Prototype-key defect (#551 class) remains in three user-keyed maps outside placement maps
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức phù hợp với người mới
- 72/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Ít trao đổi
- Công nghệ
- typescript
Hướng nghiên cứu
Bắt đầu với ba tệp được liệt kê: src/dashboard/model/dashboard-variable-store.ts, src/workspace/workspace-dashboards.ts và src/dashboard/application/dashboard-viewer-session.ts. Đọc các primitive defineJsonField và readJsonField trong src/core/saved-query.ts, sau đó thêm các bài kiểm thử round-trip cho các key proto và constructor. Được coi là hoàn tất khi mỗi entry vẫn tồn tại với Object.hasOwn và giá trị chính xác của nó, bao gồm mọi read path liên quan.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
What
Three more plain-object maps are built by assigning a user-authored string key directly (out[key] = …), which is the same defect #551 fixed for Dashboard placement maps. A key of __proto__ invokes the inherited Object.prototype setter and creates no own property, so the entry silently vanishes; a bare read of the same key resolves up the prototype chain to Object.prototype itself, which a merge-then-rewrite can then mutate realm-wide.
Sites
src/dashboard/model/dashboard-variable-store.ts:66,76,93,96—out[variableId],out[dashboardId]src/workspace/workspace-dashboards.ts:133—configs[name] = configsrc/dashboard/application/dashboard-viewer-session.ts:1495-1496—proposedValues[variable.def.parameter]
All three are keyed by strings the user authors: variable IDs, dashboard IDs, and variable parameter names (the {name:Type} placeholder text in panel SQL). Nothing constrains those away from __proto__ or constructor.
Why this is cheap to fix
#551 already landed the two shared primitives in src/core/saved-query.ts and exported them:
defineJsonField(target, key, value)—Object.defineProperty-based writereadJsonField(target, key)— own-property-only read, for any map that gets merged, mutated, or where "no entry" differs from "an empty entry"
So this is a mechanical sweep plus round-trip tests with __proto__/constructor keys that assert the entry survives (Object.hasOwn + exact value), not merely that nothing throws.
Why deferred
Out of scope for #551, which was explicitly about placement maps keyed by tile ID — one sweep across every site it named, rather than quietly widening that PR's diff. Found while doing that sweep (PR #558).
Note on severity
#551's body originally claimed "no prototype pollution escapes". That is not true of the read path: setStylePlacement was reproduced polluting Object.prototype.grid for the whole realm. Whether any of the three sites above is reachable that way has not been checked — each needs the read side examined, not just the write.
- Ngôn ngữ chính
- TypeScript
- Star
- 8
- Fork
- 2
- Merge trung bình
- 1 giờ 17 phút
- Pull request đã merge (30 ngày)
- 3
Chuẩn bị môi trường
- Có Dockerfile hoặc tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của Altinity/altinity-sql-browser
-
inbox
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
Altinity/altinity-sql-browser#605 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
inbox
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
Altinity/altinity-sql-browser#509 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
inbox
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
Altinity/altinity-sql-browser#489 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
flamegraphĐang mởenhancement
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 25/100
Altinity/altinity-sql-browser#684 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 68/100
Altinity/altinity-sql-browser#680 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của Altinity/altinity-sql-browser
Issue tương tự
-
type/bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
Maintainer thường phản hồi trong vòng 1 ngày
-
community first-timers-only good first issue hacktoberfest help wanted low hanging fruit up-for-grabs
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 95/100
lingdojo/kana-dojo#31593 · 1 bình luận · 5 reaction ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug
Độ khó 1/5 1-3 giờ Mức phù hợp với người mới 90/100
apache/fineract-backoffice-ui#697 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
good first issue hacktoberfest help wanted
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
libredb/libredb-studio#1291 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug P1
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
Yeachan-Heo/gajae-code#6295 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày