Repository navigation
Commit 99af3fc
authored
Merge commit from fork
* fix(architecture): handle arbitrary prototype pollution
Update the `ArchitectureGroupAlignments` to use a
`Map<`${string}-${string},` instead of being a
`Record<string, Record<string,`. Not only does this make the code
simpler, but it also means we avoid arbritary prototype pollution
attacks.
Fixes: GHSA-3rrr-jr9j-h3q3
Fixes: cb0a470
* refactor(architecture): use `Map` for registeredIds
* fix(architecture): improve group ID handling
`__proto__`, `constructor`, `toString`, etc. can now be used as a group ID in
architecture diagrams.
* refactor(architecture): use Map for nodes in DB
* refactor(architecture): use Map for spatial maps
* refactor(architecture): use `Set` for visit record
* refactor(architecture): use Map for `adjList`
* refactor(architecture): use Map for elements storage
* refactor(architecture): use Map for alignments
* test(architecture): test for service ID sorting
The old code sorted services by their ID using object iteration order,
which would sort numeric keys before string keys.
Now they are sorted in insertion order, so you can change around the
order of `service` statements in your diagram.
* test(architecture): test for GHSA-3rrr-jr9j-h3q3
Add a modified test to confirm that the prototype pollution in
GHSA-3rrr-jr9j-h3q3 is no longer exploitable.1 parent 2337f7e commit 99af3fc
6 files changed
Lines changed: 232 additions & 168 deletions
File tree
- .changeset
- .cspell
- packages/mermaid/src/diagrams/architecture
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
| 5 | + | |
5 | 6 | | |
6 | 7 | | |
7 | 8 | | |
| |||
Lines changed: 45 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
195 | 195 | | |
196 | 196 | | |
197 | 197 | | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
| 203 | + | |
| 204 | + | |
| 205 | + | |
| 206 | + | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
| 212 | + | |
| 213 | + | |
| 214 | + | |
| 215 | + | |
| 216 | + | |
| 217 | + | |
| 218 | + | |
| 219 | + | |
| 220 | + | |
| 221 | + | |
| 222 | + | |
| 223 | + | |
| 224 | + | |
| 225 | + | |
| 226 | + | |
| 227 | + | |
| 228 | + | |
| 229 | + | |
| 230 | + | |
| 231 | + | |
| 232 | + | |
| 233 | + | |
| 234 | + | |
| 235 | + | |
| 236 | + | |
| 237 | + | |
| 238 | + | |
| 239 | + | |
| 240 | + | |
| 241 | + | |
| 242 | + | |
198 | 243 | | |
199 | 244 | | |
200 | 245 | | |
| |||
0 commit comments