Skip to content

Object.assign / spread of http request object difference between v14.15.1 and v14.15.2 #36550

Description

@rubenstolk
  • Version: 14.15.2
  • Platform: any
  • Subsystem: any

What steps will reproduce the bug?

While trying to create a cloned version of an http request object, prototype properties/methods such as headers and get get lost.

const assert = require('assert');
const http = require('http');

const server = http
  .createServer((req, res) => {
    const dummyReq = { ...req };
    res.writeHead(200, { 'Content-Type': 'text/plain' });
    res.end('ok');
    assert.deepStrictEqual(req.headers, dummyReq.headers);
  })
  .listen();

server.on('listening', () => {
  http.get(`http://localhost:${server.address().port}`);
});

What is the expected behavior?

I honestly don't know if the behavior from 14.15.1 or from 14.15.2 is expected.

Behavior until 14.15.1: dummyReq.headers is not undefined.

What do you see instead?

Output in 14.15.2: dummyReq.headers is undefined.

Additional info

The same happens while using Object.assign

Activity

  1. rubenstolk commented on Dec 17, 2020

    @rubenstolk
    Author

    As @ExE-Boss indicated here (#36023 (comment)), the http request object must now be of a different inheritance level...

  2. ExE-Boss commented on Dec 17, 2020

    @ExE-Boss
    Contributor

    Object.assign also copies only own enumerable properties, but uses [[Set]] instead of [[Define]], so:

    const target = {};
    Object.assign(
    	target,
    	JSON.parse(`{
    		"__proto__": null
    	}`,
    );

    results in target having its prototype set to null instead of adding an own __proto__ property, because of the Object.prototype.__proto__ accessor.


    Whereas:

    const target = {
    	...(JSON.parse(`{
    		"__proto__": null
    	}`)),
    };

    Results in an object with an own __proto__ property set to null and a prototype of Object.prototype.

  3. aduh95 commented on Dec 17, 2020

    @aduh95
    Contributor

    This likely related to #35281.

  4. ExE-Boss commented on Dec 17, 2020

    @ExE-Boss
    Contributor

    This is definitely caused by #35281.

  5. aduh95 commented on Dec 17, 2020

    @aduh95
    Contributor

    I think a quick fix would be to do something like:

    const dummyReq = { ...req, get headers() { return req.headers }, get trailers() { return req.trailers; } };
  6. rubenstolk commented on Dec 17, 2020

    @rubenstolk
    Author

    Yep, thanks for that! I have already implemented something similar.

  7. added
    httpIssues and PRs related to the http subsystem.
    confirmed-bugIssues and PRs for confirmed bugs.
    on Dec 17, 2020
  8. BethGriggs commented on Dec 17, 2020

    @BethGriggs
    Member

    Opinions on whether this warrants an urgent revert of #35281 and follow-up patch release this week? cc: @ronag @mcollina

    (I'd need to get started on that today if so, as i'll be out-of-office/mostly offline from tomorrow until the New Year.)

  9. mcollina commented on Dec 17, 2020

    @mcollina
    SponsorMember

    I'd just revert it in v14, not v15.

  10. mhdawson commented on Dec 17, 2020

    @mhdawson
    Member

    I agree with @mcollina that a revert in v14 would amke sense, and it would be good to get a release out.

  11. BethGriggs commented on Dec 17, 2020

    @BethGriggs
    Member

    Raised a revert PR for Node.js 14 (#36553). Hope to get this into a v14.15.3 very soon so that there are no barriers to adopting the upcoming security release on January 4th.

  12. mcollina commented on Dec 17, 2020

    @mcollina
    SponsorMember

    I've investigated this with a bit more detail, and I don't think it's a bug. I would recommend against using the spread operator on any stream. Nevertheless, this should be reverted in v14.x as it was probably a significant breaking change that slipped in a patch release.

  13. 16 remaining items

  14. added a commit that references this issue on Dec 22, 2020
  15. added a commit that references this issue on Aug 15, 2023
  16. added a commit that references this issue on May 11, 2026
  17. added a commit that references this issue on May 13, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    confirmed-bugIssues and PRs for confirmed bugs.httpIssues and PRs related to the http subsystem.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions