Repository navigation
Fix a markup parser crash when a tag name shadows hasOwnProperty - #9468
Conversation
The markup parser stores tag names as keys on plain objects, then calls `.hasOwnProperty` on those objects while merging. A tag named `[hasOwnProperty]` shadows the method and the parser throws a TypeError. Call `Object.prototype.hasOwnProperty` directly instead. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Build size reportThis PR changes the size of the minified bundles.
|
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The change is minimal, targeted to the reported failure mode, and is backed by regression tests covering the crash scenario.
Review effort: Lite
Findings: 1
What changed in this PR
This pull request fixes a crash in the Element markup parser when a user-defined tag name shadows Object.prototype.hasOwnProperty (e.g. [hasOwnProperty]...[/hasOwnProperty]). It does so by switching internal own-property checks to Object.prototype.hasOwnProperty.call(...) (via a module-level hasOwn reference) and adds a focused unit test suite covering the shadowing case and a __proto__ non-pollution check.
Changes:
- Replace direct
.hasOwnProperty(...)calls inmarkup.jswithhasOwn.call(obj, key)to avoid shadowing crashes. - Add
Markupunit tests for tag-stripping and for handling ahasOwnPropertytag name without throwing. - Add a regression test ensuring
__proto__tags do not polluteObject.prototype.
| File | Description |
|---|---|
| src/framework/components/element/markup.js | Hardens internal merging/edge-building logic against hasOwnProperty shadowing by using hasOwn.call(...). |
| test/framework/components/element/markup.test.mjs | Adds unit coverage for the reported crash scenario and a __proto__ non-pollution regression check. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Exercises the target-side own-property check in the markup merge helper. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

Fixes the crash reported in #8578 with the minimal change.
The markup parser stores tag names as keys on plain objects and then calls
.hasOwnPropertyon those same objects while merging overlapping tags. A text element withenableMarkupset and text containing a tag namedhasOwnPropertyshadows the method and the parser throws:This replaces the four method calls in
markup.jswithObject.prototype.hasOwnProperty.call(...)via a module-levelhasOwnconstant, and adds aMarkuptest file that covers the shadowing case and confirmsObject.prototypeis not polluted by a[__proto__]tag. The shadowing tests fail against the unmodified parser and pass with the change.Unlike #8578, this does not touch the core
extendutility or its merge semantics. The[__proto__]case was never a pollution vector: the tag is silently dropped both before and after this change.🤖 Generated with Claude Code