@samitouri / QOS-React-1 / commits / 843ec07021

[Flight] Taint APIs (#27445)

This lets a registered object or value be "tainted", which we block from crossing the serialization boundary. It's only allowed to stay in-memory. This is an extra layer of protection against mistakes of transferring data from a data access layer to a client. It doesn't provide perfect protection, because it doesn't trace through derived values and substrings. So it shouldn't be used as the only security layer but more layers are better. `taintObjectReference` is for specific object instances, not any nested objects or values inside that object. It's useful to avoid specific objects from getting passed as is. It ensures that you don't accidentally leak values in a specific context. It can be for security reasons like tokens, privacy reasons like personal data or performance reasons like avoiding passing large objects over the wire. It might be privacy violation to leak the age of a specific user, but the number itself isn't blocked in any other context. As soon as the value is extracted and passed specifically without the object, it can therefore leak. `taintUniqueValue` is useful for high entropy values such as hashes, tokens or crypto keys that are very unique values. In that case it can be useful to taint the actual primitive values themselves. These can be encoded as a string, bigint or typed array. We don't currently check for this value in a substring or inside other typed arrays. Since values can be created from different sources they don't just follow garbage collection. In this case an additional object must be provided that defines the life time of this value for how long it should be blocked. It can be `globalThis` for essentially forever, but that risks leaking memory for ever when you're dealing with dynamic values like reading a token from a database. So in that case the idea is that you pass the object that might end up in cache. A request is the only thing that is expected to do any work. The principle is that you can derive values from out of a tainted entry during a request. Including stashing it in a per request cache. What you can't do is store a derived value in a global module level cache. At least not without also tainting the object.

Sebastian Markbåge committed Oct 2, 2023 at 13:55 UTC 843ec0702140f2d1e9407a38859abdf5b8dfe4e4
23 files changed +540 -5
.eslintrc.js
+1
@@ -506,6 +506,7 @@ module.exports = {
506 Thenable: 'readonly',
507 TimeoutID: 'readonly',
508 WheelEventHandler: 'readonly',
509 + FinalizationRegistry: 'readonly',
510
511 spyOnDev: 'readonly',
512 spyOnDevAndProd: 'readonly',
packages/react-client/src/__tests__/ReactFlight-test.js
+215
@@ -10,6 +10,23 @@
10
11 'use strict';
12
13 +const heldValues = [];
14 +let finalizationCallback;
15 +function FinalizationRegistryMock(callback) {
16 + finalizationCallback = callback;
17 +}
18 +FinalizationRegistryMock.prototype.register = function (target, heldValue) {
19 + heldValues.push(heldValue);
20 +};
21 +global.FinalizationRegistry = FinalizationRegistryMock;
22 +
23 +function gc() {
24 + for (let i = 0; i < heldValues.length; i++) {
25 + finalizationCallback(heldValues[i]);
26 + }
27 + heldValues.length = 0;
28 +}
29 +
30 let act;
31 let use;
32 let startTransition;
@@ -1446,4 +1463,202 @@ describe('ReactFlight', () => {
1463 );
1464 });
1465 });
1466 +
1467 + // @gate enableTaint
1468 + it('errors when a tainted object is serialized', async () => {
1469 + function UserClient({user}) {
1470 + return <span>{user.name}</span>;
1471 + }
1472 + const User = clientReference(UserClient);
1473 +
1474 + const user = {
1475 + name: 'Seb',
1476 + age: 'rather not say',
1477 + };
1478 + ReactServer.experimental_taintObjectReference(
1479 + "Don't pass the raw user object to the client",
1480 + user,
1481 + );
1482 + const errors = [];
1483 + ReactNoopFlightServer.render(<User user={user} />, {
1484 + onError(x) {
1485 + errors.push(x.message);
1486 + },
1487 + });
1488 +
1489 + expect(errors).toEqual(["Don't pass the raw user object to the client"]);
1490 + });
1491 +
1492 + // @gate enableTaint
1493 + it('errors with a specific message when a tainted function is serialized', async () => {
1494 + function UserClient({user}) {
1495 + return <span>{user.name}</span>;
1496 + }
1497 + const User = clientReference(UserClient);
1498 +
1499 + function change() {}
1500 + ReactServer.experimental_taintObjectReference(
1501 + 'A change handler cannot be passed to a client component',
1502 + change,
1503 + );
1504 + const errors = [];
1505 + ReactNoopFlightServer.render(<User onChange={change} />, {
1506 + onError(x) {
1507 + errors.push(x.message);
1508 + },
1509 + });
1510 +
1511 + expect(errors).toEqual([
1512 + 'A change handler cannot be passed to a client component',
1513 + ]);
1514 + });
1515 +
1516 + // @gate enableTaint
1517 + it('errors when a tainted string is serialized', async () => {
1518 + function UserClient({user}) {
1519 + return <span>{user.name}</span>;
1520 + }
1521 + const User = clientReference(UserClient);
1522 +
1523 + const process = {
1524 + env: {
1525 + SECRET: '3e971ecc1485fe78625598bf9b6f85db',
1526 + },
1527 + };
1528 + ReactServer.experimental_taintUniqueValue(
1529 + 'Cannot pass a secret token to the client',
1530 + process,
1531 + process.env.SECRET,
1532 + );
1533 +
1534 + const errors = [];
1535 + ReactNoopFlightServer.render(<User token={process.env.SECRET} />, {
1536 + onError(x) {
1537 + errors.push(x.message);
1538 + },
1539 + });
1540 +
1541 + expect(errors).toEqual(['Cannot pass a secret token to the client']);
1542 +
1543 + // This just ensures the process object is kept alive for the life time of
1544 + // the test since we're simulating a global as an example.
1545 + expect(process.env.SECRET).toBe('3e971ecc1485fe78625598bf9b6f85db');
1546 + });
1547 +
1548 + // @gate enableTaint
1549 + it('errors when a tainted bigint is serialized', async () => {
1550 + function UserClient({user}) {
1551 + return <span>{user.name}</span>;
1552 + }
1553 + const User = clientReference(UserClient);
1554 +
1555 + const currentUser = {
1556 + name: 'Seb',
1557 + token: BigInt('0x3e971ecc1485fe78625598bf9b6f85dc'),
1558 + };
1559 + ReactServer.experimental_taintUniqueValue(
1560 + 'Cannot pass a secret token to the client',
1561 + currentUser,
1562 + currentUser.token,
1563 + );
1564 +
1565 + function App({user}) {
1566 + return <User token={user.token} />;
1567 + }
1568 +
1569 + const errors = [];
1570 + ReactNoopFlightServer.render(<App user={currentUser} />, {
1571 + onError(x) {
1572 + errors.push(x.message);
1573 + },
1574 + });
1575 +
1576 + expect(errors).toEqual(['Cannot pass a secret token to the client']);
1577 + });
1578 +
1579 + // @gate enableTaint && enableBinaryFlight
1580 + it('errors when a tainted binary value is serialized', async () => {
1581 + function UserClient({user}) {
1582 + return <span>{user.name}</span>;
1583 + }
1584 + const User = clientReference(UserClient);
1585 +
1586 + const currentUser = {
1587 + name: 'Seb',
1588 + token: new Uint32Array([0x3e971ecc, 0x1485fe78, 0x625598bf, 0x9b6f85dd]),
1589 + };
1590 + ReactServer.experimental_taintUniqueValue(
1591 + 'Cannot pass a secret token to the client',
1592 + currentUser,
1593 + currentUser.token,
1594 + );
1595 +
1596 + function App({user}) {
1597 + const clone = user.token.slice();
1598 + return <User token={clone} />;
1599 + }
1600 +
1601 + const errors = [];
1602 + ReactNoopFlightServer.render(<App user={currentUser} />, {
1603 + onError(x) {
1604 + errors.push(x.message);
1605 + },
1606 + });
1607 +
1608 + expect(errors).toEqual(['Cannot pass a secret token to the client']);
1609 + });
1610 +
1611 + // @gate enableTaint
1612 + it('keep a tainted value tainted until the end of any pending requests', async () => {
1613 + function UserClient({user}) {
1614 + return <span>{user.name}</span>;
1615 + }
1616 + const User = clientReference(UserClient);
1617 +
1618 + function getUser() {
1619 + const user = {
1620 + name: 'Seb',
1621 + token: '3e971ecc1485fe78625598bf9b6f85db',
1622 + };
1623 + ReactServer.experimental_taintUniqueValue(
1624 + 'Cannot pass a secret token to the client',
1625 + user,
1626 + user.token,
1627 + );
1628 + return user;
1629 + }
1630 +
1631 + function App() {
1632 + const user = getUser();
1633 + const derivedValue = {...user};
1634 + // A garbage collection can happen at any time. Even before the end of
1635 + // this request. This would clean up the user object.
1636 + gc();
1637 + // We should still block the tainted value.
1638 + return <User user={derivedValue} />;
1639 + }
1640 +
1641 + let errors = [];
1642 + ReactNoopFlightServer.render(<App />, {
1643 + onError(x) {
1644 + errors.push(x.message);
1645 + },
1646 + });
1647 +
1648 + expect(errors).toEqual(['Cannot pass a secret token to the client']);
1649 +
1650 + // After the previous requests finishes, the token can be rendered again.
1651 +
1652 + errors = [];
1653 + ReactNoopFlightServer.render(
1654 + <User user={{token: '3e971ecc1485fe78625598bf9b6f85db'}} />,
1655 + {
1656 + onError(x) {
1657 + errors.push(x.message);
1658 + },
1659 + },
1660 + );
1661 +
1662 + expect(errors).toEqual([]);
1663 + });
1664 });
packages/react-server/src/ReactFlightServer.js
+85 -4
@@ -11,7 +11,11 @@ import type {Chunk, BinaryChunk, Destination} from './ReactServerStreamConfig';
11
12 import type {Postpone} from 'react/src/ReactPostpone';
13
14 -import {enableBinaryFlight, enablePostpone} from 'shared/ReactFeatureFlags';
14 +import {
15 + enableBinaryFlight,
16 + enablePostpone,
17 + enableTaint,
18 +} from 'shared/ReactFeatureFlags';
19
20 import {
21 scheduleWork,
@@ -106,6 +110,8 @@ import {
110 import {getOrCreateServerContext} from 'shared/ReactServerContextRegistry';
111 import ReactServerSharedInternals from './ReactServerSharedInternals';
112 import isArray from 'shared/isArray';
113 +import binaryToComparableString from 'shared/binaryToComparableString';
114 +
115 import {SuspenseException, getSuspendedThenable} from './ReactFlightThenable';
116
117 type JSONValue =
@@ -192,14 +198,42 @@ export type Request = {
198 writtenProviders: Map<string, number>,
199 identifierPrefix: string,
200 identifierCount: number,
201 + taintCleanupQueue: Array<string | bigint>,
202 onError: (error: mixed) => ?string,
203 onPostpone: (reason: string) => void,
204 toJSON: (key: string, value: ReactClientValue) => ReactJSONValue,
205 };
206
200 -const ReactCurrentDispatcher =
201 - ReactServerSharedInternals.ReactCurrentDispatcher;
202 -const ReactCurrentCache = ReactServerSharedInternals.ReactCurrentCache;
207 +const {
208 + TaintRegistryObjects,
209 + TaintRegistryValues,
210 + TaintRegistryByteLengths,
211 + TaintRegistryPendingRequests,
212 + ReactCurrentDispatcher,
213 + ReactCurrentCache,
214 +} = ReactServerSharedInternals;
215 +
216 +function throwTaintViolation(message: string) {
217 + // eslint-disable-next-line react-internal/prod-error-codes
218 + throw new Error(message);
219 +}
220 +
221 +function cleanupTaintQueue(request: Request): void {
222 + const cleanupQueue = request.taintCleanupQueue;
223 + TaintRegistryPendingRequests.delete(cleanupQueue);
224 + for (let i = 0; i < cleanupQueue.length; i++) {
225 + const entryValue = cleanupQueue[i];
226 + const entry = TaintRegistryValues.get(entryValue);
227 + if (entry !== undefined) {
228 + if (entry.count === 1) {
229 + TaintRegistryValues.delete(entryValue);
230 + } else {
231 + entry.count--;
232 + }
233 + }
234 + }
235 + cleanupQueue.length = 0;
236 +}
237
238 function defaultErrorHandler(error: mixed) {
239 console['error'](error);
@@ -235,6 +269,10 @@ export function createRequest(
269
270 const abortSet: Set<Task> = new Set();
271 const pingedTasks: Array<Task> = [];
272 + const cleanupQueue: Array<string | bigint> = [];
273 + if (enableTaint) {
274 + TaintRegistryPendingRequests.add(cleanupQueue);
275 + }
276 const hints = createHints();
277 const request: Request = {
278 status: OPEN,
@@ -258,6 +296,7 @@ export function createRequest(
296 writtenProviders: new Map(),
297 identifierPrefix: identifierPrefix || '',
298 identifierCount: 1,
299 + taintCleanupQueue: cleanupQueue,
300 onError: onError === undefined ? defaultErrorHandler : onError,
301 onPostpone: onPostpone === undefined ? defaultPostponeHandler : onPostpone,
302 // $FlowFixMe[missing-this-annot]
@@ -781,6 +820,18 @@ function serializeTypedArray(
820 tag: string,
821 typedArray: $ArrayBufferView,
822 ): string {
823 + if (enableTaint) {
824 + if (TaintRegistryByteLengths.has(typedArray.byteLength)) {
825 + // If we have had any tainted values of this length, we check
826 + // to see if these bytes matches any entries in the registry.
827 + const tainted = TaintRegistryValues.get(
828 + binaryToComparableString(typedArray),
829 + );
830 + if (tainted !== undefined) {
831 + throwTaintViolation(tainted.message);
832 + }
833 + }
834 + }
835 request.pendingChunks += 2;
836 const bufferId = request.nextChunkId++;
837 // TODO: Convert to little endian if that's not the server default.
@@ -959,6 +1010,12 @@ function resolveModelToJSON(
1010 }
1011
1012 if (typeof value === 'object') {
1013 + if (enableTaint) {
1014 + const tainted = TaintRegistryObjects.get(value);
1015 + if (tainted !== undefined) {
1016 + throwTaintViolation(tainted);
1017 + }
1018 + }
1019 if (isClientReference(value)) {
1020 return serializeClientReference(request, parent, key, (value: any));
1021 // $FlowFixMe[method-unbinding]
@@ -1091,6 +1148,12 @@ function resolveModelToJSON(
1148 }
1149
1150 if (typeof value === 'string') {
1151 + if (enableTaint) {
1152 + const tainted = TaintRegistryValues.get(value);
1153 + if (tainted !== undefined) {
1154 + throwTaintViolation(tainted.message);
1155 + }
1156 + }
1157 // TODO: Maybe too clever. If we support URL there's no similar trick.
1158 if (value[value.length - 1] === 'Z') {
1159 // Possibly a Date, whose toJSON automatically calls toISOString
@@ -1122,6 +1185,12 @@ function resolveModelToJSON(
1185 }
1186
1187 if (typeof value === 'function') {
1188 + if (enableTaint) {
1189 + const tainted = TaintRegistryObjects.get(value);
1190 + if (tainted !== undefined) {
1191 + throwTaintViolation(tainted);
1192 + }
1193 + }
1194 if (isClientReference(value)) {
1195 return serializeClientReference(request, parent, key, (value: any));
1196 }
@@ -1171,6 +1240,12 @@ function resolveModelToJSON(
1240 }
1241
1242 if (typeof value === 'bigint') {
1243 + if (enableTaint) {
1244 + const tainted = TaintRegistryValues.get(value);
1245 + if (tainted !== undefined) {
1246 + throwTaintViolation(tainted.message);
1247 + }
1248 + }
1249 return serializeBigInt(value);
1250 }
1251
@@ -1198,6 +1273,9 @@ function logRecoverableError(request: Request, error: mixed): string {
1273 }
1274
1275 function fatalError(request: Request, error: mixed): void {
1276 + if (enableTaint) {
1277 + cleanupTaintQueue(request);
1278 + }
1279 // This is called outside error handling code such as if an error happens in React internals.
1280 if (request.destination !== null) {
1281 request.status = CLOSED;
@@ -1522,6 +1600,9 @@ function flushCompletedChunks(
1600 flushBuffered(destination);
1601 if (request.pendingChunks === 0) {
1602 // We're done.
1603 + if (enableTaint) {
1604 + cleanupTaintQueue(request);
1605 + }
1606 close(destination);
1607 }
1608 }
packages/react/src/ReactServerSharedInternals.js
+17
@@ -7,10 +7,27 @@
7
8 import ReactCurrentDispatcher from './ReactCurrentDispatcher';
9 import ReactCurrentCache from './ReactCurrentCache';
10 +import {
11 + TaintRegistryObjects,
12 + TaintRegistryValues,
13 + TaintRegistryByteLengths,
14 + TaintRegistryPendingRequests,
15 +} from './ReactTaintRegistry';
16 +
17 +import {enableTaint} from 'shared/ReactFeatureFlags';
18
19 const ReactServerSharedInternals = {
20 ReactCurrentDispatcher,
21 ReactCurrentCache,
22 };
23
24 +if (enableTaint) {
25 + ReactServerSharedInternals.TaintRegistryObjects = TaintRegistryObjects;
26 + ReactServerSharedInternals.TaintRegistryValues = TaintRegistryValues;
27 + ReactServerSharedInternals.TaintRegistryByteLengths =
28 + TaintRegistryByteLengths;
29 + ReactServerSharedInternals.TaintRegistryPendingRequests =
30 + TaintRegistryPendingRequests;
31 +}
32 +
33 export default ReactServerSharedInternals;
packages/react/src/ReactSharedSubset.experimental.js
+6
@@ -14,6 +14,12 @@ export {default as __SECRET_INTERNALS_DO_NOT_USE_OR_YOU_WILL_BE_FIRED} from './R
14
15 export {default as __SECRET_SERVER_INTERNALS_DO_NOT_USE_OR_YOU_WILL_BE_FIRED} from './ReactServerSharedInternals';
16
17 +// These are server-only
18 +export {
19 + taintUniqueValue as experimental_taintUniqueValue,
20 + taintObjectReference as experimental_taintObjectReference,
21 +} from './ReactTaint';
22 +
23 export {
24 Children,
25 Fragment,
packages/react/src/ReactTaint.js new
+138
@@ -0,0 +1,138 @@
1 +/**
2 + * Copyright (c) Meta Platforms, Inc. and affiliates.
3 + *
4 + * This source code is licensed under the MIT license found in the
5 + * LICENSE file in the root directory of this source tree.
6 + *
7 + * @flow
8 + */
9 +
10 +import {enableTaint, enableBinaryFlight} from 'shared/ReactFeatureFlags';
11 +
12 +import binaryToComparableString from 'shared/binaryToComparableString';
13 +
14 +import ReactServerSharedInternals from './ReactServerSharedInternals';
15 +const {
16 + TaintRegistryObjects,
17 + TaintRegistryValues,
18 + TaintRegistryByteLengths,
19 + TaintRegistryPendingRequests,
20 +} = ReactServerSharedInternals;
21 +
22 +interface Reference {}
23 +
24 +// This is the shared constructor of all typed arrays.
25 +const TypedArrayConstructor = Object.getPrototypeOf(
26 + Uint32Array.prototype,
27 +).constructor;
28 +
29 +const defaultMessage =
30 + 'A tainted value was attempted to be serialized to a Client Component or Action closure. ' +
31 + 'This would leak it to the client.';
32 +
33 +function cleanup(entryValue: string | bigint): void {
34 + const entry = TaintRegistryValues.get(entryValue);
35 + if (entry !== undefined) {
36 + TaintRegistryPendingRequests.forEach(function (requestQueue) {
37 + requestQueue.push(entryValue);
38 + entry.count++;
39 + });
40 + if (entry.count === 1) {
41 + TaintRegistryValues.delete(entryValue);
42 + } else {
43 + entry.count--;
44 + }
45 + }
46 +}
47 +
48 +// If FinalizationRegistry doesn't exist, we assume that objects life forever.
49 +// E.g. the whole VM is just the lifetime of a request.
50 +const finalizationRegistry =
51 + typeof FinalizationRegistry === 'function'
52 + ? new FinalizationRegistry(cleanup)
53 + : null;
54 +
55 +export function taintUniqueValue(
56 + message: ?string,
57 + lifetime: Reference,
58 + value: string | bigint | $ArrayBufferView,
59 +): void {
60 + if (!enableTaint) {
61 + throw new Error('Not implemented.');
62 + }
63 + // eslint-disable-next-line react-internal/safe-string-coercion
64 + message = '' + (message || defaultMessage);
65 + if (
66 + lifetime === null ||
67 + (typeof lifetime !== 'object' && typeof lifetime !== 'function')
68 + ) {
69 + throw new Error(
70 + 'To taint a value, a lifetime must be defined by passing an object that holds ' +
71 + 'the value.',
72 + );
73 + }
74 + let entryValue: string | bigint;
75 + if (typeof value === 'string' || typeof value === 'bigint') {
76 + // Use as is.
77 + entryValue = value;
78 + } else if (
79 + enableBinaryFlight &&
80 + (value instanceof TypedArrayConstructor || value instanceof DataView)
81 + ) {
82 + // For now, we just convert binary data to a string so that we can just use the native
83 + // hashing in the Map implementation. It doesn't really matter what form the string
84 + // take as long as it's the same when we look it up.
85 + // We're not too worried about collisions since this should be a high entropy value.
86 + TaintRegistryByteLengths.add(value.byteLength);
87 + entryValue = binaryToComparableString(value);
88 + } else {
89 + const kind = value === null ? 'null' : typeof value;
90 + if (kind === 'object' || kind === 'function') {
91 + throw new Error(
92 + 'taintUniqueValue cannot taint objects or functions. Try taintObjectReference instead.',
93 + );
94 + }
95 + throw new Error(
96 + 'Cannot taint a ' +
97 + kind +
98 + ' because the value is too general and not unique enough to block globally.',
99 + );
100 + }
101 + const existingEntry = TaintRegistryValues.get(entryValue);
102 + if (existingEntry === undefined) {
103 + TaintRegistryValues.set(entryValue, {
104 + message,
105 + count: 1,
106 + });
107 + } else {
108 + existingEntry.count++;
109 + }
110 + if (finalizationRegistry !== null) {
111 + finalizationRegistry.register(lifetime, entryValue);
112 + }
113 +}
114 +
115 +export function taintObjectReference(
116 + message: ?string,
117 + object: Reference,
118 +): void {
119 + if (!enableTaint) {
120 + throw new Error('Not implemented.');
121 + }
122 + // eslint-disable-next-line react-internal/safe-string-coercion
123 + message = '' + (message || defaultMessage);
124 + if (typeof object === 'string' || typeof object === 'bigint') {
125 + throw new Error(
126 + 'Only objects or functions can be passed to taintObjectReference. Try taintUniqueValue instead.',
127 + );
128 + }
129 + if (
130 + object === null ||
131 + (typeof object !== 'object' && typeof object !== 'function')
132 + ) {
133 + throw new Error(
134 + 'Only objects or functions can be passed to taintObjectReference.',
135 + );
136 + }
137 + TaintRegistryObjects.set(object, message);
138 +}
packages/react/src/ReactTaintRegistry.js new
+27
@@ -0,0 +1,27 @@
1 +/**
2 + * Copyright (c) Meta Platforms, Inc. and affiliates.
3 + *
4 + * This source code is licensed under the MIT license found in the
5 + * LICENSE file in the root directory of this source tree.
6 + *
7 + * @flow
8 + */
9 +
10 +interface Reference {}
11 +
12 +type TaintEntry = {
13 + message: string,
14 + count: number,
15 +};
16 +
17 +export const TaintRegistryObjects: WeakMap<Reference, string> = new WeakMap();
18 +export const TaintRegistryValues: Map<string | bigint, TaintEntry> = new Map();
19 +// Byte lengths of all binary values we've ever seen. We don't both refcounting this.
20 +// We expect to see only a few lengths here such as the length of token.
21 +export const TaintRegistryByteLengths: Set<number> = new Set();
22 +
23 +// When a value is finalized, it means that it has been removed from any global caches.
24 +// No future requests can get a handle on it but any ongoing requests can still have
25 +// a handle on it. It's still tainted until that happens.
26 +type RequestCleanupQueue = Array<string | bigint>;
27 +export const TaintRegistryPendingRequests: Set<RequestCleanupQueue> = new Set();
packages/shared/ReactFeatureFlags.js
+2
@@ -86,6 +86,8 @@ export const enableFormActions = __EXPERIMENTAL__;
86
87 export const enableBinaryFlight = __EXPERIMENTAL__;
88
89 +export const enableTaint = __EXPERIMENTAL__;
90 +
91 export const enablePostpone = __EXPERIMENTAL__;
92
93 export const enableTransitionTracing = false;
packages/shared/binaryToComparableString.js new
+19
@@ -0,0 +1,19 @@
1 +/**
2 + * Copyright (c) Meta Platforms, Inc. and affiliates.
3 + *
4 + * This source code is licensed under the MIT license found in the
5 + * LICENSE file in the root directory of this source tree.
6 + *
7 + * @flow
8 + */
9 +
10 +// Turns a TypedArray or ArrayBuffer into a string that can be used for comparison
11 +// in a Map to see if the bytes are the same.
12 +export default function binaryToComparableString(
13 + view: $ArrayBufferView,
14 +): string {
15 + return String.fromCharCode.apply(
16 + String,
17 + new Uint8Array(view.buffer, view.byteOffset, view.byteLength),
18 + );
19 +}
packages/shared/forks/ReactFeatureFlags.native-fb.js
+1
@@ -38,6 +38,7 @@ export const enableCacheElement = true;
38 export const enableFetchInstrumentation = false;
39 export const enableFormActions = true; // Doesn't affect Native
40 export const enableBinaryFlight = true;
41 +export const enableTaint = true;
42 export const enablePostpone = false;
43 export const enableSchedulerDebugging = false;
44 export const debugRenderPhaseSideEffectsForStrictMode = true;
packages/shared/forks/ReactFeatureFlags.native-oss.js
+1
@@ -25,6 +25,7 @@ export const enableCacheElement = false;
25 export const enableFetchInstrumentation = false;
26 export const enableFormActions = true; // Doesn't affect Native
27 export const enableBinaryFlight = true;
28 +export const enableTaint = true;
29 export const enablePostpone = false;
30 export const disableJavaScriptURLs = false;
31 export const disableCommentsAsDOMContainers = true;
packages/shared/forks/ReactFeatureFlags.test-renderer.js
+1
@@ -25,6 +25,7 @@ export const enableCacheElement = __EXPERIMENTAL__;
25 export const enableFetchInstrumentation = true;
26 export const enableFormActions = true; // Doesn't affect Test Renderer
27 export const enableBinaryFlight = true;
28 +export const enableTaint = true;
29 export const enablePostpone = false;
30 export const disableJavaScriptURLs = false;
31 export const disableCommentsAsDOMContainers = true;
packages/shared/forks/ReactFeatureFlags.test-renderer.native.js
+1
@@ -25,6 +25,7 @@ export const enableCacheElement = true;
25 export const enableFetchInstrumentation = false;
26 export const enableFormActions = true; // Doesn't affect Test Renderer
27 export const enableBinaryFlight = true;
28 +export const enableTaint = true;
29 export const enablePostpone = false;
30 export const disableJavaScriptURLs = false;
31 export const disableCommentsAsDOMContainers = true;
packages/shared/forks/ReactFeatureFlags.test-renderer.www.js
+1
@@ -25,6 +25,7 @@ export const enableCacheElement = true;
25 export const enableFetchInstrumentation = false;
26 export const enableFormActions = true; // Doesn't affect Test Renderer
27 export const enableBinaryFlight = true;
28 +export const enableTaint = true;
29 export const enablePostpone = false;
30 export const enableSchedulerDebugging = false;
31 export const disableJavaScriptURLs = false;
packages/shared/forks/ReactFeatureFlags.www.js
+1
@@ -75,6 +75,7 @@ export const enableFetchInstrumentation = false;
75 export const enableFormActions = false;
76
77 export const enableBinaryFlight = true;
78 +export const enableTaint = false;
79
80 export const enablePostpone = false;
81
scripts/error-codes/codes.json
+6 -1
@@ -477,5 +477,10 @@
477 "489": "Expected to see a component of type \"%s\" in this slot. The tree doesn't match so React will fallback to client rendering.",
478 "490": "Expected to see a Suspense boundary in this slot. The tree doesn't match so React will fallback to client rendering.",
479 "491": "It should not be possible to postpone both at the root of an element as well as a slot below. This is a bug in React.",
480 - "492": "The \"react\" package in this environment is not configured correctly. The \"react-server\" condition must be enabled in any environment that runs React Server Components."
480 + "492": "The \"react\" package in this environment is not configured correctly. The \"react-server\" condition must be enabled in any environment that runs React Server Components.",
481 + "493": "To taint a value, a lifetime must be defined by passing an object that holds the value.",
482 + "494": "taintUniqueValue cannot taint objects or functions. Try taintObjectReference instead.",
483 + "495": "Cannot taint a %s because the value is too general and not unique enough to block globally.",
484 + "496": "Only objects or functions can be passed to taintObjectReference. Try taintUniqueValue instead.",
485 + "497": "Only objects or functions can be passed to taintObjectReference."
486 }
\ No newline at end of file
scripts/flow/environment.js
+2
@@ -24,6 +24,8 @@ declare var queueMicrotask: (fn: Function) => void;
24 declare var reportError: (error: mixed) => void;
25 declare var AggregateError: Class<Error>;
26
27 +declare var FinalizationRegistry: any;
28 +
29 declare module 'create-react-class' {
30 declare var exports: React$CreateClass;
31 }
scripts/rollup/validate/eslintrc.cjs.js
+3
@@ -31,6 +31,9 @@ module.exports = {
31
32 Reflect: 'readonly',
33 globalThis: 'readonly',
34 +
35 + FinalizationRegistry: 'readonly',
36 +
37 // Vendor specific
38 MSApp: 'readonly',
39 __REACT_DEVTOOLS_GLOBAL_HOOK__: 'readonly',
scripts/rollup/validate/eslintrc.cjs2015.js
+1
@@ -31,6 +31,7 @@ module.exports = {
31
32 Reflect: 'readonly',
33 globalThis: 'readonly',
34 + FinalizationRegistry: 'readonly',
35 // Vendor specific
36 MSApp: 'readonly',
37 __REACT_DEVTOOLS_GLOBAL_HOOK__: 'readonly',
scripts/rollup/validate/eslintrc.esm.js
+3
@@ -31,6 +31,9 @@ module.exports = {
31
32 Reflect: 'readonly',
33 globalThis: 'readonly',
34 +
35 + FinalizationRegistry: 'readonly',
36 +
37 // Vendor specific
38 MSApp: 'readonly',
39 __REACT_DEVTOOLS_GLOBAL_HOOK__: 'readonly',
scripts/rollup/validate/eslintrc.fb.js
+3
@@ -31,6 +31,9 @@ module.exports = {
31
32 Reflect: 'readonly',
33 globalThis: 'readonly',
34 +
35 + FinalizationRegistry: 'readonly',
36 +
37 // Vendor specific
38 MSApp: 'readonly',
39 __REACT_DEVTOOLS_GLOBAL_HOOK__: 'readonly',
scripts/rollup/validate/eslintrc.rn.js
+3
@@ -31,6 +31,9 @@ module.exports = {
31
32 Reflect: 'readonly',
33 globalThis: 'readonly',
34 +
35 + FinalizationRegistry: 'readonly',
36 +
37 // Vendor specific
38 MSApp: 'readonly',
39 __REACT_DEVTOOLS_GLOBAL_HOOK__: 'readonly',
scripts/rollup/validate/eslintrc.umd.js
+3
@@ -30,6 +30,9 @@ module.exports = {
30
31 Reflect: 'readonly',
32 globalThis: 'readonly',
33 +
34 + FinalizationRegistry: 'readonly',
35 +
36 // Vendor specific
37 MSApp: 'readonly',
38 __REACT_DEVTOOLS_GLOBAL_HOOK__: 'readonly',