sep 17 00:00:00 2001 From: Damien Arrachequesne Date: Sat, 30 Apr 2022 13:54:19 +0200 Subject: [PATCH 5/7] chore: point the CI badge towards the main branch --- Readme.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Readme.md b/Readme.md index 9c57c5e..b109650 100644 --- a/Readme.md +++ b/Readme.md @@ -1,7 +1,7 @@ # engine.io-parser -[![Build Status](https://github.com/socketio/engine.io-parser/workflows/CI/badge.svg)](https://github.com/socketio/engine.io-parser/actions) +[![Build Status](https://github.com/socketio/engine.io-parser/workflows/CI/badge.svg?branch=main)](https://github.com/socketio/engine.io-parser/actions) [![NPM version](https://badge.fury.io/js/engine.io-parser.svg)](https://npmjs.com/package/engine.io-parser) This is the JavaScript parser for the engine.io protocol encoding, From bc7400a5e8076a34296e36953348c7ac18359721 Mon Sep 17 00:00:00 2001 From: Damien Arrachequesne Date: Sat, 30 Apr 2022 13:59:34 +0200 Subject: [PATCH 6/7] refactor: include base64-arraybuffer in the repository In order to reduce the number of dependencies and the attack surface in case of supply chain attacks. --- .prettierignore | 1 + lib/contrib/base64-arraybuffer.ts | 64 +++++++++++++++++++++++++++++++ lib/decodePacket.browser.ts | 2 +- package-lock.json | 16 -------- package.json | 3 -- 5 files changed, 66 insertions(+), 20 deletions(-) create mode 100644 .prettierignore create mode 100644 lib/contrib/base64-arraybuffer.ts diff --git a/.prettierignore b/.prettierignore new file mode 100644 index 0000000..e6108ed --- /dev/null +++ b/.prettierignore @@ -0,0 +1 @@ +lib/contrib/* diff --git a/lib/contrib/base64-arraybuffer.ts b/lib/contrib/base64-arraybuffer.ts new file mode 100644 index 0000000..5c5c6c1 --- /dev/null +++ b/lib/contrib/base64-arraybuffer.ts @@ -0,0 +1,64 @@ +// imported from https://github.com/socketio/base64-arraybuffer +const chars = 'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/'; + +// Use a lookup table to find the index. +const lookup = typeof Uint8Array === 'undefined' ? [] : new Uint8Array(256); +for (let i = 0; i < chars.length; i++) { + lookup[chars.charCodeAt(i)] = i; +} + +export const encode = (arraybuffer: ArrayBuffer): string => { + let bytes = new Uint8Array(arraybuffer), + i, + len = bytes.length, + base64 = ''; + + for (i = 0; i < len; i += 3) { + base64 += chars[bytes[i] >> 2]; + base64 += chars[((bytes[i] & 3) << 4) | (bytes[i + 1] >> 4)]; + base64 += chars[((bytes[i + 1] & 15) << 2) | (bytes[i + 2] >> 6)]; + base64 += chars[bytes[i + 2] & 63]; + } + + if (len % 3 === 2) { + base64 = base64.substring(0, base64.length - 1) + '='; + } else if (len % 3 === 1) { + base64 = base64.substring(0, base64.length - 2) + '=='; + } + + return base64; +}; + +export const decode = (base64: string): ArrayBuffer => { + let bufferLength = base64.length * 0.75, + len = base64.length, + i, + p = 0, + encoded1, + encoded2, + encoded3, + encoded4; + + if (base64[base64.length - 1] === '=') { + bufferLength--; + if (base64[base64.length - 2] === '=') { + bufferLength--; + } + } + + const arraybuffer = new ArrayBuffer(bufferLength), + bytes = new Uint8Array(arraybuffer); + + for (i = 0; i < len; i += 4) { + encoded1 = lookup[base64.charCodeAt(i)]; + encoded2 = lookup[base64.charCodeAt(i + 1)]; + encoded3 = lookup[base64.charCodeAt(i + 2)]; + encoded4 = lookup[base64.charCodeAt(i + 3)]; + + bytes[p++] = (encoded1 << 2) | (encoded2 >> 4); + bytes[p++] = ((encoded2 & 15) << 4) | (encoded3 >> 2); + bytes[p++] = ((encoded3 & 3) << 6) | (encoded4 & 63); + } + + return arraybuffer; +}; diff --git a/lib/decodePacket.browser.ts b/lib/decodePacket.browser.ts index 71e3480..704c147 100644 --- a/lib/decodePacket.browser.ts +++ b/lib/decodePacket.browser.ts @@ -5,7 +5,7 @@ import { BinaryType, RawData } from "./commons.js"; -import { decode } from "@socket.io/base64-arraybuffer"; +import { decode } from "./contrib/base64-arraybuffer.js"; const withNativeArrayBuffer = typeof ArrayBuffer === "function"; diff --git a/package-lock.json b/package-lock.json index b977e41..9305cab 100644 --- a/package-lock.json +++ b/package-lock.json @@ -8,9 +8,6 @@ "name": "engine.io-parser", "version": "5.0.3", "license": "MIT", - "dependencies": { - "@socket.io/base64-arraybuffer": "~1.0.2" - }, "devDependencies": { "@babel/core": "~7.9.6", "@babel/preset-env": "~7.9.6", @@ -1410,14 +1407,6 @@ "node": ">=8" } }, - "node_modules/@socket.io/base64-arraybuffer": { - "version": "1.0.2", - "resolved": "https://registry.npmjs.org/@socket.io/base64-arraybuffer/-/base64-arraybuffer-1.0.2.tgz", - "integrity": "sha512-dOlCBKnDw4iShaIsH/bxujKTM18+2TOAsYz+KSc11Am38H4q5Xw8Bbz97ZYdrVNM+um3p7w86Bvvmcn9q+5+eQ==", - "engines": { - "node": ">= 0.6.0" - } - }, "node_modules/@tsconfig/node10": { "version": "1.0.8", "resolved": "https://registry.npmjs.org/@tsconfig/node10/-/node10-1.0.8.tgz", @@ -12648,11 +12637,6 @@ "integrity": "sha512-tsAQNx32a8CoFhjhijUIhI4kccIAgmGhy8LZMZgGfmXcpMbPRUqn5LWmgRttILi6yeGmBJd2xsPkFMs0PzgPCw==", "dev": true }, - "@socket.io/base64-arraybuffer": { - "version": "1.0.2", - "resolved": "https://registry.npmjs.org/@socket.io/base64-arraybuffer/-/base64-arraybuffer-1.0.2.tgz", - "integrity": "sha512-dOlCBKnDw4iShaIsH/bxujKTM18+2TOAsYz+KSc11Am38H4q5Xw8Bbz97ZYdrVNM+um3p7w86Bvvmcn9q+5+eQ==" - }, "@tsconfig/node10": { "version": "1.0.8", "resolved": "https://registry.npmjs.org/@tsconfig/node10/-/node10-1.0.8.tgz", diff --git a/package.json b/package.json index cd8def4..e1b521d 100644 --- a/package.json +++ b/package.json @@ -30,9 +30,6 @@ "zuul": "3.11.1", "zuul-ngrok": "4.0.0" }, - "dependencies": { - "@socket.io/base64-arraybuffer": "~1.0.2" - }, "scripts": { "compile": "rimraf ./build && tsc && tsc -p tsconfig.esm.json && ./postcompile.sh", "test": "npm run format:check && npm run compile && if test \"$BROWSERS\" = \"1\" ; then npm run test:browser; else npm run test:node; fi", From 764c99f136d2dc6873d1bdef684d1b5c2e061029 Mon Sep 17 00:00:00 2001 From: Damien Arrachequesne Date: Sat, 30 Apr 2022 14:13:42 +0200 Subject: [PATCH 7/7] chore(release): 5.0.4 Diff: https://github.com/socketio/engine.io-parser/compare/5.0.3...5.0.4 --- CHANGELOG.md | 10 ++++++++++ package-lock.json | 4 ++-- package.json | 2 +- 3 files changed, 13 insertions(+), 3 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 549507f..c240a57 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,3 +1,13 @@ +## [5.0.4](https://github.com/socketio/engine.io-parser/compare/5.0.3...5.0.4) (2022-04-30) + + +### Bug Fixes + +* add missing file extension for ESM import ([a421bbe](https://github.com/socketio/engine.io-parser/commit/a421bbec7bf43c567c49c608dee604872f6db823)) +* **typings:** update the type of RawData ([039b45c](https://github.com/socketio/engine.io-parser/commit/039b45cc65b50acc1f9da42ad605eaccb8ccbcde)) + + + ## [5.0.3](https://github.com/socketio/engine.io-parser/compare/5.0.2...5.0.3) (2022-01-17) diff --git a/package-lock.json b/package-lock.json index 9305cab..f17947c 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "engine.io-parser", - "version": "5.0.3", + "version": "5.0.4", "lockfileVersion": 2, "requires": true, "packages": { "": { "name": "engine.io-parser", - "version": "5.0.3", + "version": "5.0.4", "license": "MIT", "devDependencies": { "@babel/core": "~7.9.6", diff --git a/package.json b/package.json index e1b521d..76f7db7 100644 --- a/package.json +++ b/package.json @@ -2,7 +2,7 @@ "name": "engine.io-parser", "description": "Parser for the client for the realtime Engine", "license": "MIT", - "version": "5.0.3", + "version": "5.0.4", "main": "./build/cjs/index.js", "module": "./build/esm/index.js", "exports": {