fix(packaging): reject inherited profile names

This commit is contained in:
4gray committed 2026-07-17 22:42:36 +02:00
1 parent 81f970d281
commit cee65d0b2e
2 files changed
+19 -3

No files matched your search

+2 -3
View File
@@ -51,13 +51,12 @@ function findLinuxFrameCopyProfile(value) {
}
const name = typeof value === 'string' ? value.trim() : String(value);
const profile = LINUX_FRAME_COPY_PROFILES[name];
if (!profile) {
if (!Object.hasOwn(LINUX_FRAME_COPY_PROFILES, name)) {
throw new Error(
`Unsupported Linux frame-copy profile "${name}". Expected one of: ${expectedProfileNames()}.`
);
}
return profile;
return LINUX_FRAME_COPY_PROFILES[name];
}
function resolveLinuxFrameCopyProfile(value) {
@@ -109,6 +109,23 @@ test('rejects missing and unsupported profile names with clear errors', () => {
);
});
test('rejects inherited object property names as unsupported profiles', () => {
for (const value of ['constructor', 'toString', '__proto__']) {
const unsupportedProfileError = new RegExp(
`Unsupported Linux frame-copy profile "${value}"`
);
assert.throws(
() => resolveLinuxFrameCopyProfile(value),
unsupportedProfileError
);
assert.throws(
() => validateLinuxProfileTargets(value, ['deb']),
unsupportedProfileError
);
}
});
test('validates profile targets case-insensitively with deterministic errors', () => {
const targets = ['DEB', 'AppImage', 'RPM'];