{"_id":"@csaf-poc/csaf-webview","_rev":"3-b55c440e80cfd96ae368a65024e36188","name":"@csaf-poc/csaf-webview","dist-tags":{"latest":"1.1.0"},"versions":{"1.0.1":{"name":"@csaf-poc/csaf-webview","version":"1.0.1","keywords":["csaf"],"license":"Apache-2.0","_id":"@csaf-poc/csaf-webview@1.0.1","maintainers":[{"name":"tschmidtb51","email":"secvisogram@bsi.bund.de"},{"name":"koplas","email":"npm@schwabauer.co"}],"dist":{"shasum":"6ac2880fa4b707a10ca1575e12ac36c6d5ba7f81","tarball":"https://registry.npmjs.org/@csaf-poc/csaf-webview/-/csaf-webview-1.0.1.tgz","fileCount":174,"integrity":"sha512-zikpsPWCKL90FOPYnNXR0vMFAwbHLOSbYhgQgaCPPOxtl3BIP/0O8ux5kZeDtdPO8/Jyse/s6CsGRRKN2Me+7w==","signatures":[{"sig":"MEUCIQClg9no2YhkjvcesS/QvJC3u8CefH5Dx/ubJ8PySSD4fQIgCs8h+GXsax2NCGJZX6RVy6RveipQWM008HbtgYBiRRQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":923584},"type":"module","engines":{"node":">=20.0.0"},"gitHead":"c68e19dc864ee67aedcaca338f76c3e4c85aac9e","scripts":{"dev":"vite dev","lint":"prettier --plugin-search-dir . --check . && eslint .","test":"npm run test:integration && npm run test:unit","build":"vite build","check":"svelte-kit sync && svelte-check --tsconfig ./tsconfig.json","deploy":"git subtree push --prefix build origin gh-pages","format":"prettier --plugin-search-dir . --write .","preview":"vite preview","coverage":"vitest run --coverage","test:unit":"vitest","check:watch":"svelte-kit sync && svelte-check --tsconfig ./tsconfig.json --watch","build:ghpage":"BASE_PATH=/csaf_webview vite build","test:integration":"playwright test"},"_npmUser":{"name":"tschmidtb51","actor":{"name":"tschmidtb51","type":"user","email":"secvisogram@bsi.bund.de"},"email":"secvisogram@bsi.bund.de"},"_npmVersion":"10.9.2","description":"<!--  This file is Free Software under the Apache-2.0 License  without warranty, see README.md and LICENSES/Apache-2.0.txt for details.","directories":{},"_nodeVersion":"22.16.0","dependencies":{"chota":"^0.9.2","boxicons":"^2.1.4"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vite":"^4.5.9","tslib":"^2.4.1","eslint":"^8.28.0","svelte":"^4.2.19","vitest":"^0.32.2","prettier":"^2.8.0","typescript":"^5.0.0","svelte-check":"^3.4.3","@sveltejs/kit":"^1.30.4","@playwright/test":"^1.52.0","eslint-plugin-svelte":"^2.30.0","@sveltejs/adapter-auto":"^2.1.1","eslint-config-prettier":"^8.5.0","prettier-plugin-svelte":"^2.10.1","@sveltejs/adapter-static":"^2.0.2","@typescript-eslint/parser":"^5.45.0","@vitest/coverage-istanbul":"^0.33.0","@typescript-eslint/eslint-plugin":"^5.45.0"},"_npmOperationalInternal":{"tmp":"tmp/csaf-webview_1.0.1_1750259977509_0.4103314173395969","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@csaf-poc/csaf-webview","version":"1.1.0","keywords":["csaf"],"license":"Apache-2.0","_id":"@csaf-poc/csaf-webview@1.1.0","maintainers":[{"name":"tschmidtb51","email":"secvisogram@bsi.bund.de"},{"name":"koplas","email":"npm@schwabauer.co"}],"dist":{"shasum":"0d0c65bb788ab0083d5fa70958b8ef1b89cba495","tarball":"https://registry.npmjs.org/@csaf-poc/csaf-webview/-/csaf-webview-1.1.0.tgz","fileCount":174,"integrity":"sha512-vTVIzu14JKVzDUbJ6qNb7xYfSKRX7EgioglWZDQKuttZOhWVHCHifQ44ZzufbGWrxyTQAQMgVen0ph3K5DRb1A==","signatures":[{"sig":"MEYCIQCgK3ajXCpZzNFEfnZjTKmLgzTmKKXR/yeyXbQnwyfY5QIhAKlZonOtcbpgIEN+m0wDKZI+zgoUg5vhyx7sNXUWAEkl","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":923584},"type":"module","engines":{"node":">=20.0.0"},"gitHead":"01c9fad0f330dc3c9cfda20ab3ea930817bbc3bf","scripts":{"dev":"vite dev","lint":"prettier --plugin-search-dir . --check . && eslint .","test":"npm run test:integration && npm run test:unit","build":"vite build","check":"svelte-kit sync && svelte-check --tsconfig ./tsconfig.json","deploy":"git subtree push --prefix build origin gh-pages","format":"prettier --plugin-search-dir . --write .","preview":"vite preview","coverage":"vitest run --coverage","test:unit":"vitest","check:watch":"svelte-kit sync && svelte-check --tsconfig ./tsconfig.json --watch","build:ghpage":"BASE_PATH=/csaf_webview vite build","test:integration":"playwright test"},"_npmUser":{"name":"tschmidtb51","actor":{"name":"tschmidtb51","type":"user","email":"secvisogram@bsi.bund.de"},"email":"secvisogram@bsi.bund.de"},"_npmVersion":"10.9.2","description":"<!--  This file is Free Software under the Apache-2.0 License  without warranty, see README.md and LICENSES/Apache-2.0.txt for details.","directories":{},"_nodeVersion":"22.16.0","dependencies":{"chota":"^0.9.2","boxicons":"^2.1.4"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vite":"^4.5.9","tslib":"^2.4.1","eslint":"^8.28.0","svelte":"^4.2.19","vitest":"^0.32.2","prettier":"^2.8.0","typescript":"^5.0.0","svelte-check":"^3.4.3","@sveltejs/kit":"^1.30.4","@playwright/test":"^1.52.0","eslint-plugin-svelte":"^2.30.0","@sveltejs/adapter-auto":"^2.1.1","eslint-config-prettier":"^8.5.0","prettier-plugin-svelte":"^2.10.1","@sveltejs/adapter-static":"^2.0.2","@typescript-eslint/parser":"^5.45.0","@vitest/coverage-istanbul":"^0.33.0","@typescript-eslint/eslint-plugin":"^5.45.0"},"_npmOperationalInternal":{"tmp":"tmp/csaf-webview_1.1.0_1750260393067_0.22312955660746514","host":"s3://npm-registry-packages-npm-production"}}},"time":{"created":"2025-06-18T15:19:37.376Z","modified":"2025-11-25T16:20:21.807Z","1.0.1":"2025-06-18T15:19:37.741Z","1.1.0":"2025-06-18T15:26:33.375Z"},"license":"Apache-2.0","keywords":["csaf"],"description":"<!--  This file is Free Software under the Apache-2.0 License  without warranty, see README.md and LICENSES/Apache-2.0.txt for details.","maintainers":[{"email":"secvisogram@bsi.bund.de","name":"tschmidtb51"}],"readme":"<!--\n This file is Free Software under the Apache-2.0 License\n without warranty, see README.md and LICENSES/Apache-2.0.txt for details.\n\n SPDX-License-Identifier: Apache-2.0\n\n SPDX-FileCopyrightText: 2023 German Federal Office for Information Security (BSI) <https://www.bsi.bund.de>\n Software-Engineering: 2023 Intevation GmbH <https://intevation.de>\n-->\n\n# CSAF Webview\n\nA browser based web app (module) to:\n\n- Display the contents of a\n  [CSAF 2.0](https://docs.oasis-open.org/csaf/csaf/v2.0/csaf-v2.0.html)\n  document.\n- Browse the tree of documents offered by a CSAF Provider or mirror\n  via the ROLIE feed.\n\nNote: As of 2023-12-14 all but one server do not allow web applications\nto read the CSAF information directly. So you will get failures\ndue to _CORS restrictions_ often.\nSee https://github.com/oasis-tcs/csaf/issues/653 for more details.\n\nA backend can act as a proxy to avoid the problems caused by\nCSAF Providers missing `Access-Control-Allow-Origin: *` headers.\n\nThe envisoned usage is to be integrated in a larger application.\nTherefore, `csaf_webview` is kept simple and stylable.\n\n## Feedback sought\n\n> [!NOTE]\n> If you have tried or considered using this component\n> please contact us and explain your use cases.\n>\n> Please also let us know in case you are using webview and the reasons for its selection.\n>\n> Open an issue in this repo or send us an email, e.g. to\n> [@bernhardreiter](https://github.com/bernhardreiter).\n\nBackground: Initially this web component was used\nin [ISDuBA](https://github.com/ISDuBA/ISDuBA) and the plan\nwas to keep it external and by doing so, develop a more\nuniversal component to display CSAF files.\n\nDuring ISDuBA's development we've changed the approach,\nintegrated a copy of the code and made it ISDuBA specific instead.\nPutting the focus on the needs of ISDuBA first\nhelped to understand more about what this real CSAF-handling application\nneeded from a viewing component. Mainly a deeper integration\nwith the handled use cases.\nIt is hard to display CSAF documents well;\nwhich means fast and navigable that users will find the information\nthey want easily. Depending on their tasks, users profit from\ntayloring the viewing experience.\n\nBeing ISDuBA specific means, we cannot easily\nrip out the viewing component there and make it an external module again.\nWe could do a much better one now, but if other applications would need\na deeper integration as well anyway, they may or may not profit that much.\n\nWhich leaves us with the questions:\n\n- Is a universal web viewing component (for displaying CSAF documents)\n  feasable and useful?\n- Is there is enough demand for it?\n\nThus we would like to hear from you about how close this component gets to what\nyou need to support displaying CSAF documents on the web\nand what you would need from it. This helps us planning the maintenance.\n\n### Screenshots\n\n![](docs/app_single.png)\n\n_Displaying a single document_\n\n![](docs/app_feed.png)\n_Displaying a ROLIE-Feed_\n\nThe deployment via github pages is a demo\nand thus may not reflect the current state of the source repository.\n\n## Development\n\n### Clone the repo\n\n`git clone https://github.com/csaf-poc/csaf_webview.git`\n\n### `cd` into app directory\n\n`cd csaf_webview`\n\n### Install dependencies\n\nInstall current LTS version of NodeJS, e.g. see\nhttps://github.com/nodesource/distributions/blob/master/README.md .\nUpgrade to the latest version of npm if you can.\nDevelopment has been started with Node v20 and npm 10.2.1\n\n```sh\nnpm install\nnpx playwright install\n```\n\n### Run development server\n\nOptionally add `-- --open` to directly open a browser.\n\n`npm run dev -- --open`\n\n### Drag a valid csaf-file over the `dropzone`.\n\n### Run unit tests\n\n`npm run test:unit`\n\n### Run integration tests\n\n`npm run test:integration`\n\n### Run unit tests coverage\n\n`npm run coverage`\n\n### Deploy new version of GH page\n\n`npm run build:ghpage`\n`npm run deploy`\n\n## Configure a local proxysetup\n\nIn order to configure a proxy server use `vite.config.js`.\nThe default configuration is:\n\n```javascript\n...\nserver: {\n    proxy: {\n      \"/proxy/\": {\n        target: \"https://wid.cert-bund.de/\",\n        changeOrigin: true,\n        rewrite: (path) => path.replace(/^\\/proxy/, \"\")\n      }\n    }\n  },\n...\n```\n\nFor more information look [here](https://vitejs.dev/config/server-options.html#server-proxy).\n\nChange target to the URL to be proxied.\n\n## License\n\n- csaf_webview is licensed as Free Software under Apache-2.0 License.\n\n- See the specific source files\n  for details, the licenses itself can be found in the directory `LICENSES/`.\n\n- The resulting webpage contains third party Free Software components under\n  licenses that to our best knowledge are compatible at time of adding\n  the dependency. See `package.json` for details.\n","readmeFilename":"README.md"}