fix: v0.7.1 API 修复与防御统一 — static create / 未 open 防护 / 原型污染 / lint 清零
- MetonaSqlark.create 静态工厂(README 示例在 ESM/Node 下此前 TypeError), 独立 create 函数委托静态实现 - close 未初始化防御(engine undefined 不再崩溃) - AriaEngine hasTable/getTableNames/getTableSchema 统一 ensureOpen - 事务回滚失败不掩盖原始错误 - __proto__ 列名防护:Executor 列映射 Object.create(null) + schema 校验拒绝 - lint 清零(移除 5 处未使用导入) 测试 1147 → 1155(73 套件);行覆盖率 89.8%;版本 0.7.1
This commit is contained in:
@@ -26,6 +26,12 @@ export function validateColumns(columns: Record<string, ColumnDef>): void {
|
||||
let primaryKeyCount = 0;
|
||||
|
||||
for (const [colName, colDef] of Object.entries(columns)) {
|
||||
// v0.7.1: '__proto__' 作为列名会触发对象原型 setter(列静默丢失);
|
||||
// 显式拒绝避免原型污染类攻击面
|
||||
if (colName === '__proto__') {
|
||||
throw new DatabaseError('Column name "__proto__" is not allowed', 'SCHEMA_ERROR');
|
||||
}
|
||||
|
||||
// 类型校验
|
||||
if (!FIELD_TYPES.includes(colDef.type)) {
|
||||
throw new DatabaseError(
|
||||
|
||||
Reference in New Issue
Block a user