7 ms·
> (Hint: some of those seemingly random characters pull a double quote out of JS' leaky guts. Nope! It’s just JSFuck [0] 1. All objects have a `toString` meth
by __ryan__ 7y ago
> (Hint: some of those seemingly random characters pull a double quote out of JS' leaky guts.
Nope! It’s just JSFuck [0]
1. All objects have a `toString` method that returns a string.
2. Object properties can be accessed by subscript (`object.prop === object[“prop”]`) and numeric property keys are really strings (`object[0] === object[“0”]`).
3. String characters can be accessed by index (`”hello”[0] == “h”`).
4. JavaScript has string concatenation support. It occasionally will implicitly convert something to a string if it’s used like a primitive value.
The script you posted just abused those facts to generate the string “Hello World”. It does not “pull a double quote out of JS’ leaky guts”.
Is it weird? Sure. But using strict types prevents this type of stupid stuff from occurring. Do you really think TypeScript doesn’t try to prevent you from using an object as a string? Of course it does.
If you use strict types internally and validate at the edges then you really shouldn’t have a problem.
[0]: http://www.jsfuck.com/ http://www.jsfuck.com/
- shakna 7y agoThat process _is_ string leaking out from inside JavaScript. That all property keys are actually strings is a leak from JS' original implementation. You've accurately explained how it works, without understanding that what I've said explains why that how is allowed to occur.
- nebulous1 7y agoThere's no double quote involved, you saying that implied you didn't know how the statement worked (regardless of whether you actually understood it or not), so their reply was valid. I feel like this whole avenue doesn't fit your overall point. You can certainly create a string in C without using quotes, and you can also write heavily obfuscated code that would be difficult to understand and look very strange.