Repository navigation
The document is different from the runtime #48688
Description
Activity
The "with
methodalways set toGET." part is wrong but the other sentence is correct. The following example is what the documentation refers to.const assert = require('assert'); const http = require('http'); function Options() {} Options.prototype.method = 'POST'; const options = new Options(); assert.strictEqual(options.method, 'POST'); const server = http.createServer(); server.on('request', function (request, response) { console.log(request.method); response.end('OK'); }); server.listen(function () { const { port } = server.address(); const request = http.get(`http://localhost:${port}`, options); request.on('response', function (response) { response.resume(); response.on('end', function () { server.close(); }); }); });
The last sentence inherits attributes from the prototype to ignore ambiguities, which I understand as follows:
const http = require('http'); var obj = {}; obj.__proto__.method = 'POST'; const server = http.createServer(); server.on('request', function (request, response) { console.log(request.method); response.end('OK'); }); server.listen(function () { const { port } = server.address(); const request = http.get(`http://localhost:${port}`); request.on('response', function (response) { response.resume(); response.on('end', function () { server.close(); }); }); });
If the code written by the user has any prototype chain contamination, there may be a vulnerability hazard
Wanna open a docs PR? A fix would probably be: "With the method set to
GETby default" or something?- addedhttpIssues and PRs related to the http subsystem.Issues and PRs related to the http subsystem.docIssues and PRs related to Node.js documentation.Issues and PRs related to Node.js documentation.
on Jul 7, 2023 Yes, I did, I originally wanted to fix this prototype inheritance issue because it could cause bugs, but I found I couldn't do it, so I fixed docs
If the code written by the user has any prototype chain contamination, there may be a vulnerability hazard
Changing the global object prototype is a different thing and is at the user's risk. It is not limited to this but the whole runtime environment.
Reacted by Benjamin Gruenbaum and an4er- added a commit that references this issue
on Jul 13, 2023 - added 2 commits that reference this issue
on Aug 14, 2023 - added a commit that references this issue
on Feb 18, 2024
Version
all
Platform
all
Subsystem
No response
What steps will reproduce the bug?
that's what it says in the documentation


but i test it
How often does it reproduce? Is there a required condition?
all
What is the expected behavior? Why is that the expected behavior?
It does not inherit the properties of the prototype
What do you see instead?
It inherits the properties of the prototype
Additional information
No response