Revert "Fix mistyped script arbitrary code execution vulnerability (#18660)" (#19018)
This reverts commit e5cc1462b3e7be78306a1f6961ce82d942eb36d2.
Dan Abramov committed
May 27, 2020 at 17:37 UTC
b41beb1a358c0db21e9a72725da19729f73c8310
2 files changed
+2
-20
packages/react-dom/src/client/ReactDOMComponent.js
+2
-4
@@ -430,13 +430,11 @@ export function createElement(
430
namespaceURI = getIntrinsicNamespace(type);
431
}
432
if (namespaceURI === HTML_NAMESPACE) {
433
- const lowerCaseType = type.toLowerCase();
434
-
433
if (__DEV__) {
434
isCustomComponentTag = isCustomComponent(type, props);
435
// Should this check be gated by parent namespace? Not sure we want to
436
// allow <SVG> or <mATH>.
439
- if (!isCustomComponentTag && type !== lowerCaseType) {
437
+ if (!isCustomComponentTag && type !== type.toLowerCase()) {
438
console.error(
439
'<%s /> is using incorrect casing. ' +
440
'Use PascalCase for React components, ' +
@@ -446,7 +444,7 @@ export function createElement(
444
}
445
}
446
449
- if (lowerCaseType === 'script') {
447
+ if (type === 'script') {
448
// Create the script via .innerHTML so its "parser-inserted" flag is
449
// set to true and it does not execute
450
const div = ownerDocument.createElement('div');
packages/react-dom/src/client/__tests__/trustedTypes-test.internal.js
-16
@@ -242,20 +242,4 @@ describe('when Trusted Types are available in global object', () => {
242
// check that the warning is printed only once
243
ReactDOM.render(<script>alert("I am not executed")</script>, container);
244
});
245
-
246
- it('should warn twice when rendering scRipt tag and prevent code execution on mistyped tag', () => {
247
- expect(() => {
248
- ReactDOM.render(<scRipt>alert("I am not executed")</scRipt>, container);
249
- }).toErrorDev([
250
- 'Warning: <scRipt /> is using incorrect casing. ' +
251
- 'Use PascalCase for React components, ' +
252
- 'or lowercase for HTML elements.\n' +
253
- ' in scRipt (at **)',
254
- 'Warning: Encountered a script tag while rendering React component. ' +
255
- 'Scripts inside React components are never executed when rendering ' +
256
- 'on the client. Consider using template tag instead ' +
257
- '(https://developer.mozilla.org/en-US/docs/Web/HTML/Element/template).\n' +
258
- ' in scRipt (at **)',
259
- ]);
260
- });
245
});