Repository navigation
Version 3.1.0 is not working in React-Native when is not in debugging mode or when is generating release #87
Description
Activity
I'm not familiar with React Native, but as the error message says, you need
crypto.randomBytes(for Node.js) orCrypto.getRandomValues(for browsers). If you can apply something like the crypto pollyfill libs for React Native it might work well.I tried to find something like this but I've no success. Idk how to fix this.
I also bumped into this issue.
It happens because of the following single line (and the dependency on
randombyteslibrary, introduced by it):
Line 38 in 05a3224
var bytes = randomBytes(UID_LENGTH); This comes from this commit: f21a6fb
I don't really understand, why random UUIDs are necessary during JS serialization. Lazy to dig in too deep, but my guess is that original implementation just cut some corners, and used in-place UID instead of building a separate index of transformed entities, thus the correct fix of the problem should be not relying on a more randomized UUID, but re-writing the algo to not use UUIDs at all.
The working workaround for RN is to shim
randombyteswith https://www.npmjs.com/package/react-native-randombytes, but it requires some efforts to setup, and alias therandombytesfor 3-rd party packages.Reacted by DomiTo add to @birdofpreyru 's analysis:
- Problem in
randombytes: Missingnodesupport
The actual issue comes fromrandombytesnot supporting node. It determines the "old browser" label (which will always throw) in browser.js:It could be that we come across this issue not because this library does not supportif (crypto && crypto.getRandomValues) { module.exports = randomBytes } else { module.exports = oldBrowser }
node, but because there might be an issue in your build setup, as explained below. - Why is a random UID necessary?
It is used byserialize-javascriptonly once during initialization here, evidently for security reasons. - Simple, node-only workaround
Put this code anywhere at the very beginning of your code:import nodeCrypto from 'crypto'; // const nodeCrypto = __non_webpack_require__('crypto'); // use this instead, if you are working on a Webpack@4 `umd` build /** * @see https://github.com/yahoo/serialize-javascript/issues/87 */ (function hackfixes() { // eslint-disable-next-line global-require if (!globalThis.crypto) { globalThis.crypto = {}; } if (!globalThis.crypto.getRandomValues) { globalThis.crypto.getRandomValues = (buf) => { const bytes = nodeCrypto.randomBytes(buf.length); buf.set(bytes); return buf; }; } })();
- Portable workaround
As pointed out here, you can use the get-random-values polyfill. The annoying part is that it would be quite hacky to tellrandombytesto use that. - NOTE: I'm using Webpack@4 to produce a
umdbuild, and webpack@4 is not very good at that. This often translates it to Webpack deciding to use browser-only shims.
- Problem in
Why is a random UID necessary?
It is used by serialize-javascript only once during initialization here, evidently for security reasons.
I had a second brief look at the code, and it still looks to me like a lame implementation rather than a security feature:
UIDis only used inside temporary placeholders during stringification, and there is noUIDincluded into stringified result. In my current understanding, if here:instead of writing out indices of detected (extracted into auxiliary arrays) functions / objects into intermediate string as text, one would bother to index them in a better way (say, having a separate mapping object saying for each extracted function / object at which location in the output string it should be inserted in the end), it would not be necessary to use any UID.Lines 94 to 117 in 45fb0f1
if (type === 'object') { if(origValue instanceof RegExp) { return '@__R-' + UID + '-' + (regexps.push(origValue) - 1) + '__@'; } if(origValue instanceof Date) { return '@__D-' + UID + '-' + (dates.push(origValue) - 1) + '__@'; } if(origValue instanceof Map) { return '@__M-' + UID + '-' + (maps.push(origValue) - 1) + '__@'; } if(origValue instanceof Set) { return '@__S-' + UID + '-' + (sets.push(origValue) - 1) + '__@'; } if(origValue instanceof Array) { var isSparse = origValue.filter(function(){return true}).length !== origValue.length; if (isSparse) { return '@__A-' + UID + '-' + (arrays.push(origValue) - 1) + '__@'; } } } Why didn't you close this issue? it's for version 3.x
@amerllica The code in question, thus the issue, is still present in the current version v6.0.0.
Hello, I'm using serialize-javascript in React-Native instead of JSON.stringify function. The version 3.1.0 is not working in React-Native when the debugger is off or in the release apk (because there is no debugger).
The issue is:
Error: Secure random number generation is not supported by this browser. Use Chrome, Firefox or Internet Explorer 11.
Reproduce:
My set is:
Running app in simulators:
Chrome version:
The previous version (3.0.0) working well. There are a prevision/way to fix this to work without debugger?