Skip to content

Commit c7751d0

Browse files
committed
fix(run-store): drop the redundant own-property guard in carryUnknownKeys
The normalizer only ever sets known keys, so a non-known source key is never already present; the check was unnecessary and tripped the lint rule against hasOwnProperty. Skipping the prototype-pollution keys still holds.
1 parent 8766d54 commit c7751d0

2 files changed

Lines changed: 6 additions & 7 deletions

File tree

‎internal-packages/run-store/src/snapshotComparator.test.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -143,7 +143,7 @@ describe("diffLatest", () => {
143143
const read: SnapshotRead = { id: "s1", seq: 1, isValid: true, raw: "{}", entry };
144144
const n = normalizeFromRedis(read) as Record<string, unknown>;
145145

146-
expect(Object.prototype.hasOwnProperty.call(n, "toString")).toBe(true); // carried despite inherited name
146+
expect(Object.keys(n)).toContain("toString"); // carried as an own key despite the inherited name
147147
expect(n["toString"]).toBe("surprise");
148148
expect(Object.getPrototypeOf(n)).toBe(Object.prototype); // __proto__ skipped, no pollution
149149
expect("polluted" in {}).toBe(false);

‎internal-packages/run-store/src/snapshotComparator.ts‎

Lines changed: 5 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -78,16 +78,15 @@ const KNOWN_KEYS = new Set<string>([
7878
"waitpointIdSet",
7979
]);
8080

81-
// Carry a source key normalization does not recognise onto the normalized object, so the
82-
// unknownField check sees it instead of it being silently dropped (a false clean comparison).
83-
// Uses an own-property check (not `in`, which sees the prototype chain and would hide keys like
84-
// `constructor`), and skips prototype-pollution keys.
81+
// Carry a source key normalization does not recognise onto the normalized object, so the unknownField
82+
// check sees it instead of it being silently dropped (a false clean comparison). Skips the
83+
// prototype-pollution keys. No own-property guard is needed: the normalizer only ever sets KNOWN_KEYS,
84+
// so a non-known source key is never already present and cannot overwrite a normalized value.
8585
const DANGEROUS_KEYS = new Set(["__proto__", "constructor", "prototype"]);
86-
const hasOwn = (o: object, k: string): boolean => Object.prototype.hasOwnProperty.call(o, k);
8786
function carryUnknownKeys(target: NormalizedSnapshot, source: Record<string, unknown>): void {
8887
for (const k of Object.keys(source)) {
8988
if (DANGEROUS_KEYS.has(k)) continue;
90-
if (!KNOWN_KEYS.has(k) && !hasOwn(target, k)) target[k] = source[k];
89+
if (!KNOWN_KEYS.has(k)) target[k] = source[k];
9190
}
9291
}
9392

0 commit comments

Comments
 (0)