# secure-scheduler

> Secure scheduler is an easy to use module for scheduling events via end-user input using sandboxed method execution.

Latest version **1.2.0** (published 2018-03-13) · ISC license · 0 weekly downloads

## Install

```sh
npm install secure-scheduler
pnpm add secure-scheduler
yarn add secure-scheduler
bun add secure-scheduler
```

## Health

**Score 15/100 (F)** — status: abandoned.

Positive: no vulnerabilities.

Warnings: low downloads; no types; no esm support.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 1.2.0 |
| Published | 2018-03-13 |
| First published | 2018-03-09 |
| Weekly downloads | 0 |
| License | ISC |
| TypeScript types | none |
| Module format | CommonJS |
| Dependencies | 5 |
| Unpacked size | 15.9 KB |
| Known vulnerabilities | 0 (+1 in 1 direct dependencies) |
| Install scripts | no |
| GitHub stars | 0 |
| Author | Kolya Venturi |
| Maintainers | kolyaventuri |
| Keywords | scheduler, schedule, security, virtualization, timer, cron, cron job |

## Links

- npm: https://www.npmjs.com/package/secure-scheduler
- Repository: https://github.com/kolyaventuri/secure_scheduler
- Homepage: https://github.com/kolyaventuri/secure_scheduler#readme
- Issues: https://github.com/kolyaventuri/secure_scheduler/issues
- npm.io page: https://npm.io/package/secure-scheduler

## Dependencies (5)

- [vm2](https://npm.io/package/vm2.md) ^3.5.2
- [uuid](https://npm.io/package/uuid.md) ^3.2.1
- [lowdb](https://npm.io/package/lowdb.md) ^1.0.0
- [cron-parser](https://npm.io/package/cron-parser.md) ^2.4.5
- [node-schedule](https://npm.io/package/node-schedule.md) ^1.3.0

## Alternatives

- [cron](https://npm.io/package/cron.md) — 4.9M weekly downloads
- [@vercel/queue](https://npm.io/package/@vercel/queue.md) — 731.6K weekly downloads
- [create-sonicjs](https://npm.io/package/create-sonicjs.md) — 1.6K weekly downloads
- [@exellix/jobs-api](https://npm.io/package/@exellix/jobs-api.md) — 941 weekly downloads
- [@forwardimpact/libskill](https://npm.io/package/@forwardimpact/libskill.md) — 575 weekly downloads

## Recent versions

- 1.2.0 (latest) — 2018-03-13
- 1.1.1 — 2018-03-12
- 1.1.0 — 2018-03-12
- 1.0.1 — 2018-03-09
- 1.0.0 — 2018-03-09

## README

# Secure Scheduler

Secure scheduler is an easy to use module for scheduling events via end-user input using sandboxed method execution.

As such, the filesystem is not exposed in the event of a vulnerability. Hence, users can safely execute JavaScript code in Jobs.

## Installation
Install with `npm i secure-scheduler`

## Usage
Create a new scheduler as follows
```
const Scheduler = require('secure-scheduler');
const scheduler = new Scheduler('./jobs.json');
```

where the parameter is the storage path for jobs.

Functions can then be queued by passing a Function and Date or cron expression to the Scheduler.add method
```
scheduler.add(
  () => {
    // Do stuff
  },
  new Date(2018, 06, 05)
);
// returns Job { method: . . ., date: Date, id: "job_id" }
```

Cron expressions are also valid in place of fixed dates
```
scheduler.add(
  () => {
    // Do stuff
  },
  '*/30 * * * *'
);
```

Scheduler.add returns an _id_ (UUID-V1 formatted) to refer to the Job.

Jobs/scheduled events can be cancelled by calling Scheduler.cancel with the job id
`scheduler.cancel("[JOB ID]")`

Job IDs can be retrieved as an array with Scheduler.jobs
`scheduler.jobs // [id, id, . . .]`

## Allowing access to Node.JS modules
Modules can be exposed using identical option parameters to [vm2](https://github.com/patriksimek/vm2).

They can be defined globally in the Scheduler constructor
```
const scheduler = new Scheduler('./jobs.json', {
    require: {
      builtin: ['path']
    }
})
```

Or they can be defined on Scheduler.add
```
scheduler.add(() => {
    return require('path').extname('index.html');
    },
    new Date(2018, 06, 05),
    {
      require: {
        builtin: ['path']
      }
    }
)
```

*vm2 options defined in Scheduler.add take precedent over globally defined options in the constructor*

**Take care in exposing modules**
Exposing the built in `fs` module can lead to irreparable harm to your filesystem should an end user be able to invoke it. Only expose what is needed for your module to function. If needed, stub your modules with vm2 mock syntax.

---
_Source: https://npm.io/package/secure-scheduler · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
