Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(core): Prevent prototype pollution on injectable services #6309

Merged
merged 1 commit into from
May 26, 2023

Conversation

netroy
Copy link
Member

@netroy netroy commented May 24, 2023

This helps prevent classes from being tampered by external-hooks or community nodes

@n8n-assistant n8n-assistant bot added the n8n team Authored by the n8n team label May 24, 2023
@codecov
Copy link

codecov bot commented May 24, 2023

Codecov Report

Patch and project coverage have no change.

Comparison is base (7a7b884) 27.66% compared to head (176733c) 27.66%.

Additional details and impacted files
@@           Coverage Diff           @@
##           master    #6309   +/-   ##
=======================================
  Coverage   27.66%   27.66%           
=======================================
  Files        2958     2958           
  Lines      181357   181357           
  Branches    19723    19724    +1     
=======================================
  Hits        50179    50179           
  Misses     130433   130433           
  Partials      745      745           

☔ View full report in Codecov by Sentry.
📢 Do you have feedback about the report comment? Let us know in this issue.

This helps prevent classes from being tampered by external-hooks or community nodes
@github-actions
Copy link
Contributor

✅ All Cypress E2E specs passed

@netroy netroy merged commit d94c20a into master May 26, 2023
22 checks passed
@netroy netroy deleted the tamper-proof-services branch May 26, 2023 16:03
csuermann pushed a commit that referenced this pull request May 26, 2023
This helps prevent classes from being tampered by external-hooks or community nodes
maspio pushed a commit that referenced this pull request May 30, 2023
This helps prevent classes from being tampered by external-hooks or community nodes
@janober
Copy link
Member

janober commented May 31, 2023

Got released with n8n@0.230.2

MiloradFilipovic added a commit that referenced this pull request Jun 1, 2023
* master: (54 commits)
  feat: Version control mvp (#6271)
  feat(editor): Implement Resource Mapper component (#6207)
  fix(editor): Update SSO settings styles (#6342)
  fix: Show `Ask AI` only on Code Node (#6336)
  feat(core): Add metadata (customdata) to event log (#6334)
  refactor: Add telemetry to upgrade paths (no-changelog) (#6313)
  fix(Code Node): Fix `item` and `items` alias regression (#6331)
  feat: Add manual login option and password reset link for SSO (#6328)
  fix(editor): Fix Luxon date parsing of ExecutionsUsage component (#6333)
  fix(core): Do not track errored workflow executions for automated executions (no-changelog) (#6322)
  fix(core): Prevent prototype pollution on injectable services (#6309)
  fix(core): Optimize getSharedWorkflowIds query (#6314)
  ci: Reset DB only once per e2e test (no-changelog) (#6216)
  feat(editor): Bring back checklist experiment (no-changelog) (#6307)
  fix: Add ldapts to nodes-base package (no-changelog) (#6315)
  fix(Code Node): Update vm2 to address CVE-2023-32313 (#6318)
  feat: Add tab visibility change detection when polling executions (no-changelog) (#6311)
  fix(editor): Fix locale plularisation if count is 0 (#6312)
  🚀 Release 0.230.0 (#6310)
  fix(Execute Command Node): Block executions when `command` is empty (#6308)
  ...
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
n8n team Authored by the n8n team Released
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants