npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2024 – Pkg Stats / Ryan Hefner

tbk_signer

v1.0.5

Published

Firma y verificación de sistema SOAP de Transbank

Downloads

88

Readme

Módulo de seguridad, firma y verificación de SOAP para Transbank

https://nodei.co/npm/tbk_signer.png?downloads=true&downloadRank=true&stars=true

Build Status contributions welcome Known Vulnerabilities

Este módulo está pensado para usarse en conjunto con la biblioteca Node SOAP. Su función principal es retornar el objeto que se debe colocar en la función setSecurity al construir la instancia de SOAP que se usará para enviar todas las transacciones del sistema Transbank.

Antes de usar

La versión de node con que se ha probado esta biblioteca es la 12, actualmente definida como LTS. Eso no significa que no sea compatible con las futuras versiones, pero hay que tener esto en cuenta en caso de que aparezca un error.

Por otra parte recuerda que debes obtener tus propios certificados mediante Transbank para ser usados junto a esta biblioteca. Los archivos que encuentres acá son solo de prueba y por ningún motivo permitirán que puedas realizar transacciones válidas al sistema de pagos.

Es recomendado que uses la API oficial listada en Transbank, pero en caso de que necesites una implementación especial puedes usar este módulo para crearla.

Instalación

npm i --save tbk_signer

Uso

Obtención de objeto de seguridad para Node-SOAP

import { tbkSecurityGenerator } from 'tbk_signer';

/*
 * privateCert es un string que contiene el certificado privado en formato PEM
 * publicCert es un string que contiene el certificado público en formato PEM
 */
tbkSecurityGenerator(privateCert, publicCert)
        .then(
          (tbkSecurityForSoap) => {
            createClient(
              'https://webpay3gint.transbank.cl/WSWebpayTransaction/cxf/WSWebpayService?wsdl',
              {
                ignoredNamespaces: {
                  namespaces: [],
                  override: true,
                },
              },
              (soapError, client) => {
                client.setSecurity(tbkSecurityForSoap);

                /*
                 * Desde este punto en adelante el cliente está listo para hacer
                 * una transacción.
                 */
              },
            );
          },
        )

Verificación de respuesta de Transbank usando certificado PEM

import{ verifySignature } from 'tbk_signer';

client.WSWebpayServiceImplService.WSWebpayServiceImplPort.initTransaction(
  testInput,
  (error, result, raw) => {
    /*
     * WebpayCert es la ruta al archivo que contiene la firma de verificación en
     * formato PEM
     */
    if(verifySignature(webpayCert, raw)){
      /*
       * Mensaje verificado, todo OK para continuar con la transacción
       */
    } else {
      /*
       * Mensaje falla la verificación, posible ataque o mensaje sospechoso
       */
    }
    
  },
);

Test

npm test

Se usa Jest para testear este módulo, además de que se prueba antes el formato del código con eslint. No se aceptará ningún pull request que no pase ambas etapas del testeo.

Cómo contribuir

Todas las contribuciones son bienvenidas, es recomendable eso si que primero escribas un issue explicando la mejora o problema. Luego crea el pull request en base a ese issue.

También, si es que quieres aportar un café porque te ha gustado este repositorio, puedes hacerlo a través de ko-fi:

ko-fi

Licencia

BSD 3-Clause License

Copyright (c) 2020, Fabian Alexis Bravo Abarca All rights reserved.

Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met:

  1. Redistributions of source code must retain the above copyright notice, this list of conditions and the following disclaimer.

  2. Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution.

  3. Neither the name of the copyright holder nor the names of its contributors may be used to endorse or promote products derived from this software without specific prior written permission.

THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.