Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Next Next commit
Revert "sec: security patch for CVE-2024-51999"
This reverts commit 2f64f68.
  • Loading branch information
UlisesGascon committed Dec 1, 2025
commit ebd3876588a7fd41d9f16dd36348bbadf1615a05
2 changes: 1 addition & 1 deletion lib/utils.js
Original file line number Diff line number Diff line change
Expand Up @@ -266,6 +266,6 @@ function createETagGenerator (options) {

function parseExtendedQueryString(str) {
return qs.parse(str, {
plainObjects: true
allowPrototypes: true
});
}
91 changes: 2 additions & 89 deletions test/req.query.js
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,6 @@
var assert = require('node:assert')
var express = require('../')
, request = require('supertest');
var qs = require('qs');

describe('req', function(){
describe('.query', function(){
Expand Down Expand Up @@ -39,22 +38,6 @@ describe('req', function(){
.get('/?user.name=tj')
.expect(200, '{"user.name":"tj"}', done);
});

it('should not be able to access object prototype properties', function (done) {
var app = createApp('extended', true);

request(app)
.get('/?foo=yee')
.expect(200, /TypeError: req\.query\.hasOwnProperty is not a function/, done);
});

it('should be able to use object prototype property names as keys', function (done) {
var app = createApp('extended', true);

request(app)
.get('/?hasOwnProperty=yee')
.expect(200, '{"query":{"hasOwnProperty":"yee"},"error":"TypeError: req.query.hasOwnProperty is not a function"}', done);
});
});

describe('when "query parser" is simple', function () {
Expand All @@ -65,22 +48,6 @@ describe('req', function(){
.get('/?user%5Bname%5D=tj')
.expect(200, '{"user[name]":"tj"}', done);
});

it('should not be able to access object prototype properties', function (done) {
var app = createApp('simple', true);

request(app)
.get('/?foo=yee')
.expect(200, /TypeError: req\.query\.hasOwnProperty is not a function/, done);
});

it('should be able to use object prototype property names as keys', function (done) {
var app = createApp('simple', true);

request(app)
.get('/?hasOwnProperty=yee')
.expect(200, '{"query":{"hasOwnProperty":"yee"},"error":"TypeError: req.query.hasOwnProperty is not a function"}', done);
});
});

describe('when "query parser" is a function', function () {
Expand All @@ -93,18 +60,6 @@ describe('req', function(){
.get('/?user%5Bname%5D=tj')
.expect(200, '{"length":17}', done);
});

// test exists to verify behavior for folks wishing to workaround our qs defaults
it('should drop object prototype property names and be able to access object prototype properties', function (done) {
var app = createApp(
function (str) {
return qs.parse(str)
}, true);

request(app)
.get('/?hasOwnProperty=biscuits')
.expect(200, '{"query":{},"hasOwnProperty":false}', done);
});
});

describe('when "query parser" disabled', function () {
Expand All @@ -115,22 +70,6 @@ describe('req', function(){
.get('/?user%5Bname%5D=tj')
.expect(200, '{}', done);
});

it('should not be able to access object prototype properties', function (done) {
var app = createApp('extended', true);

request(app)
.get('/?foo=yee')
.expect(200, /TypeError: req\.query\.hasOwnProperty is not a function/, done);
});

it('should be able to use object prototype property names as keys', function (done) {
var app = createApp('extended', true);

request(app)
.get('/?hasOwnProperty=yee')
.expect(200, '{"query":{"hasOwnProperty":"yee"},"error":"TypeError: req.query.hasOwnProperty is not a function"}', done);
});
});

describe('when "query parser" enabled', function () {
Expand All @@ -141,22 +80,6 @@ describe('req', function(){
.get('/?user%5Bname%5D=tj')
.expect(200, '{"user[name]":"tj"}', done);
});

it('should not be able to access object prototype properties', function (done) {
var app = createApp('extended', true);

request(app)
.get('/?foo=yee')
.expect(200, /TypeError: req\.query\.hasOwnProperty is not a function/, done);
});

it('should be able to use object prototype property names as keys', function (done) {
var app = createApp('extended', true);

request(app)
.get('/?hasOwnProperty=yee')
.expect(200, '{"query":{"hasOwnProperty":"yee"},"error":"TypeError: req.query.hasOwnProperty is not a function"}', done);
});
});

describe('when "query parser" an unknown value', function () {
Expand All @@ -168,25 +91,15 @@ describe('req', function(){
})
})

function createApp(setting, isPrototypePropertyTest) {
function createApp(setting) {
var app = express();

if (setting !== undefined) {
app.set('query parser', setting);
}

app.use(function (req, res) {
if(isPrototypePropertyTest) {
try {
var hasOwnProperty = req.query.hasOwnProperty('✨ express ✨');
res.send({ query: req.query, hasOwnProperty: hasOwnProperty });
} catch (error) {
res.send({ query: req.query, error: error.toString() });
}
}
else {
res.send(req.query);
}
res.send(req.query);
});

return app;
Expand Down