Repository navigation
Conversation
`deserialize_binary_form` rebuilds each upload as a `LazyFile` wrapped in a Proxy that reports `File.prototype`, so that validators accept it. That also gets the value past the type check in `FormData.append(name, blob, filename)` without it being a real `Blob`, and `FormData` then falls back to string coercion: the request carries the fifteen bytes of `[object Object]` under the right filename and content type, and nothing reports a failure. Without the Proxy, `append` raises `TypeError: parameter 2 is not of type 'Blob'`. So the Proxy does not cause a coercion bug so much as suppress an accurate error. A `Symbol.toPrimitive` that throws puts that error back, with a message naming the likely cause, and leaves everything else alone — the two-argument `append(name, blob)` still streams, and validators still see a `File`. Subclassing `File` was tried first and is worse. A subclass built with an empty `super([])` that overrides `size` and `stream()` passes every type check and is written to the wire empty, because the three-argument path reads the blob's internal slots rather than calling `stream()`. An empty part is harder to notice than `[object Object]`. The test appends a deserialized file both ways: three arguments must throw, and two arguments must still put the contents on the wire. Claude-Session: https://claude.ai/code/session_01EssSzytrsfTbMhCguS3RmD
|
Install the latest version of pnpm add https://pkg.svelte.dev/@sveltejs/kit/c/46c2292772a2aa2ade6b510a105fc76500801184Open in Note This PR is from a fork. A maintainer must approve approve each commit before it can be built and installed. |
🦋 Changeset detectedLatest commit: 46c2292 The changes in this PR will be included in the next version bump. This PR includes changesets to release 1 package
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
closes #17313
A remote form's file is a
LazyFilebehind aProxythat reportsFile.prototype. That gets it pastFormData.append(name, blob, filename)'s type check without it being a realBlob, and the value is then coerced to a string: the request carries[object Object]under the right filename and content type, and nothing fails.FormData.setwith a filename andnew Blob([file])lose the contents the same way.This gives
LazyFileaSymbol.toPrimitivethat throws aTypeErrornaming the likely cause. All three silent paths fail by string coercion, so all three now fail loudly. Nothing else changes: the two-argumentappend(name, file)still streams lazily, and validators still see aFile.It closes the failure mode rather than the underlying mismatch. The structural options (buffering into a real
File, or a distinct type with an explicit.blob()) are discussed in #17313, and this can land without choosing between them.The test deserializes a binary form, then checks that string coercion and a three-argument
appendthrow, and that a two-argumentappendstill puts the contents on the wire. It fails without the change.Please don't delete this checklist! Before submitting the PR, please make sure you do the following:
Tests
pnpm testand lint the project withpnpm lintandpnpm checkRan the kit unit suite (
pnpm test:unit: 77 files, 1054 passed, 110 skipped),oxfmt --check ., eslint on the changed files, andpnpm checkinpackages/kit, all passing. I did not run the integration suites locally.Changesets
pnpm changesetand following the prompts. Changesets that add features should beminorand those that fix bugs should bepatch. Please prefix changeset messages withfeat:,fix:, orchore:.Edits