Skip to content

fix(plugin-grid): guard useRowColor's object-literal lookups with hasOwnProperty - #6381

Merged
os-support-ai merged 2 commits into
mainfrom
claude/issue-6295-rowcolor-prototype-guard
Aug 25, 2026
Merged

fix(plugin-grid): guard useRowColor's object-literal lookups with hasOwnProperty#6381
os-support-ai merged 2 commits into
mainfrom
claude/issue-6295-rowcolor-prototype-guard

Conversation

@os-support-ai

Copy link
Copy Markdown
Collaborator

Fixes#6295

useRowColor reached two plain object literals with a bare index, and both inherit Object.prototype. Both reads are now guarded with Object.prototype.hasOwnProperty.call, mirroring the guard #6178 / PR #6294 applied to the analogous lookup in packages/plugin-detail/src/headerColor.ts.

The two halves

config.colors[value] (:67) — the loud half. Indexed with record data. A record whose colour field held constructor / toString / valueOf / hasOwnProperty resolved to an inherited function; if (!color) passed it (functions are truthy) and colorToClass then called .startsWith on it — TypeError: color.startsWith is not a function, thrown inside the row-className resolver during render. A grid crash triggered by data rather than by metadata. The authored map does not have to mention the value: an empty colors: {} crashes just the same, which this PR pins.

COLOR_TO_CLASS[lower] (:52) — the quiet half. Same shape one call deeper, reached with the authored colour value. It never threw; it returned the inherited member, so a function left the resolver as the row's className and reached React as a class attribute. Fixing only the thrower would have left this.

Both now resolve to undefined, exactly as an undeclared value always did.

Object.hasOwn is ES2022 and is not available here — verified rather than assumed: tsconfig.json (which packages/plugin-grid/tsconfig.json extends without overriding) sets "lib": ["ES2020", "DOM", "DOM.Iterable"]. Worth noting for the next reader: packages/plugin-grid/tsconfig.test.json deliberately sits one notch above at ES2022, so Object.hasOwnwould have compiled in a test while failing in shipped source.

Ghost-assertion guard — both readings

New assertions run against unmodified origin/main (fix not yet applied), then against the fix. Same file, same command.

Before — 13 failed | 3 passed (16):

FAIL ... (:67, the loud half) > does not throw when a record colour field holds `constructor`
AssertionError: expected [Function] to not throw an error but
'TypeError: color.startsWith is not a …' was thrown
FAIL ... (:52, the quiet half) > returns undefined when the authored colour value is constructor
AssertionError: expected [Function Object] to be undefined
- Expected: undefined
+ Received: [Function Object]
FAIL ... (:52, the quiet half) > returns undefined when the authored colour value is __proto__
AssertionError: expected { …(12) } to be undefined
+ Received: {}

TypeError: color.startsWith is not a function appears 4× in that run. All 13 failures are in the two defect describes; the 3 that passed are the control below.

After — 16 passed (16):

 Test Files 1 passed (1)
Tests 16 passed (16)

Degenerate control

The control fixture is CONTROL_CONFIG{ field: 'status', colors: { open: 'green', closed: 'red', urgent: 'bg-red-200' } } — in useRowColor — ordinary lookups still work (degenerate control). Its three tests (openbg-green-100, closedbg-red-100, the bg-* pass-through, and an undeclared value → undefined) are the 3 that were green both before and after, so the guard is shown not to have switched ordinary lookups off.

One deliberate asymmetry, called out so nobody "helpfully" widens it into ghost assertions: the quiet half asserts only constructor and __proto__, not the full eight. colorToClass lower-cases before indexing, so toString arrives as tostring, valueOf as valueof, and so on — none of which is an inherited member. Measured on unmodified main, those six return undefined there too, so asserting them would assert nothing. Only the two already-lower-case names actually reach Object.prototype. The loud half indexes the record value verbatim, so all eight apply there and all eight are pinned.

Verification

All readings below are from the final commit, e9f263574 (after merging origin/main).

CheckResult
pnpm exec vitest run packages/plugin-grid/Test Files 91 passed (91) / Tests 853 passed (853), exit 0
pnpm --filter @object-ui/plugin-grid type-checkexit 0 (tsc --noEmit && tsc -p tsconfig.test.json)
pnpm --filter @object-ui/plugin-grid lint✖ 691 problems (0 errors, 691 warnings), exit 0
node scripts/check-changeset-presence.mjs✅ 2 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s)

Lint delta measured, not assumed.useRowColor.ts carries two warnings (react-hooks/preserve-manual-memoization, @typescript-eslint/no-explicit-any). Both are pre-existing: eslint --format json on the file at origin/main and at this branch returns identical per-rule counts ({preserve-manual-memoization: 1, no-explicit-any: 1}, errorCount=0 both). This change introduces no new lint finding.

Typecheck coverage proven, not inferred.packages/plugin-grid/tsconfig.json excludes **/__tests__/**, so "typecheck clean" could have been true while saying nothing about the new test. tsc --listFiles confirms both changed files are real program inputs — useRowColor.prototypeGuard.test.tsx in the tsconfig.test.json program, useRowColor.ts in the build program.

Declared narrowing. Local verification is scoped to @object-ui/plugin-grid (its full suite, its typecheck, its lint) plus the repo-wide changeset-presence check — not a repo-wide pnpm lint/pnpm test. CI runs the full farm regardless; this is a declared narrowing, not a skipped check.

Scope

packages/plugin-grid/src/useRowColor.ts (the two index reads only), one new test file, one changeset. The colour-resolution flow, the authored colors map shape, and plugin-detail's already-fixed sibling are untouched. No edits to content/docs/releases/.

Draft, and staying draft — the PM lands it.


Generated by Claude Code

…OwnProperty
`useRowColor` reached two plain object literals with a bare index, and both
inherit `Object.prototype`.
`config.colors[value]` is indexed with RECORD DATA, so a record whose colour
field held `constructor`, `toString`, `valueOf` or `hasOwnProperty` resolved to
an inherited function. `if (!color)` passed it (functions are truthy) and
`colorToClass` then called `.startsWith` on it — a TypeError thrown inside the
row-className resolver during render, crashing the grid on data rather than on
metadata.
`COLOR_TO_CLASS[lower]` one call deeper has the same shape and is the quieter
half: it never threw, it handed an `Object.prototype` member back as the row's
`className`, which reached React as a class attribute.
Both reads now go through `Object.prototype.hasOwnProperty.call` and resolve to
`undefined`, exactly as an undeclared value always did. (`Object.hasOwn` is
ES2022; this workspace compiles against the ES2020 lib.) Mirrors the guard
objectui#6178 / PR objectui#6294 applied to the analogous lookup in
`packages/plugin-detail/src/headerColor.ts`.
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3224.3 KB3266.6 KB
Main entry chunk (gzip)154.1 KB350 KB
Entry fileindex-iu-9whwf.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)10.96KB4.16KB
app-shell (runtime-config.js)18.10KB6.51KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)505.84KB114.57KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)173.18KB47.97KB
fields (index.js)238.89KB60.02KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.66KB12.84KB
plugin-charts (index.js)64.66KB18.32KB
plugin-chatbot (index.js)188.21KB44.67KB
plugin-dashboard (index.js)133.46KB34.48KB
plugin-designer (index.js)211.95KB42.75KB
plugin-detail (index.js)245.10KB62.31KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)128.11KB31.17KB
plugin-gantt (index.js)164.14KB39.87KB
plugin-grid (index.js)201.79KB54.60KB
plugin-kanban (index.js)52.87KB14.57KB
plugin-list (index.js)112.63KB27.45KB
plugin-map (index.js)20.09KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.49KB11.93KB
plugin-timeline (index.js)26.70KB7.69KB
plugin-tree (index.js)9.26KB3.13KB
plugin-view (index.js)84.55KB20.74KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)54.84KB18.43KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.35KB0.70KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)12.13KB3.65KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)7.54KB2.63KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-support-ai
os-support-ai marked this pull request as ready for review August 25, 2026 18:58
@os-support-ai
os-support-ai added this pull request to the merge queueAug 25, 2026
Merged via the queue into main with commit 591bf27Aug 25, 2026
28 checks passed
@os-support-ai
os-support-ai deleted the claude/issue-6295-rowcolor-prototype-guard branch August 25, 2026 19:10
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

useRowColor throws a TypeError when a record's colour field holds an Object.prototype member name (constructor, toString, …)

2 participants

@os-support-ai@claude