mirror of
https://github.com/react/react-native-devtools-frontend.git
synced 2026-10-04 11:01:37 +08:00
This change addresses 2 issues in uglify-js and socket.io-parser. See reports below for details: - https://www.mend.io/vulnerability-database/CVE-2022-37598 - https://nvd.nist.gov/vuln/detail/CVE-2022-2421 The socket.io-parser issue was addressed by running npm audit via the following command: `npm run install-deps audit fix --audit-level=critical` Since audit didn't recognize the uglify-js issue, I updated uglify-js to version 3.13.10 "manually" by adding an entry in manage_node_deps.py. running install-deps to update package-lock.json and then removing the entry from manage_node_deps.py. Bug: None Change-Id: I29238b14773a1b94b973886b0bb700f50e45cfa9 Reviewed-on: https://chromium-review.googlesource.com/c/devtools/devtools-frontend/+/4061168 Reviewed-by: Benedikt Meurer <bmeurer@chromium.org> Commit-Queue: Brandon Walderman <brwalder@microsoft.com>
84 lines
2.7 KiB
JavaScript
84 lines
2.7 KiB
JavaScript
import { isBinary } from "./is-binary.js";
|
|
/**
|
|
* Replaces every Buffer | ArrayBuffer | Blob | File in packet with a numbered placeholder.
|
|
*
|
|
* @param {Object} packet - socket.io event packet
|
|
* @return {Object} with deconstructed packet and list of buffers
|
|
* @public
|
|
*/
|
|
export function deconstructPacket(packet) {
|
|
const buffers = [];
|
|
const packetData = packet.data;
|
|
const pack = packet;
|
|
pack.data = _deconstructPacket(packetData, buffers);
|
|
pack.attachments = buffers.length; // number of binary 'attachments'
|
|
return { packet: pack, buffers: buffers };
|
|
}
|
|
function _deconstructPacket(data, buffers) {
|
|
if (!data)
|
|
return data;
|
|
if (isBinary(data)) {
|
|
const placeholder = { _placeholder: true, num: buffers.length };
|
|
buffers.push(data);
|
|
return placeholder;
|
|
}
|
|
else if (Array.isArray(data)) {
|
|
const newData = new Array(data.length);
|
|
for (let i = 0; i < data.length; i++) {
|
|
newData[i] = _deconstructPacket(data[i], buffers);
|
|
}
|
|
return newData;
|
|
}
|
|
else if (typeof data === "object" && !(data instanceof Date)) {
|
|
const newData = {};
|
|
for (const key in data) {
|
|
if (Object.prototype.hasOwnProperty.call(data, key)) {
|
|
newData[key] = _deconstructPacket(data[key], buffers);
|
|
}
|
|
}
|
|
return newData;
|
|
}
|
|
return data;
|
|
}
|
|
/**
|
|
* Reconstructs a binary packet from its placeholder packet and buffers
|
|
*
|
|
* @param {Object} packet - event packet with placeholders
|
|
* @param {Array} buffers - binary buffers to put in placeholder positions
|
|
* @return {Object} reconstructed packet
|
|
* @public
|
|
*/
|
|
export function reconstructPacket(packet, buffers) {
|
|
packet.data = _reconstructPacket(packet.data, buffers);
|
|
packet.attachments = undefined; // no longer useful
|
|
return packet;
|
|
}
|
|
function _reconstructPacket(data, buffers) {
|
|
if (!data)
|
|
return data;
|
|
if (data && data._placeholder === true) {
|
|
const isIndexValid = typeof data.num === "number" &&
|
|
data.num >= 0 &&
|
|
data.num < buffers.length;
|
|
if (isIndexValid) {
|
|
return buffers[data.num]; // appropriate buffer (should be natural order anyway)
|
|
}
|
|
else {
|
|
throw new Error("illegal attachments");
|
|
}
|
|
}
|
|
else if (Array.isArray(data)) {
|
|
for (let i = 0; i < data.length; i++) {
|
|
data[i] = _reconstructPacket(data[i], buffers);
|
|
}
|
|
}
|
|
else if (typeof data === "object") {
|
|
for (const key in data) {
|
|
if (Object.prototype.hasOwnProperty.call(data, key)) {
|
|
data[key] = _reconstructPacket(data[key], buffers);
|
|
}
|
|
}
|
|
}
|
|
return data;
|
|
}
|