Prototype pollution
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Aptitud para principiantes
- 48/100
- Tipo de issue
- Error
- Claridad
- Bastante claro
- Estado de actividad
- Estancado
- Stack tecnológico
- javascript, python
Línea de trabajo
Start with the org.transcrypt.runtime.js module and inspect the prototype helper definitions for Array, String, Uint8Array, and the other affected built-ins. Use the provided for-in example after importing a Transcrypt module to verify the helpers are no longer enumerable, then check that the reported helper functionality still works.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
After importing a transcrypt module, various prototypes such as Array, String, Uint8Array are polluted with python specific helper functions. These appear to be coming from the org.transcrypt.runtime.js module such as
Array.prototype.extend = function (aList) {
this.push.apply (this, aList);
};
Unfortunately these functions are listed as enumerable resulting in unexpected behaviour in external code ran later when its iterating even when the array wasn't created in the python code. Executing the following in the js console after simply importing the module
for( v in []){
console.log(v)
}
results in all these items being output
_class__
__iter__
__getslice__
__setslice__
__repr__
__str__
append
py_clear
extend
insert
remove
index
py_pop
py_sort
__add__
__mul__
__rmul__
__bindexOf__
add
discard
isdisjoint
issuperset
issubset
union
intersection
difference
symmetric_difference
py_update
__eq__
__ne__
__le__
__ge__
__lt__
__gt__
Changing it to be defined as the following appears to resolve the issue and doesn't appear to impact the functionality in my test case
Object.defineProperty(Array.prototype, 'extend', {
value: function (aList) {
this.push.apply (this, aList);
},
enumerable: false,
writable: true
})
- Lenguaje dominante
- Python
- Estrellas
- 2.9k
- Forks
- 218
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Preparar el entorno
Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de TranscryptOrg/Transcrypt
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
TranscryptOrg/Transcrypt#913 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
TranscryptOrg/Transcrypt#911 · 2 comentarios ·
-
IS: bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
TranscryptOrg/Transcrypt#908 ·
-
SUB: documentation
Dificultad 1/5 Menos de una hora Aptitud para principiantes 62/100
TranscryptOrg/Transcrypt#656 · 7 comentarios ·
-
Dificultad 3/5 1-2 días Aptitud para principiantes 76/100
TranscryptOrg/Transcrypt#914 ·
Todos los issues de TranscryptOrg/Transcrypt
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
-
bug
Dificultad 1/5 Menos de una hora Aptitud para principiantes 88/100
qgis/QGIS-Plugins-Website#459 ·
-
bug severity:medium
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Los mantenedores suelen responder en 2 días
-
bot-found bug priority: P3
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
madenvel/KalinkaPlayer#179 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
ls1intum/edutelligence#1098 ·
Los mantenedores suelen responder en 1 día