You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Bruno导入cose-js库时遭遇VMError错误求助

解决Bruno中导入cose-js时的"Operation not allowed on contextified object"错误

针对你遇到的这个错误,这里提供几个可行的解决思路:

1. 改用ES模块动态导入

Bruno的脚本沙箱对CommonJS模块的require可能存在上下文限制,替换为ES模块的动态导入或许能绕过这个问题:

// 替换原有的require语句
const { Cose } = await import('cose-js');
const cose = new Cose();

2. 补充cose-js依赖的核心模块到白名单

查看cose-js的package.json依赖列表,把它用到的Node.js核心模块(比如stream、util等)添加到bruno.json的moduleWhitelist中,确保沙箱允许加载这些依赖:

{
  "version": "1",
  "name": "myCollection",
  "type": "collection",
  "scripts": {
    "moduleWhitelist": [
      "cose-js",
      "@peculiar/webcrypto",
      "crypto",
      "process",
      "buffer",
      "util",
      "stream"
    ],
    "filesystemAccess": { "allow": true }
  },
  "ignore": ["node_modules", ".git"]
}

3. 替换为轻量化的COSE实现

cose-js的依赖链可能较复杂,尝试用更适配沙箱环境的库替代,比如@noble/curves配合手动处理COSE的CBOR结构,或者寻找专门的ES模块版本COSE库。

4. 手动实现COSE签名逻辑(临时替代)

如果上述方法都不生效,可以直接基于已有的@peculiar/webcrypto手动实现COSE签名核心逻辑,跳过cose-js依赖:

const encoder = new TextEncoder();
const payload = encoder.encode('your-payload-content');

// 构建COSE_Sign1结构的待签数据
const protectedHeader = encoder.encode(JSON.stringify({ alg: -7 })); // ES256对应COSE算法标识
const coseSign1Template = new Uint8Array([
  0xd2, // CBOR标签:COSE_Sign1
  0x84, // 数组长度4
  protectedHeader,
  new Uint8Array(), // 无保护头
  payload,
  new Uint8Array() // 签名占位
]);

// 对占位前的部分签名
const signature = await crypto.subtle.sign(
  { name: "ECDSA", hash: "SHA-256" },
  keys.privateKey,
  coseSign1Template.slice(0, coseSign1Template.length - 1)
);

// 替换占位得到最终的COSE_Sign1结构
const finalCose = new Uint8Array([
  ...coseSign1Template.slice(0, coseSign1Template.length - 1),
  ...new Uint8Array(signature)
]);

内容的提问来源于stack exchange,提问作者Omar.R

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 06:22:50