Conversation
…rty names in reference resolution Follow-on to PR aws-amplify#14964. The initial change made the reference resolver skip a set of reserved property names but left three paths that still resolved or wrote them: the getter case-normalized second lookup, the set/put/setX write branches, and the set.js setValue path walk. Apply the same reserved-name check in all three. Adds tests/sandbox-escape.test.js.
sarayev
force-pushed
the
fix/velocity-template-prototype-chain-followup
branch
from
September 29, 2026 21:10
3ec6a45 to
1278cec
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-on to #14964, which made the VTL reference resolver skip a set of reserved property names but left three code paths that still resolved or wrote those names. This makes the handling consistent across all of them.
What changed
getter()case-normalized lookup (src/compile/references.js) —getter()only checked its firstbase[property]lookup. When that returnsundefined, it re-cases the property name (for examplegetConstructor()->Constructor-> lowercasedconstructor) and does a second lookup with no check, so a reserved name still resolved through the re-cased path. Added the same reserved-name check before both lookups.Write branches in
getPropMethod(src/compile/references.js) —set("k", v),put("k", v), and thesetX(v)accessor (baseRef[id.slice(3)] = ...) assigned to a computed key without the same check the read paths use. Each computed key is now checked before the write.setValue()#setpath walk (src/compile/set.js) — the#setdirective walksref.pathdoingbaseRef[key] = valper segment with no check (for example#set($x.__proto__.foo = ...)). Added a local copy of the reserved-name list (no cross-module import) and check every path segment before traversal and write.The generic method fall-through is left as-is; the existing top-level guard already covers a literal reserved name there.
Tests
Adds
tests/reserved-property-names.test.js(matching the existing test style): the getter re-cased path,get("constructor")/get("__proto__"), the#setpath walk, and theput/setwrite cases all resolve to empty and leaveObject.prototypeuntouched, while normal getters /#set/putstill work as before.mocha tests: 166 passing, 0 failing (13 new assertions, no regressions).