Description
The public AppRegistry stores app and section keys in plain object literals. Looking up an unregistered key such as constructor returns an inherited Object member. Registering the valid string key __proto__ mutates the registry prototype rather than creating an own entry, so the app/section key lists omit it.
The defect is present in React Native 0.87.1 and current main.
Steps to reproduce
Call AppRegistry.getRunnable("constructor"), then register an app or section named __proto__ and inspect getAppKeys() / getSectionKeys().
Expected behavior
Only explicitly registered keys should resolve, and all string app/section keys should be stored as ordinary own entries.
React Native Version
0.87.1 and current main.
Description
The public AppRegistry stores app and section keys in plain object literals. Looking up an unregistered key such as
constructorreturns an inheritedObjectmember. Registering the valid string key__proto__mutates the registry prototype rather than creating an own entry, so the app/section key lists omit it.The defect is present in React Native 0.87.1 and current main.
Steps to reproduce
Call
AppRegistry.getRunnable("constructor"), then register an app or section named__proto__and inspectgetAppKeys()/getSectionKeys().Expected behavior
Only explicitly registered keys should resolve, and all string app/section keys should be stored as ordinary own entries.
React Native Version
0.87.1 and current main.