Commit a0922b0
authored
fix: handle frozen globalThis in setGlobalDispatcher (#5574)
* fix: handle frozen globalThis in setGlobalDispatcher
When Object.freeze(globalThis) is called before undici globals are accessed,
setGlobalDispatcher would throw TypeError because it cannot extend globalThis.
This fix wraps the Object.defineProperty calls in try/catch. When globalThis
is not extensible (frozen), the dispatcher is stored in a module-level
fallback variable instead. getGlobalDispatcher is updated to return the
fallback dispatcher when the globalThis property is not available.
This allows undici to work correctly even when globalThis has been frozen,
which is recommended by Node.js security best practices (CWE-349).
Fixes issue where Object.freeze(globalThis) breaks undici access.
* test: add unit test for frozen globalThis in setGlobalDispatcher
Add comprehensive test coverage for the frozen globalThis fix. Tests verify:
1. setGlobalDispatcher does not throw when globalThis is frozen
2. getGlobalDispatcher continues to return a valid dispatcher
3. The fallback mechanism works correctly when globalThis is not extensible
This addresses the review feedback from mcollina requesting tests.
* test: improve frozen globalThis test coverage
Add comprehensive test cases to ensure all code paths in the frozen globalThis
fix are exercised. Tests verify:
1. setGlobalDispatcher does not throw when globalThis is frozen
2. getGlobalDispatcher returns a valid dispatcher
3. Fallback dispatcher persists across multiple calls
This addresses review feedback requesting tests.1 parent 354a151 commit a0922b0
2 files changed
Lines changed: 98 additions & 16 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
11 | 14 | | |
12 | 15 | | |
13 | 16 | | |
| |||
17 | 20 | | |
18 | 21 | | |
19 | 22 | | |
20 | | - | |
21 | | - | |
22 | | - | |
23 | | - | |
24 | | - | |
25 | | - | |
26 | | - | |
27 | | - | |
28 | | - | |
29 | | - | |
30 | | - | |
31 | | - | |
32 | | - | |
33 | | - | |
34 | | - | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
35 | 55 | | |
36 | 56 | | |
37 | 57 | | |
38 | | - | |
| 58 | + | |
39 | 59 | | |
40 | 60 | | |
41 | 61 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
0 commit comments