Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Next Next commit
Revert "sec: security patch for CVE-2024-51999"
This reverts commit 6e97452.
  • Loading branch information
UlisesGascon committed Dec 1, 2025
commit 88970ec6e25fca466d22d45a9aa266aeb79f27d7
2 changes: 1 addition & 1 deletion lib/utils.js
Original file line number Diff line number Diff line change
Expand Up @@ -287,7 +287,7 @@ function createETagGenerator (options) {

function parseExtendedQueryString(str) {
return qs.parse(str, {
plainObjects: true
allowPrototypes: true
});
}

Expand Down
107 changes: 2 additions & 105 deletions test/req.query.js
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,6 @@
var assert = require('assert')
var express = require('../')
, request = require('supertest');
var qs = require('qs');

describe('req', function(){
describe('.query', function(){
Expand Down Expand Up @@ -39,22 +38,6 @@ describe('req', function(){
.get('/?user.name=tj')
.expect(200, '{"user.name":"tj"}', done);
});

it('should not be able to access object prototype properties', function (done) {
var app = createApp('extended', true);

request(app)
.get('/?foo=yee')
.expect(200, /TypeError: req\.query\.hasOwnProperty is not a function/, done);
});

it('should be able to use object prototype property names as keys', function (done) {
var app = createApp('extended', true);

request(app)
.get('/?hasOwnProperty=yee')
.expect(200, '{"query":{"hasOwnProperty":"yee"},"error":"TypeError: req.query.hasOwnProperty is not a function"}', done);
});
});

describe('when "query parser" is simple', function () {
Expand All @@ -65,22 +48,6 @@ describe('req', function(){
.get('/?user%5Bname%5D=tj')
.expect(200, '{"user[name]":"tj"}', done);
});

it('should not be able to access object prototype properties', function (done) {
var app = createApp('simple', true);

request(app)
.get('/?foo=yee')
.expect(200, /TypeError: req\.query\.hasOwnProperty is not a function/, done);
});

it('should be able to use object prototype property names as keys', function (done) {
var app = createApp('simple', true);

request(app)
.get('/?hasOwnProperty=yee')
.expect(200, '{"query":{"hasOwnProperty":"yee"},"error":"TypeError: req.query.hasOwnProperty is not a function"}', done);
});
});

describe('when "query parser" is a function', function () {
Expand All @@ -93,18 +60,6 @@ describe('req', function(){
.get('/?user%5Bname%5D=tj')
.expect(200, '{"length":17}', done);
});

// test exists to verify behavior for folks wishing to workaround our qs defaults
it('should drop object prototype property names and be able to access object prototype properties', function (done) {
var app = createApp(
function (str) {
return qs.parse(str)
}, true);

request(app)
.get('/?hasOwnProperty=biscuits')
.expect(200, '{"query":{},"hasOwnProperty":false}', done);
});
});

describe('when "query parser" disabled', function () {
Expand All @@ -115,22 +70,6 @@ describe('req', function(){
.get('/?user%5Bname%5D=tj')
.expect(200, '{}', done);
});

it('should not be able to access object prototype properties', function (done) {
var app = createApp('extended', true);

request(app)
.get('/?foo=yee')
.expect(200, /TypeError: req\.query\.hasOwnProperty is not a function/, done);
});

it('should be able to use object prototype property names as keys', function (done) {
var app = createApp('extended', true);

request(app)
.get('/?hasOwnProperty=yee')
.expect(200, '{"query":{"hasOwnProperty":"yee"},"error":"TypeError: req.query.hasOwnProperty is not a function"}', done);
});
});

describe('when "query parser" enabled', function () {
Expand All @@ -141,22 +80,6 @@ describe('req', function(){
.get('/?user%5Bname%5D=tj')
.expect(200, '{"user[name]":"tj"}', done);
});

it('should not be able to access object prototype properties', function (done) {
var app = createApp('extended', true);

request(app)
.get('/?foo=yee')
.expect(200, /TypeError: req\.query\.hasOwnProperty is not a function/, done);
});

it('should be able to use object prototype property names as keys', function (done) {
var app = createApp('extended', true);

request(app)
.get('/?hasOwnProperty=yee')
.expect(200, '{"query":{"hasOwnProperty":"yee"},"error":"TypeError: req.query.hasOwnProperty is not a function"}', done);
});
});

describe('when "query parser fn" is missing', function () {
Expand All @@ -174,22 +97,6 @@ describe('req', function(){
.get('/?user[name]=tj&user.name=tj')
.expect(200, '{"user":{"name":"tj"},"user.name":"tj"}', done);
});

it('should not be able to access object prototype properties', function (done) {
var app = createApp('extended', true);

request(app)
.get('/?foo=yee')
.expect(200, /TypeError: req\.query\.hasOwnProperty is not a function/, done);
});

it('should be able to use object prototype property names as keys', function (done) {
var app = createApp('extended', true);

request(app)
.get('/?hasOwnProperty=yee')
.expect(200, '{"query":{"hasOwnProperty":"yee"},"error":"TypeError: req.query.hasOwnProperty is not a function"}', done);
});
});

describe('when "query parser" an unknown value', function () {
Expand All @@ -201,25 +108,15 @@ describe('req', function(){
})
})

function createApp(setting, isPrototypePropertyTest) {
function createApp(setting) {
var app = express();

if (setting !== undefined) {
app.set('query parser', setting);
}

app.use(function (req, res) {
if(isPrototypePropertyTest) {
try {
var hasOwnProperty = req.query.hasOwnProperty('✨ express ✨');
res.send({ query: req.query, hasOwnProperty: hasOwnProperty });
} catch (error) {
res.send({ query: req.query, error: error.toString() });
}
}
else {
res.send(req.query);
}
res.send(req.query);
});

return app;
Expand Down