Repository navigation
Object.assign / spread of http request object difference between v14.15.1 and v14.15.2 #36550
Description
Activity
As @ExE-Boss indicated here (#36023 (comment)), the
httprequest object must now be of a different inheritance level...Object.assignalso copies only own enumerable properties, but uses[[Set]]instead of[[Define]], so:const target = {}; Object.assign( target, JSON.parse(`{ "__proto__": null }`, );
results in
targethaving its prototype set tonullinstead of adding an own__proto__property, because of theObject.prototype.__proto__accessor.
Whereas:
const target = { ...(JSON.parse(`{ "__proto__": null }`)), };
Results in an object with an own
__proto__property set tonulland a prototype ofObject.prototype.This likely related to #35281.
Reacted by ExE BossThis is definitely caused by #35281.
I think a quick fix would be to do something like:
const dummyReq = { ...req, get headers() { return req.headers }, get trailers() { return req.trailers; } };
Reacted by ExE Boss, Ruben Stolk and Leandro HarukiYep, thanks for that! I have already implemented something similar.
- addedhttpIssues and PRs related to the http subsystem.Issues and PRs related to the http subsystem.confirmed-bugIssues and PRs for confirmed bugs.Issues and PRs for confirmed bugs.
on Dec 17, 2020 I'd just revert it in v14, not v15.
Reacted by Antoine du Hamel, ExE Boss and Igor SavinI agree with @mcollina that a revert in v14 would amke sense, and it would be good to get a release out.
Raised a revert PR for Node.js 14 (#36553). Hope to get this into a v14.15.3 very soon so that there are no barriers to adopting the upcoming security release on January 4th.
Reacted by ExE BossReacted by Richard Lau and Ruben StolkI've investigated this with a bit more detail, and I don't think it's a bug. I would recommend against using the spread operator on any stream. Nevertheless, this should be reverted in v14.x as it was probably a significant breaking change that slipped in a patch release.
Reacted by Robert Nagy, Ruben Stolk, ExE Boss and Igor Savin16 remaining items
- added 2 commits that reference this issue
on Dec 22, 2020 - added a commit that references this issue
on Dec 22, 2020 - added a commit that references this issue
on Dec 25, 2020 - added a commit that references this issue
on Jan 12, 2021 - added 2 commits that reference this issue
on Dec 12, 2023 - added a commit that references this issue
on May 13, 2026
What steps will reproduce the bug?
While trying to create a cloned version of an http request object, prototype properties/methods such as
headersandgetget lost.What is the expected behavior?
I honestly don't know if the behavior from 14.15.1 or from 14.15.2 is expected.
Behavior until 14.15.1:
dummyReq.headersis notundefined.What do you see instead?
Output in 14.15.2:
dummyReq.headersisundefined.Additional info
The same happens while using
Object.assign