Skip to content

Commit

Permalink
fix: address prototype pollution issue
Browse files Browse the repository at this point in the history
  • Loading branch information
bcoe committed Nov 30, 2020
1 parent 45d2568 commit 7de58ca
Show file tree
Hide file tree
Showing 3 changed files with 20 additions and 2 deletions.
2 changes: 1 addition & 1 deletion index.js
Expand Up @@ -11,7 +11,7 @@ function Y18N (opts) {
this.fallbackToLanguage = typeof opts.fallbackToLanguage === 'boolean' ? opts.fallbackToLanguage : true

// internal stuff.
this.cache = {}
this.cache = Object.create(null)
this.writeQueue = []
}

Expand Down
2 changes: 1 addition & 1 deletion package.json
@@ -1,6 +1,6 @@
{
"name": "y18n",
"version": "4.0.0",
"version": "4.0.1",
"description": "the bare-bones internationalization library used by yargs",
"main": "index.js",
"scripts": {
Expand Down
18 changes: 18 additions & 0 deletions test/y18n-test.js
Expand Up @@ -352,6 +352,24 @@ describe('y18n', function () {
})
})

// See: https://github.com/yargs/y18n/issues/96,
// https://github.com/yargs/y18n/pull/107
describe('prototype pollution', () => {
it('does not pollute prototype, with __proto__ locale', () => {
const y = y18n()
y.setLocale('__proto__')
y.updateLocale({ polluted: '👽' })
y.__('polluted').should.equal('👽')
;(typeof polluted).should.equal('undefined')
})

it('does not pollute prototype, when __ is used with __proto__ locale', () => {
const __ = y18n({ locale: '__proto__' }).__
__('hello')
;(typeof {}.hello).should.equal('undefined')
})
})

after(function () {
rimraf.sync('./test/locales/fr.json')
})
Expand Down

0 comments on commit 7de58ca

Please sign in to comment.