fix: restore req/res prototypes when a mounted app hands control back - #7428
Open
lazerg wants to merge 2 commits into
Open
fix: restore req/res prototypes when a mounted app hands control back#7428lazerg wants to merge 2 commits into
lazerg wants to merge 2 commits into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
app.handleswaps thereq/resprototypes for its own, but onlyapp.use()puts them back, inside themounted_appclosure it wraps around a sub-app. Mount an app withrouter.use()instead and the swap is never undone, so every middleware that runs after the sub-app callsnext()readsreq.app,req.ip,req.secureandreq.hostnamethrough the sub-app's settings rather than the parent's.app.handlenow saves the prototypes it replaces and restores them before invoking the callback it was handed, so the cleanup happens on whichever path the app was mounted through. The issue suggested patchingrestore()insiderouter, but the swap originates here, and doing it here also covers any other caller that passes a callback without needing arouterrelease.This covers the prototype half of #7427 only. A router-mounted app still gets no
mountevent and so does not inherittrust proxy, which would needrouterto know about express apps.Fixes #7427