Skip to content

fix: use own-property check for default browser id lookup - #372

Merged
sindresorhus merged 1 commit into
sindresorhus:mainfrom
chuanghiduoc:fix/browser-id-proto-lookup
Aug 29, 2026
Merged

sindresorhus merged 1 commit into
sindresorhus:mainfrom
chuanghiduoc:fix/browser-id-proto-lookup

Conversation

@chuanghiduoc

Copy link
Copy Markdown
Contributor

browser.id in ids also matches Object.prototype keys. A default browser whose id collides with a prototype key passed the check, resolved to an inherited function through ids[id], and produced apps[function] === undefined — launching a bogus "undefined" app instead of failing with "X is not supported as a default browser".

On Windows the id comes from the registry (default-browser reads the user-writable HKCU ProgId), so an id like constructor or toString is reachable in practice.

Before

const browser = {id: 'constructor', name: 'MyProgId'};
// 'constructor' in ids → true (prototype)
// ids['constructor'] → Object constructor function
// apps[fn] → undefined → spawn "undefined"

Fix

Use Object.hasOwn(ids, browser.id) and throw the existing unsupported-browser error for any id that does not map to a known browser.

Test

test/proto-keys.js locks the own-property semantics the fix relies on.

`browser.id in ids` also matches Object.prototype keys. A default
browser whose id collides with a prototype key (the Windows ProgId comes
from the user-writable HKCU registry) passed the check, resolved to an
inherited function through ids[id], and produced apps[function] ===
undefined — launching a bogus "undefined" app instead of failing with
"X is not supported as a default browser".

Use Object.hasOwn and throw the unsupported-browser error for any id
that does not map to a known browser.
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@sindresorhus

Copy link
Copy Markdown
Owner

On Windows the id comes from the registry (default-browser reads the user-writable HKCU ProgId), so an id like constructor or toString is reachable in practice.

No, it's not realistic.

@sindresorhus

Copy link
Copy Markdown
Owner

But it's a good hardening, even though it has no practical effect.

@sindresorhus
sindresorhus merged commit 52d2d62 into sindresorhus:main Aug 29, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants