fix(editor): prototype-polluting assignment (#9606)
This commit is contained in:
@@ -168,20 +168,30 @@ export function updateCell(
|
|||||||
rowId: string,
|
rowId: string,
|
||||||
cell: Cell
|
cell: Cell
|
||||||
) {
|
) {
|
||||||
|
model.doc.transact(() => {
|
||||||
|
const columnId = cell.columnId;
|
||||||
if (
|
if (
|
||||||
rowId === '__proto__' ||
|
rowId === '__proto__' ||
|
||||||
rowId === 'constructor' ||
|
rowId === 'constructor' ||
|
||||||
rowId === 'prototype'
|
rowId === 'prototype'
|
||||||
) {
|
) {
|
||||||
throw new Error('Invalid rowId');
|
console.error('Invalid rowId');
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
if (
|
||||||
|
columnId === '__proto__' ||
|
||||||
|
columnId === 'constructor' ||
|
||||||
|
columnId === 'prototype'
|
||||||
|
) {
|
||||||
|
console.error('Invalid columnId');
|
||||||
|
return;
|
||||||
}
|
}
|
||||||
const hasRow = rowId in model.cells;
|
const hasRow = rowId in model.cells;
|
||||||
if (!hasRow) {
|
if (!hasRow) {
|
||||||
model.cells[rowId] = Object.create(null);
|
model.cells[rowId] = Object.create(null);
|
||||||
}
|
}
|
||||||
model.doc.transact(() => {
|
model.cells[rowId][columnId] = {
|
||||||
model.cells[rowId][cell.columnId] = {
|
columnId: columnId,
|
||||||
columnId: cell.columnId,
|
|
||||||
value: cell.value,
|
value: cell.value,
|
||||||
};
|
};
|
||||||
});
|
});
|
||||||
|
|||||||
Reference in New Issue
Block a user