[pull] main from nodejs:main#342
Merged
Merged
Conversation
Functions bypassed the object guard in processHeader() and were coerced via template literals without isValidHeaderValue(), allowing CRLF injection when toString/Symbol.toPrimitive returned embedded newlines. Validate after coercion on both scalar and array paths. Signed-off-by: Matteo Collina <hello@matteocollina.com>
* fix: handle frozen globalThis in setGlobalDispatcher When Object.freeze(globalThis) is called before undici globals are accessed, setGlobalDispatcher would throw TypeError because it cannot extend globalThis. This fix wraps the Object.defineProperty calls in try/catch. When globalThis is not extensible (frozen), the dispatcher is stored in a module-level fallback variable instead. getGlobalDispatcher is updated to return the fallback dispatcher when the globalThis property is not available. This allows undici to work correctly even when globalThis has been frozen, which is recommended by Node.js security best practices (CWE-349). Fixes issue where Object.freeze(globalThis) breaks undici access. * test: add unit test for frozen globalThis in setGlobalDispatcher Add comprehensive test coverage for the frozen globalThis fix. Tests verify: 1. setGlobalDispatcher does not throw when globalThis is frozen 2. getGlobalDispatcher continues to return a valid dispatcher 3. The fallback mechanism works correctly when globalThis is not extensible This addresses the review feedback from mcollina requesting tests. * test: improve frozen globalThis test coverage Add comprehensive test cases to ensure all code paths in the frozen globalThis fix are exercised. Tests verify: 1. setGlobalDispatcher does not throw when globalThis is frozen 2. getGlobalDispatcher returns a valid dispatcher 3. Fallback dispatcher persists across multiple calls This addresses review feedback requesting tests.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
See Commits and Changes for more details.
Created by
pull[bot] (v2.0.0-alpha.4)
Can you help keep this open source service alive? 💖 Please sponsor : )