Skip to content

Commit

Permalink
Revert "When objects are merged together, the target prototype can be…
Browse files Browse the repository at this point in the history
… polluted. (chartjs#7918)"

This reverts commit dff7140.
  • Loading branch information
GramParallelo committed Mar 23, 2022
1 parent 3c7924e commit f573324
Show file tree
Hide file tree
Showing 2 changed files with 0 additions and 21 deletions.
16 changes: 0 additions & 16 deletions src/helpers/helpers.core.js
Original file line number Diff line number Diff line change
@@ -1,9 +1,5 @@
'use strict';

function isValidKey(key) {
return ['__proto__', 'prototype', 'constructor'].indexOf(key) === -1;
}

/**
* @namespace Chart.helpers
*/
Expand Down Expand Up @@ -200,12 +196,6 @@ var helpers = {
* @private
*/
_merger: function(key, target, source, options) {
if (!isValidKey(key)) {
// We want to ensure we do not copy prototypes over
// as this can pollute global namespaces
return;
}

var tval = target[key];
var sval = source[key];

Expand All @@ -221,12 +211,6 @@ var helpers = {
* @private
*/
_mergerIf: function(key, target, source) {
if (!isValidKey(key)) {
// We want to ensure we do not copy prototypes over
// as this can pollute global namespaces
return;
}

var tval = target[key];
var sval = source[key];

Expand Down
5 changes: 0 additions & 5 deletions test/specs/helpers.core.tests.js
Original file line number Diff line number Diff line change
Expand Up @@ -304,11 +304,6 @@ describe('Chart.helpers.core', function() {
});

describe('merge', function() {
it('should not allow prototype pollution', function() {
var test = helpers.merge({}, JSON.parse('{"__proto__":{"polluted": true}}'));
expect(test.prototype).toBeUndefined();
expect(Object.prototype.polluted).toBeUndefined();
});
it('should update target and return it', function() {
var target = {a: 1};
var result = helpers.merge(target, {a: 2, b: 'foo'});
Expand Down

0 comments on commit f573324

Please sign in to comment.