chore: initial clean commit without large binaries
This commit is contained in:
Generated
Vendored
+27
@@ -0,0 +1,27 @@
|
||||
Copyright 2014 Yahoo! Inc.
|
||||
All rights reserved.
|
||||
|
||||
Redistribution and use in source and binary forms, with or without
|
||||
modification, are permitted provided that the following conditions are met:
|
||||
|
||||
* Redistributions of source code must retain the above copyright
|
||||
notice, this list of conditions and the following disclaimer.
|
||||
|
||||
* Redistributions in binary form must reproduce the above copyright
|
||||
notice, this list of conditions and the following disclaimer in the
|
||||
documentation and/or other materials provided with the distribution.
|
||||
|
||||
* Neither the name of the Yahoo! Inc. nor the
|
||||
names of its contributors may be used to endorse or promote products
|
||||
derived from this software without specific prior written permission.
|
||||
|
||||
THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND
|
||||
ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
|
||||
WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
|
||||
DISCLAIMED. IN NO EVENT SHALL YAHOO! INC. BE LIABLE FOR ANY
|
||||
DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
|
||||
(INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
|
||||
LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND
|
||||
ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
|
||||
(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
|
||||
SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
|
||||
Generated
Vendored
+149
@@ -0,0 +1,149 @@
|
||||
Serialize JavaScript
|
||||
====================
|
||||
|
||||
Serialize JavaScript to a _superset_ of JSON that includes regular expressions, dates and functions.
|
||||
|
||||
[![npm Version][npm-badge]][npm]
|
||||

|
||||
|
||||
## Overview
|
||||
|
||||
The code in this package began its life as an internal module to [express-state][]. To expand its usefulness, it now lives as `serialize-javascript` — an independent package on npm.
|
||||
|
||||
You're probably wondering: **What about `JSON.stringify()`!?** We've found that sometimes we need to serialize JavaScript **functions**, **regexps**, **dates**, **sets** or **maps**. A great example is a web app that uses client-side URL routing where the route definitions are regexps that need to be shared from the server to the client.
|
||||
|
||||
The string returned from this package's single export function is literal JavaScript which can be saved to a `.js` file, or be embedded into an HTML document by making the content of a `<script>` element.
|
||||
|
||||
> **HTML characters and JavaScript line terminators are escaped automatically.**
|
||||
|
||||
Please note that serialization for ES6 Sets & Maps requires support for `Array.from` (not available in IE or Node < 0.12), or an `Array.from` polyfill.
|
||||
|
||||
> [!WARNING]
|
||||
> It may be tempting to use this package as a way to pass arbitrary functions into [worker threads][], since you cannot pass them directly via `postMessage()`. However, passing functions between worker threads is not possible in the general case. This package lets you serialize *some* functions, but it has limitations.
|
||||
>
|
||||
> For instance, if a function references something from outside the function body, it will not run properly if serialized and deserialized. This could include [closed-over variables][] or imports from other packages. For a serialized function to run properly, it must be entirely self-contained.
|
||||
>
|
||||
> In general, it is not possible to send arbitrary JavaScript to a worker thread, and pretend it's running the same way it would run on the main thread. This package doesn't let you do that.
|
||||
|
||||
## Installation
|
||||
|
||||
Install using npm:
|
||||
|
||||
```shell
|
||||
$ npm install serialize-javascript
|
||||
```
|
||||
|
||||
## Usage
|
||||
|
||||
```js
|
||||
var serialize = require('serialize-javascript');
|
||||
|
||||
serialize({
|
||||
str : 'string',
|
||||
num : 0,
|
||||
obj : {foo: 'foo'},
|
||||
arr : [1, 2, 3],
|
||||
bool : true,
|
||||
nil : null,
|
||||
undef: undefined,
|
||||
inf : Infinity,
|
||||
date : new Date("Thu, 28 Apr 2016 22:02:17 GMT"),
|
||||
map : new Map([['hello', 'world']]),
|
||||
set : new Set([123, 456]),
|
||||
fn : function echo(arg) { return arg; },
|
||||
re : /([^\s]+)/g,
|
||||
big : BigInt(10),
|
||||
url : new URL('https://example.com/'),
|
||||
});
|
||||
```
|
||||
|
||||
The above will produce the following string output:
|
||||
|
||||
```js
|
||||
'{"str":"string","num":0,"obj":{"foo":"foo"},"arr":[1,2,3],"bool":true,"nil":null,"undef":undefined,"inf":Infinity,"date":new Date("2016-04-28T22:02:17.000Z"),"map":new Map([["hello","world"]]),"set":new Set([123,456]),"fn":function echo(arg) { return arg; },"re":new RegExp("([^\\\\s]+)", "g"),"big":BigInt("10"),"url":new URL("https://example.com/")}'
|
||||
```
|
||||
|
||||
Note: to produce a beautified string, you can pass an optional second argument to `serialize()` to define the number of spaces to be used for the indentation.
|
||||
|
||||
### Automatic Escaping of HTML Characters
|
||||
|
||||
A primary feature of this package is to serialize code to a string of literal JavaScript which can be embedded in an HTML document by adding it as the contents of the `<script>` element. In order to make this safe, HTML characters and JavaScript line terminators are escaped automatically.
|
||||
|
||||
```js
|
||||
serialize({
|
||||
haxorXSS: '</script>'
|
||||
});
|
||||
```
|
||||
|
||||
The above will produce the following string, HTML-escaped output which is safe to put into an HTML document as it will not cause the inline script element to terminate:
|
||||
|
||||
```js
|
||||
'{"haxorXSS":"\\u003C\\u002Fscript\\u003E"}'
|
||||
```
|
||||
|
||||
> You can pass an optional `unsafe` argument to `serialize()` for straight serialization.
|
||||
|
||||
### Options
|
||||
|
||||
The `serialize()` function accepts an `options` object as its second argument. All options are being defaulted to `undefined`:
|
||||
|
||||
#### `options.space`
|
||||
|
||||
This option is the same as the `space` argument that can be passed to [`JSON.stringify`][JSON.stringify]. It can be used to add whitespace and indentation to the serialized output to make it more readable.
|
||||
|
||||
```js
|
||||
serialize(obj, {space: 2});
|
||||
```
|
||||
|
||||
#### `options.isJSON`
|
||||
|
||||
This option is a signal to `serialize()` that the object being serialized does not contain any function or regexps values. This enables a hot-path that allows serialization to be over 3x faster. If you're serializing a lot of data, and know its pure JSON, then you can enable this option for a speed-up.
|
||||
|
||||
**Note:** That when using this option, the output will still be escaped to protect against XSS.
|
||||
|
||||
```js
|
||||
serialize(obj, {isJSON: true});
|
||||
```
|
||||
|
||||
#### `options.unsafe`
|
||||
|
||||
This option is to signal `serialize()` that we want to do a straight conversion, without the XSS protection. This options needs to be explicitly set to `true`. HTML characters and JavaScript line terminators will not be escaped. You will have to roll your own.
|
||||
|
||||
```js
|
||||
serialize(obj, {unsafe: true});
|
||||
```
|
||||
|
||||
#### `options.ignoreFunction`
|
||||
|
||||
This option is to signal `serialize()` that we do not want serialize JavaScript function.
|
||||
Just treat function like `JSON.stringify` do, but other features will work as expected.
|
||||
|
||||
```js
|
||||
serialize(obj, {ignoreFunction: true});
|
||||
```
|
||||
|
||||
## Deserializing
|
||||
|
||||
For some use cases you might also need to deserialize the string. This is explicitly not part of this module. However, you can easily write it yourself:
|
||||
|
||||
```js
|
||||
function deserialize(serializedJavascript){
|
||||
return eval('(' + serializedJavascript + ')');
|
||||
}
|
||||
```
|
||||
|
||||
**Note:** Don't forget the parentheses around the serialized javascript, as the opening bracket `{` will be considered to be the start of a body.
|
||||
|
||||
## License
|
||||
|
||||
This software is free to use under the Yahoo! Inc. BSD license.
|
||||
See the [LICENSE file][LICENSE] for license text and copyright information.
|
||||
|
||||
|
||||
[npm]: https://www.npmjs.org/package/serialize-javascript
|
||||
[npm-badge]: https://img.shields.io/npm/v/serialize-javascript.svg?style=flat-square
|
||||
[express-state]: https://github.com/yahoo/express-state
|
||||
[JSON.stringify]: https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/JSON/stringify
|
||||
[LICENSE]: https://github.com/yahoo/serialize-javascript/blob/main/LICENSE
|
||||
[worker threads]: https://nodejs.org/api/worker_threads.html
|
||||
[closed-over variables]: https://developer.mozilla.org/en-US/docs/Web/JavaScript/Guide/Closures
|
||||
Generated
Vendored
+297
@@ -0,0 +1,297 @@
|
||||
/*
|
||||
Copyright (c) 2014, Yahoo! Inc. All rights reserved.
|
||||
Copyrights licensed under the New BSD License.
|
||||
See the accompanying LICENSE file for terms.
|
||||
*/
|
||||
|
||||
'use strict';
|
||||
|
||||
// Generate an internal UID to make the regexp pattern harder to guess.
|
||||
var UID_LENGTH = 16;
|
||||
var UID = generateUID();
|
||||
var PLACE_HOLDER_REGEXP = new RegExp('(\\\\)?"@__(F|R|D|M|S|A|U|I|B|L)-' + UID + '-(\\d+)__@"', 'g');
|
||||
|
||||
var IS_NATIVE_CODE_REGEXP = /\{\s*\[native code\]\s*\}/g;
|
||||
var IS_PURE_FUNCTION = /function.*?\(/;
|
||||
var IS_ARROW_FUNCTION = /.*?=>.*?/;
|
||||
var UNSAFE_CHARS_REGEXP = /[<>\/\u2028\u2029]/g;
|
||||
// Regex to match </script> and variations (case-insensitive) for XSS protection
|
||||
// Matches </script followed by optional whitespace/attributes and >
|
||||
var SCRIPT_CLOSE_REGEXP = /<\/script[^>]*>/gi;
|
||||
|
||||
var RESERVED_SYMBOLS = ['*', 'async'];
|
||||
|
||||
// Mapping of unsafe HTML and invalid JavaScript line terminator chars to their
|
||||
// Unicode char counterparts which are safe to use in JavaScript strings.
|
||||
var ESCAPED_CHARS = {
|
||||
'<' : '\\u003C',
|
||||
'>' : '\\u003E',
|
||||
'/' : '\\u002F',
|
||||
'\u2028': '\\u2028',
|
||||
'\u2029': '\\u2029'
|
||||
};
|
||||
|
||||
function escapeUnsafeChars(unsafeChar) {
|
||||
return ESCAPED_CHARS[unsafeChar];
|
||||
}
|
||||
|
||||
// Escape function body for XSS protection while preserving arrow function syntax
|
||||
function escapeFunctionBody(str) {
|
||||
// Escape </script> sequences and variations (case-insensitive) - the main XSS risk
|
||||
// Matches </script followed by optional whitespace/attributes and >
|
||||
// This must be done first before other replacements
|
||||
str = str.replace(SCRIPT_CLOSE_REGEXP, function(match) {
|
||||
// Escape all <, /, and > characters in the closing script tag
|
||||
return match.replace(/</g, '\\u003C').replace(/\//g, '\\u002F').replace(/>/g, '\\u003E');
|
||||
});
|
||||
// Escape line terminators (these are always unsafe)
|
||||
str = str.replace(/\u2028/g, '\\u2028');
|
||||
str = str.replace(/\u2029/g, '\\u2029');
|
||||
return str;
|
||||
}
|
||||
|
||||
function generateUID() {
|
||||
var bytes = crypto.getRandomValues(new Uint8Array(UID_LENGTH));
|
||||
var result = '';
|
||||
for(var i=0; i<UID_LENGTH; ++i) {
|
||||
result += bytes[i].toString(16);
|
||||
}
|
||||
return result;
|
||||
}
|
||||
|
||||
function deleteFunctions(obj){
|
||||
var functionKeys = [];
|
||||
for (var key in obj) {
|
||||
if (typeof obj[key] === "function") {
|
||||
functionKeys.push(key);
|
||||
}
|
||||
}
|
||||
for (var i = 0; i < functionKeys.length; i++) {
|
||||
delete obj[functionKeys[i]];
|
||||
}
|
||||
}
|
||||
|
||||
module.exports = function serialize(obj, options) {
|
||||
options || (options = {});
|
||||
|
||||
// Backwards-compatibility for `space` as the second argument.
|
||||
if (typeof options === 'number' || typeof options === 'string') {
|
||||
options = {space: options};
|
||||
}
|
||||
|
||||
var functions = [];
|
||||
var regexps = [];
|
||||
var dates = [];
|
||||
var maps = [];
|
||||
var sets = [];
|
||||
var arrays = [];
|
||||
var undefs = [];
|
||||
var infinities= [];
|
||||
var bigInts = [];
|
||||
var urls = [];
|
||||
|
||||
// Returns placeholders for functions and regexps (identified by index)
|
||||
// which are later replaced by their string representation.
|
||||
function replacer(key, value) {
|
||||
|
||||
// For nested function
|
||||
if(options.ignoreFunction){
|
||||
deleteFunctions(value);
|
||||
}
|
||||
|
||||
if (!value && value !== undefined && value !== BigInt(0)) {
|
||||
return value;
|
||||
}
|
||||
|
||||
// If the value is an object w/ a toJSON method, toJSON is called before
|
||||
// the replacer runs, so we use this[key] to get the non-toJSONed value.
|
||||
var origValue = this[key];
|
||||
var type = typeof origValue;
|
||||
|
||||
if (type === 'object') {
|
||||
if(origValue instanceof RegExp) {
|
||||
return '@__R-' + UID + '-' + (regexps.push(origValue) - 1) + '__@';
|
||||
}
|
||||
|
||||
if(origValue instanceof Date) {
|
||||
return '@__D-' + UID + '-' + (dates.push(origValue) - 1) + '__@';
|
||||
}
|
||||
|
||||
if(origValue instanceof Map) {
|
||||
return '@__M-' + UID + '-' + (maps.push(origValue) - 1) + '__@';
|
||||
}
|
||||
|
||||
if(origValue instanceof Set) {
|
||||
return '@__S-' + UID + '-' + (sets.push(origValue) - 1) + '__@';
|
||||
}
|
||||
|
||||
if(Array.isArray(origValue)) {
|
||||
var isSparse = Object.keys(origValue).length !== origValue.length;
|
||||
if (isSparse) {
|
||||
return '@__A-' + UID + '-' + (arrays.push(origValue) - 1) + '__@';
|
||||
}
|
||||
}
|
||||
|
||||
if(origValue instanceof URL) {
|
||||
return '@__L-' + UID + '-' + (urls.push(origValue) - 1) + '__@';
|
||||
}
|
||||
}
|
||||
|
||||
if (type === 'function') {
|
||||
return '@__F-' + UID + '-' + (functions.push(origValue) - 1) + '__@';
|
||||
}
|
||||
|
||||
if (type === 'undefined') {
|
||||
return '@__U-' + UID + '-' + (undefs.push(origValue) - 1) + '__@';
|
||||
}
|
||||
|
||||
if (type === 'number' && !isNaN(origValue) && !isFinite(origValue)) {
|
||||
return '@__I-' + UID + '-' + (infinities.push(origValue) - 1) + '__@';
|
||||
}
|
||||
|
||||
if (type === 'bigint') {
|
||||
return '@__B-' + UID + '-' + (bigInts.push(origValue) - 1) + '__@';
|
||||
}
|
||||
|
||||
return value;
|
||||
}
|
||||
|
||||
function serializeFunc(fn, options) {
|
||||
var serializedFn = fn.toString();
|
||||
if (IS_NATIVE_CODE_REGEXP.test(serializedFn)) {
|
||||
throw new TypeError('Serializing native function: ' + fn.name);
|
||||
}
|
||||
|
||||
// Escape unsafe HTML characters in function body for XSS protection
|
||||
// This must preserve arrow function syntax (=>) while escaping </script>
|
||||
if (options && options.unsafe !== true) {
|
||||
serializedFn = escapeFunctionBody(serializedFn);
|
||||
}
|
||||
|
||||
// pure functions, example: {key: function() {}}
|
||||
if(IS_PURE_FUNCTION.test(serializedFn)) {
|
||||
return serializedFn;
|
||||
}
|
||||
|
||||
// arrow functions, example: arg1 => arg1+5
|
||||
if(IS_ARROW_FUNCTION.test(serializedFn)) {
|
||||
return serializedFn;
|
||||
}
|
||||
|
||||
var argsStartsAt = serializedFn.indexOf('(');
|
||||
var def = serializedFn.substr(0, argsStartsAt)
|
||||
.trim()
|
||||
.split(' ')
|
||||
.filter(function(val) { return val.length > 0 });
|
||||
|
||||
var nonReservedSymbols = def.filter(function(val) {
|
||||
return RESERVED_SYMBOLS.indexOf(val) === -1
|
||||
});
|
||||
|
||||
// enhanced literal objects, example: {key() {}}
|
||||
if(nonReservedSymbols.length > 0) {
|
||||
return (def.indexOf('async') > -1 ? 'async ' : '') + 'function'
|
||||
+ (def.join('').indexOf('*') > -1 ? '*' : '')
|
||||
+ serializedFn.substr(argsStartsAt);
|
||||
}
|
||||
|
||||
// arrow functions
|
||||
return serializedFn;
|
||||
}
|
||||
|
||||
// Check if the parameter is function
|
||||
if (options.ignoreFunction && typeof obj === "function") {
|
||||
obj = undefined;
|
||||
}
|
||||
// Protects against `JSON.stringify()` returning `undefined`, by serializing
|
||||
// to the literal string: "undefined".
|
||||
if (obj === undefined) {
|
||||
return String(obj);
|
||||
}
|
||||
|
||||
var str;
|
||||
|
||||
// Creates a JSON string representation of the value.
|
||||
// NOTE: Node 0.12 goes into slow mode with extra JSON.stringify() args.
|
||||
if (options.isJSON && !options.space) {
|
||||
str = JSON.stringify(obj);
|
||||
} else {
|
||||
str = JSON.stringify(obj, options.isJSON ? null : replacer, options.space);
|
||||
}
|
||||
|
||||
// Protects against `JSON.stringify()` returning `undefined`, by serializing
|
||||
// to the literal string: "undefined".
|
||||
if (typeof str !== 'string') {
|
||||
return String(str);
|
||||
}
|
||||
|
||||
// Replace unsafe HTML and invalid JavaScript line terminator chars with
|
||||
// their safe Unicode char counterpart. This _must_ happen before the
|
||||
// regexps and functions are serialized and added back to the string.
|
||||
if (options.unsafe !== true) {
|
||||
str = str.replace(UNSAFE_CHARS_REGEXP, escapeUnsafeChars);
|
||||
}
|
||||
|
||||
if (functions.length === 0 && regexps.length === 0 && dates.length === 0 && maps.length === 0 && sets.length === 0 && arrays.length === 0 && undefs.length === 0 && infinities.length === 0 && bigInts.length === 0 && urls.length === 0) {
|
||||
return str;
|
||||
}
|
||||
|
||||
// Replaces all occurrences of function, regexp, date, map and set placeholders in the
|
||||
// JSON string with their string representations. If the original value can
|
||||
// not be found, then `undefined` is used.
|
||||
return str.replace(PLACE_HOLDER_REGEXP, function (match, backSlash, type, valueIndex) {
|
||||
// The placeholder may not be preceded by a backslash. This is to prevent
|
||||
// replacing things like `"a\"@__R-<UID>-0__@"` and thus outputting
|
||||
// invalid JS.
|
||||
if (backSlash) {
|
||||
return match;
|
||||
}
|
||||
|
||||
if (type === 'D') {
|
||||
// Validate ISO string format to prevent code injection via spoofed toISOString()
|
||||
var isoStr = String(dates[valueIndex].toISOString());
|
||||
if (!/^\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}(\.\d{3})?Z$/.test(isoStr)) {
|
||||
throw new TypeError('Invalid Date ISO string');
|
||||
}
|
||||
return "new Date(\"" + isoStr + "\")";
|
||||
}
|
||||
|
||||
if (type === 'R') {
|
||||
// Sanitize flags to prevent code injection (only allow valid RegExp flag characters)
|
||||
var flags = String(regexps[valueIndex].flags).replace(/[^gimsuydv]/g, '');
|
||||
return "new RegExp(" + serialize(regexps[valueIndex].source) + ", \"" + flags + "\")";
|
||||
}
|
||||
|
||||
if (type === 'M') {
|
||||
return "new Map(" + serialize(Array.from(maps[valueIndex].entries()), options) + ")";
|
||||
}
|
||||
|
||||
if (type === 'S') {
|
||||
return "new Set(" + serialize(Array.from(sets[valueIndex].values()), options) + ")";
|
||||
}
|
||||
|
||||
if (type === 'A') {
|
||||
return "Array.prototype.slice.call(" + serialize(Object.assign({ length: arrays[valueIndex].length }, arrays[valueIndex]), options) + ")";
|
||||
}
|
||||
|
||||
if (type === 'U') {
|
||||
return 'undefined'
|
||||
}
|
||||
|
||||
if (type === 'I') {
|
||||
return infinities[valueIndex];
|
||||
}
|
||||
|
||||
if (type === 'B') {
|
||||
return "BigInt(\"" + bigInts[valueIndex] + "\")";
|
||||
}
|
||||
|
||||
if (type === 'L') {
|
||||
return "new URL(" + serialize(urls[valueIndex].toString(), options) + ")";
|
||||
}
|
||||
|
||||
var fn = functions[valueIndex];
|
||||
|
||||
return serializeFunc(fn, options);
|
||||
});
|
||||
}
|
||||
Generated
Vendored
+33
@@ -0,0 +1,33 @@
|
||||
{
|
||||
"name": "serialize-javascript",
|
||||
"version": "7.0.5",
|
||||
"description": "Serialize JavaScript to a superset of JSON that includes regular expressions and functions.",
|
||||
"main": "index.js",
|
||||
"scripts": {
|
||||
"benchmark": "node -v && node test/benchmark/serialize.js",
|
||||
"test": "node --test test/unit/*.js"
|
||||
},
|
||||
"repository": {
|
||||
"type": "git",
|
||||
"url": "git+https://github.com/yahoo/serialize-javascript.git"
|
||||
},
|
||||
"keywords": [
|
||||
"serialize",
|
||||
"serialization",
|
||||
"javascript",
|
||||
"js",
|
||||
"json"
|
||||
],
|
||||
"author": "Eric Ferraiuolo <edf@ericf.me>",
|
||||
"license": "BSD-3-Clause",
|
||||
"bugs": {
|
||||
"url": "https://github.com/yahoo/serialize-javascript/issues"
|
||||
},
|
||||
"homepage": "https://github.com/yahoo/serialize-javascript",
|
||||
"devDependencies": {
|
||||
"benchmark": "^2.1.4"
|
||||
},
|
||||
"engines": {
|
||||
"node": ">=20.0.0"
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user