Visitar URL original
fix(zone.js): harden zoneSymbolEventNames against __proto__ key (defe… · angular/angular@fd7c2da · GitHub
Skip to content

Commit fd7c2da

Browse files
arturovtthePunderWoman
authored andcommitted
fix(zone.js): harden zoneSymbolEventNames against __proto__ key (defense-in-depth)
Initialize zoneSymbolEventNames with Object.create(null) instead of {}. This is hardening only. addEventListener('__proto__', fn) is not directly attacker-controllable — its presence in an application is itself an application bug and a prerequisite for any issue here. Without this change, if that application bug exists, two unexpected behaviors follow depending on environment: Browser: zoneSymbolEventNames['__proto__'] reads the __proto__ getter and returns Object.prototype (truthy), bypassing prepareEventNames. symbolEventName resolves to undefined and window['undefined'] = [] throws TypeError. Node.js + --disable-proto=throw: the assignment zoneSymbolEventNames['__proto__'] = {} inside prepareEventNames triggers the disabled __proto__ setter and throws. Using Object.create(null) removes the __proto__ accessor from the map so the key is treated as a plain missing property in both cases.
1 parent a69e56d commit fd7c2da

1 file changed

Lines changed: 6 additions & 4 deletions

File tree

‎packages/zone.js/lib/common/events.ts‎

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -85,7 +85,8 @@ const OPTIMIZED_ZONE_EVENT_TASK_DATA: EventTaskData = {
8585
useG: true,
8686
};
8787

88-
export const zoneSymbolEventNames: any = {};
88+
// tslint:disable-next-line:no-toplevel-property-access
89+
export const zoneSymbolEventNames: any = Object.create(null);
8990
export const globalSources: any = {};
9091

9192
const EVENT_NAME_SYMBOL_REGX = new RegExp('^' + ZONE_SYMBOL_PREFIX + '(\\w+)(true|false)$');
@@ -96,9 +97,10 @@ function prepareEventNames(eventName: string, eventNameToString?: (eventName: st
9697
const trueEventName = (eventNameToString ? eventNameToString(eventName) : eventName) + TRUE_STR;
9798
const symbol = ZONE_SYMBOL_PREFIX + falseEventName;
9899
const symbolCapture = ZONE_SYMBOL_PREFIX + trueEventName;
99-
zoneSymbolEventNames[eventName] = {};
100-
zoneSymbolEventNames[eventName][FALSE_STR] = symbol;
101-
zoneSymbolEventNames[eventName][TRUE_STR] = symbolCapture;
100+
zoneSymbolEventNames[eventName] = {
101+
[FALSE_STR]: symbol,
102+
[TRUE_STR]: symbolCapture,
103+
};
102104
}
103105

104106
export interface PatchEventTargetOptions {

0 commit comments

Comments
 (0)