Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Prototype-key defect (#551 class) remains in three user-keyed maps outside placement maps

Đang mở
#559 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức phù hợp với người mới
72/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Ít trao đổi
Công nghệ
typescript
Lĩnh vực
frontend, security

Hướng nghiên cứu

Bắt đầu với ba tệp được liệt kê: src/dashboard/model/dashboard-variable-store.ts, src/workspace/workspace-dashboards.ts và src/dashboard/application/dashboard-viewer-session.ts. Đọc các primitive defineJsonField và readJsonField trong src/core/saved-query.ts, sau đó thêm các bài kiểm thử round-trip cho các key proto và constructor. Được coi là hoàn tất khi mỗi entry vẫn tồn tại với Object.hasOwn và giá trị chính xác của nó, bao gồm mọi read path liên quan.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

bug inbox

What

Three more plain-object maps are built by assigning a user-authored string key directly (out[key] = …), which is the same defect #551 fixed for Dashboard placement maps. A key of __proto__ invokes the inherited Object.prototype setter and creates no own property, so the entry silently vanishes; a bare read of the same key resolves up the prototype chain to Object.prototype itself, which a merge-then-rewrite can then mutate realm-wide.

Sites

  • src/dashboard/model/dashboard-variable-store.ts:66,76,93,96 — out[variableId], out[dashboardId]
  • src/workspace/workspace-dashboards.ts:133 — configs[name] = config
  • src/dashboard/application/dashboard-viewer-session.ts:1495-1496 — proposedValues[variable.def.parameter]

All three are keyed by strings the user authors: variable IDs, dashboard IDs, and variable parameter names (the {name:Type} placeholder text in panel SQL). Nothing constrains those away from __proto__ or constructor.

Why this is cheap to fix

#551 already landed the two shared primitives in src/core/saved-query.ts and exported them:

  • defineJsonField(target, key, value) — Object.defineProperty-based write
  • readJsonField(target, key) — own-property-only read, for any map that gets merged, mutated, or where "no entry" differs from "an empty entry"

So this is a mechanical sweep plus round-trip tests with __proto__/constructor keys that assert the entry survives (Object.hasOwn + exact value), not merely that nothing throws.

Why deferred

Out of scope for #551, which was explicitly about placement maps keyed by tile ID — one sweep across every site it named, rather than quietly widening that PR's diff. Found while doing that sweep (PR #558).

Note on severity

#551's body originally claimed "no prototype pollution escapes". That is not true of the read path: setStylePlacement was reproduced polluting Object.prototype.grid for the whole realm. Whether any of the three sites above is reachable that way has not been checked — each needs the read side examined, not just the write.

Ngôn ngữ chính
TypeScript
Star
8
Fork
2
Merge trung bình
1 giờ 17 phút
Pull request đã merge (30 ngày)
3

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của Altinity/altinity-sql-browser

Tất cả issue của Altinity/altinity-sql-browser

Issue tương tự

Thêm issue về TypeScript

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.