fix[cloneDeep, clone, assign, omit, pick]: preserve own __proto__ property without setting prototype - #2128
Open
TalhaHunter101 wants to merge 2 commits into
Open
fix[cloneDeep, clone, assign, omit, pick]: preserve own __proto__ property without setting prototype#2128TalhaHunter101 wants to merge 2 commits into
TalhaHunter101 wants to merge 2 commits into
Conversation
…perty without setting prototype In JavaScript, setting `target[key] = value` when `key === '__proto__'` invokes `Object.prototype.__proto__`'s setter rather than defining an own property on the target object. This causes the target object's prototype to be modified, while dropping '__proto__' from the target's own keys. Use Object.defineProperty when assigning '__proto__' keys in object copy and assignment utilities (assign, assignIn, assignWith, assignInWith, assignValue, clone, cloneDeep, omit, omitBy, pick, pickBy, mapValues) so that own '__proto__' properties are preserved as own properties without polluting or mutating the object's prototype.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch had an error being deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes #2117.
In JavaScript, setting
target[key] = valuewhenkey === '__proto__'invokesObject.prototype.__proto__'s setter rather than defining an own property on the target object. This causes two issues:'__proto__'is dropped from the target object's own keys (Object.hasOwn(result, '__proto__')becomesfalse).Object.getPrototypeOf(result)is set to the value, causing prototype pollution).Lodash preserves an own
__proto__property as an own data property without setting or mutating the object's prototype. This PR alignses-toolkitandes-toolkit/compatwith Lodash by usingObject.definePropertywhenever assigning'__proto__'keys (matching the existing approach insrc/compat/util/toPlainObject.ts).Lodash difference
The same behavior difference occurred across
clone,cloneDeep,cloneDeepWith,assign,assignIn,assignWith,assignInWith,assignValue,omit,omitBy,pick,pickBy, andmapValues.Contributing policy checks
@types/lodashin strict mode:All of these calls typecheck without error under TypeScript strict mode.
services/secrets/src/api.js#L13),cloneDeep(JSON.parse(...))is called on decrypted secret payloads.packages/studio/src/player/components/timelineDragDrop.ts#L44),pick(JSON.parse(...) as Record<string, string | undefined>, ...)is called on parsed JSON data.Changes
assignValue(src/compat/_internal/assignValue.ts) to useObject.definePropertywhen setting'__proto__'.cloneandcloneDeepWithinsrc/object/andsrc/compat/object/clone.tsto define'__proto__'usingObject.defineProperty.assignImpl,assignInImpl,assignWithImpl, andassignInWithImplinsrc/compat/object/to safely define'__proto__'.omit,omitBy,pick,pickBy, andmapValuesin both core and compat to preserve own'__proto__'properties.'__proto__'preservation and prototype non-pollution across all 16 corresponding.spec.tstest files.