fix(SaveInterface): add hasOwnProperty checks to prevent object injection#5215
Open
WillyEverGreen wants to merge 1 commit intosugarlabs:masterfrom
Open
fix(SaveInterface): add hasOwnProperty checks to prevent object injection#5215WillyEverGreen wants to merge 1 commit intosugarlabs:masterfrom
WillyEverGreen wants to merge 1 commit intosugarlabs:masterfrom
Conversation
Contributor
|
❌ Some Jest tests failed. Please check the logs and fix the issues before merging. Failed Tests: |
Contributor
|
@WillyEverGreen Jest cases are failing.Please resolve |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
PR Description
Overview
This PR addresses security warnings (
security/detect-object-injection) identified by ESLint injs/SaveInterface.js. It adds proper property existence checks to prevent potential object injection vulnerabilities.Related
js/SaveInterface.jsChanges Made
Added
Object.prototype.hasOwnProperty.call()checks before accessing object/array properties with variable keys:drumMIDI[drum]andinstrumentMIDI[instrument]with fallbacks to default values.notationStaging[t]andnotationDrumStaging[t].Benefits
security/detect-object-injectionwarnings for this file.Verification
npx eslint js/SaveInterface.jsand confirmed 0 errors and 0 warnings (previously had 26 warnings).npx prettier --checkto ensure all files pass formatting checks.