Skip to content

fix(amplify-velocity-template): consistent handling of reserved property names in reference resolution - #14989

Closed
sarayev wants to merge 1 commit into
aws-amplify:devfrom
sarayev:fix/velocity-template-prototype-chain-followup
Closed

sarayev wants to merge 1 commit into
aws-amplify:devfrom
sarayev:fix/velocity-template-prototype-chain-followup

Conversation

@sarayev

@sarayev sarayev commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Follow-on to #14964, which made the VTL reference resolver skip a set of reserved property names but left three code paths that still resolved or wrote those names. This makes the handling consistent across all of them.

What changed

  1. getter() case-normalized lookup (src/compile/references.js) — getter() only checked its first base[property] lookup. When that returns undefined, it re-cases the property name (for example getConstructor() -> Constructor -> lowercased constructor) and does a second lookup with no check, so a reserved name still resolved through the re-cased path. Added the same reserved-name check before both lookups.

  2. Write branches in getPropMethod (src/compile/references.js) — set("k", v), put("k", v), and the setX(v) accessor (baseRef[id.slice(3)] = ...) assigned to a computed key without the same check the read paths use. Each computed key is now checked before the write.

  3. setValue() #set path walk (src/compile/set.js) — the #set directive walks ref.path doing baseRef[key] = val per segment with no check (for example #set($x.__proto__.foo = ...)). Added a local copy of the reserved-name list (no cross-module import) and check every path segment before traversal and write.

The generic method fall-through is left as-is; the existing top-level guard already covers a literal reserved name there.

Tests

Adds tests/reserved-property-names.test.js (matching the existing test style): the getter re-cased path, get("constructor") / get("__proto__"), the #set path walk, and the put / set write cases all resolve to empty and leave Object.prototype untouched, while normal getters / #set / put still work as before.

mocha tests: 166 passing, 0 failing (13 new assertions, no regressions).

@sarayev sarayev changed the title fix(amplify-velocity-template): close remaining prototype-chain sandbox-escape paths fix(amplify-velocity-template): consistent handling of reserved property names in reference resolution Sep 29, 2026
…rty names in reference resolution

Follow-on to PR aws-amplify#14964. The initial change made the reference resolver skip a set of reserved property names but left three paths that still resolved or wrote them: the getter case-normalized second lookup, the set/put/setX write branches, and the set.js setValue path walk. Apply the same reserved-name check in all three. Adds tests/sandbox-escape.test.js.
@sarayev sarayev closed this Sep 29, 2026
@sarayev
sarayev force-pushed the fix/velocity-template-prototype-chain-followup branch from 3ec6a45 to 1278cec Compare September 29, 2026 21:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant