Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Compatibility with frozen Object prototype #2773

Open
wants to merge 1 commit into
base: dev
Choose a base branch
from

Conversation

norbertsuski
Copy link

  • Freezing the global Object prototype is one of the best ways to defend against Prototype Pollution attacks
  • Doing this changes all properties of the Object prototype to become non-writable
  • JavaScript does not allow you to use the "=" assignment operator to "shadow" any inherited, non-writable object properties -- in particular, the "toString" property
  • The correct way to do this is to use the Object.defineProperty() syntax instead

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants