npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@ahoo-wang/fetcher-cosec

v6.0.1

Published

Enterprise-grade CoSec authentication integration for the Fetcher HTTP client with comprehensive security features including automatic token management, device tracking, and request attribution.

Readme

@ahoo-wang/fetcher-cosec

面向 Fetcher 的 CoSec 请求归属与可选 JWT 认证。服务端契约要求 CoSec 应用、设备、 请求、空间或 Bearer Token 行为时使用。

安装

pnpm add @ahoo-wang/fetcher @ahoo-wang/fetcher-eventbus \
  @ahoo-wang/fetcher-storage @ahoo-wang/fetcher-cosec

Peer 依赖:fetcher、fetcher-eventbus 和 fetcher-storage。

示例

import { Fetcher } from '@ahoo-wang/fetcher';
import { CoSecConfigurer, sameOriginTrust } from '@ahoo-wang/fetcher-cosec';

const api = new Fetcher({ baseURL: 'https://api.example.com' });

const cosec = new CoSecConfigurer({
  appId: 'developer-console',
  isTrusted: sameOriginTrust,
  onUnauthorized: () => window.location.assign('/login'),
  onForbidden: async () => console.error('Access denied'),
});

cosec.applyTo(api);

该最小配置只添加归属请求头,不启用认证。提供 TokenRefresher 后会启用令牌存储、 Bearer 注入与自动刷新。刷新请求使用独立、未配置 CoSec 的 Fetcher。

isTrusted: sameOriginTrust 让令牌与 CoSec 请求头(含设备 ID)只发往 baseURL 所在源与页面自身的源。不设 isTrusted 时,发往任意源绝对 URL 的请求都会收到访问令牌。

核心能力

  • 应用、设备、请求、空间、租户与所有者归属。
  • JWT 解析、持久化、登录、退出与当前用户读取。
  • 合并并发自动刷新,并防止递归刷新。
  • 可配置 401 与 403 回调。
  • 用 isTrusted / sameOriginTrust 按源决定是否携带凭据。
  • 为自定义管线提供独立拦截器。

切勿记录、嵌入或提交真实令牌。

文档

English · 许可证