fix: protect method names from token registration collisions - #359
fix: protect method names from token registration collisions#359baima365-web wants to merge 2 commits into
Conversation
Prevent token registration from overwriting module methods (token,
format, compile) by making them non-writable. Previously, calling
morgan.token('token', fn) would overwrite the morgan.token() method,
breaking subsequent token registrations.
Fixes expressjs#265
UlisesGascon
left a comment
There was a problem hiding this comment.
LGTM! WDYT @jonchurch @bjohansebas ?
bjohansebas
left a comment
There was a problem hiding this comment.
LGTM, should we add tests?
krzysdz
left a comment
There was a problem hiding this comment.
While this prevents accidentally overwriting important functions, there are still some rather unexpected behaviours:
- There is completely no information that the given token or format cannot be defined (this will become clear if someone tries to use it, but may be hard to debug).
- Formats and tokens can overwrite each other. While overwriting a token with a different token with the same name or overwriting a format with a different format using the same name (like I have previously suggested in #303 (comment), so #377 now depends on this behaviour) is something that IMO should be possible, format-token collisions should not happen.
Would it be a breaking change if formats and tokens were not defined directly as morgan properties, but instead lived separately as morgan.tokens and morgan.formats or something similar? This would allow using any names (no conflicts with the morgan functions) and get rid of collisions.
Lines 492 to 495 in 51007f9
Lines 579 to 582 in 51007f9
|
I think that #385 is a more solid approach but does not solve all the concerns from #359 (review). Also I am considering this as semver-minor based on #265 (comment) but maybe that requires a review or split between 1.x and 2.x goals |
Problem
Calling
morgan.token('token', fn)overwrites themorgan.token()method itself, breaking all subsequent token registrations. This is becausemorganserves as both the module export (with methodstoken,format,compile) and the token registry.Example:
Fix
Make the
token,format, andcompilemethods non-writable usingObject.defineProperties. This prevents user token registrations from overwriting the module API while maintaining full backward compatibility.Test plan