-
Notifications
You must be signed in to change notification settings - Fork 1.3k
fix(core): prevent private-field brand-check runtime crashes #1648
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
…eck crashes - Replace JS private fields with module-scoped WeakMaps on hot paths: - core/api-promise.ts (APIPromise ↔ client) - core/pagination.ts (AbstractPage ↔ client) - core/streaming.ts (Stream ↔ client; tee preserves client) - client.ts (replace #encoder with private field; private baseURLOverridden) - Add minimal inline rationale comments; no issue links in code. - Remove temporary repros under tests/temp/. - No public API changes.
- APIPromise: detached then/catch/finally do not throw private-field TypeError - Pagination: AbstractPage.getNextPage guarded under detachment - Streaming: Stream.tee remains stable under detachment
ab81606 to
370ab76
Compare
|
Ready for review.. |
|
Could you take a look at this fix please...? |
|
+1 |
|
Happy to help, @Pierre-Assemat @mariocandela. Just to confirm - are you referring to reviewing the current fix in this PR, or reporting a new issue caused by it? If it’s the latter, could you share a minimal example and the |
Changes being requested
Replace class private fields with module-scoped
WeakMapsto prevent runtime crashes caused by JavaScript private field brand checks across duplicate SDK installations.Core changes:
#privatefields withWeakMap-basedencapsulation in core componentscore/api-promise.ts,core/pagination.ts, andcore/streaming.tsWeakMapapproachTest coverage:
cross-copymethod compatibility works correctlyAdditional context & links
Bug: #1590
This addresses
"TypeError: Cannot read private member"runtime crashes that occur when methods from different SDK copies interact, particularly in environments with duplicate SDK installations.Problem:
JavaScript private field brand checks fail when instances cross module boundaries between different SDK copies, causing runtime errors in production environments.
Solution:
WeakMaps provide the same encapsulation benefits as private fields, but don't enforce brand checks, allowing instances from different SDK copies to interoperate safely.
Impact:
✅ I understand that this repository is auto-generated, and my pull request may not be merged