3 ms·
As of version 8.0.0 node has exposed a serialization api which is compatible with structured clone. https://nodejs.org/api/v8.html#v8_serialization_api https://
by Null-Set 8y ago
As of version 8.0.0 node has exposed a serialization api which is compatible with structured clone. https://nodejs.org/api/v8.html#v8_serialization_api https://nodejs.org/api/v8.html#v8_serialization_api
const v8 = require('v8');
const buf = v8.serialize({a: 'foo', b: new Date()});
const cloned = v8.deserialize(buf);
cloned.b.getMonth();
- devoply 8y agoHave we learned nothing from Java's serialization fiasco?
- nur0n 8y agoI want to learn, can you elaborate?
- devoply 8y agohttps://dzone.com/articles/jdk-11-beginning-of-the-end-for-java-serialization https://dzone.com/articles/jdk-11-beginning-of-the-end-for-j...
- fulafel 8y agoJava's deserialization will instantiate any classes that the data tells it to, which in practice leads to myriad vulnerabilities as many classes have constructors that can be used to write files, execute shell commands, etc. Many programmers didn't realize this, and bad things happened. This is a classic example: https://www.cvedetails.com/cve/CVE-2015-7501/ https://www.cvedetails.com/cve/CVE-2015-7501/ (Many more can be found under the CWE-502 "Deserialization of Untrusted Data" category)
- foota 8y agoI don't know how the JavaScript proposal does it, but you can certainly create generic clone structures that are safe for untrusted input.
- wheresvic1 8y agoThat's awesome, I'll update the article to reflect this!