@samitouri / QOS-React-2 / commits / b41beb1a35

Revert "Fix mistyped script arbitrary code execution vulnerability (#18660)" (#19018)

This reverts commit e5cc1462b3e7be78306a1f6961ce82d942eb36d2.

Dan Abramov committed May 27, 2020 at 17:37 UTC b41beb1a358c0db21e9a72725da19729f73c8310
2 files changed +2 -20
packages/react-dom/src/client/ReactDOMComponent.js
+2 -4
@@ -430,13 +430,11 @@ export function createElement(
430 namespaceURI = getIntrinsicNamespace(type);
431 }
432 if (namespaceURI === HTML_NAMESPACE) {
433 - const lowerCaseType = type.toLowerCase();
434 -
433 if (__DEV__) {
434 isCustomComponentTag = isCustomComponent(type, props);
435 // Should this check be gated by parent namespace? Not sure we want to
436 // allow <SVG> or <mATH>.
439 - if (!isCustomComponentTag && type !== lowerCaseType) {
437 + if (!isCustomComponentTag && type !== type.toLowerCase()) {
438 console.error(
439 '<%s /> is using incorrect casing. ' +
440 'Use PascalCase for React components, ' +
@@ -446,7 +444,7 @@ export function createElement(
444 }
445 }
446
449 - if (lowerCaseType === 'script') {
447 + if (type === 'script') {
448 // Create the script via .innerHTML so its "parser-inserted" flag is
449 // set to true and it does not execute
450 const div = ownerDocument.createElement('div');
packages/react-dom/src/client/__tests__/trustedTypes-test.internal.js
-16
@@ -242,20 +242,4 @@ describe('when Trusted Types are available in global object', () => {
242 // check that the warning is printed only once
243 ReactDOM.render(<script>alert("I am not executed")</script>, container);
244 });
245 -
246 - it('should warn twice when rendering scRipt tag and prevent code execution on mistyped tag', () => {
247 - expect(() => {
248 - ReactDOM.render(<scRipt>alert("I am not executed")</scRipt>, container);
249 - }).toErrorDev([
250 - 'Warning: <scRipt /> is using incorrect casing. ' +
251 - 'Use PascalCase for React components, ' +
252 - 'or lowercase for HTML elements.\n' +
253 - ' in scRipt (at **)',
254 - 'Warning: Encountered a script tag while rendering React component. ' +
255 - 'Scripts inside React components are never executed when rendering ' +
256 - 'on the client. Consider using template tag instead ' +
257 - '(https://developer.mozilla.org/en-US/docs/Web/HTML/Element/template).\n' +
258 - ' in scRipt (at **)',
259 - ]);
260 - });
245 });