Skip to content
This repository has been archived by the owner on May 10, 2024. It is now read-only.

Fix #8392: Ensure toString returns expected value on Object #8394

Merged
merged 1 commit into from
Nov 13, 2023
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
26 changes: 19 additions & 7 deletions Sources/Brave/Frontend/UserContent/UserScripts/__firefox__.js
Original file line number Diff line number Diff line change
Expand Up @@ -75,6 +75,10 @@ if (!window.__firefox__) {
`function ${ typeof value.name !== 'undefined' ? value.name : "" }() {\n [native code]\n}` :
'[object Object]';

const toStringString = function() {
return 'function toString() {\n [native code]\n}';
};

const toString = function() {
return description;
};
Expand Down Expand Up @@ -103,25 +107,30 @@ if (!window.__firefox__) {
}

// Secure calls to `toString`
const secureToString = function(toString) {
for (const [name, property] of $Object.entries(overrides)) {
let descriptor = $Object.getOwnPropertyDescriptor(toString, name);
const secureToString = function(fn) {
var fnOverrides = {...overrides};
if ((fn === toString || fn === toStringString) && fnOverrides['toString']) {
fnOverrides['toString'] = toStringString;
}

for (const [name, property] of $Object.entries(fnOverrides)) {
let descriptor = $Object.getOwnPropertyDescriptor(fn, name);
if (!descriptor || descriptor.configurable) {
$Object.defineProperty(toString, name, {
$Object.defineProperty(fn, name, {
enumerable: false,
configurable: false,
writable: false,
value: property
});
}

descriptor = $Object.getOwnPropertyDescriptor(toString, name);
descriptor = $Object.getOwnPropertyDescriptor(fn, name);
if (!descriptor || descriptor.writable) {
toString[name] = property;
fn[name] = property;
}

if (name !== 'toString') {
$.deepFreeze(toString[name]);
$.deepFreeze(fn[name]);
}
}

Expand All @@ -130,6 +139,9 @@ if (!window.__firefox__) {

// Secure our custom `toString`
// Freeze our custom `toString`
secureToString(toStringString);
$.deepFreeze(toStringString);

secureToString(toString);
$.deepFreeze(toString);

Expand Down