pull/18856/merge
Rich Harris 3 days ago committed by GitHub
commit edcd8242aa
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

@ -0,0 +1,5 @@
---
'svelte': patch
---
chore: bump devalue

@ -179,7 +179,7 @@
"aria-query": "5.3.1",
"axobject-query": "^4.1.0",
"clsx": "^2.1.1",
"devalue": "^5.9.2",
"devalue": "^6.0.2",
"esm-env": "^1.2.1",
"esrap": "^2.3.6",
"is-reference": "^3.0.3",

@ -1,3 +1,4 @@
/** @import { UnevalReplacer } from 'devalue' */
/** @import { HydratableLookupEntry } from '#server' */
import { async_mode_flag } from '../flags/index.js';
import { get_render_context } from './render-context.js';
@ -54,22 +55,24 @@ function encode(key, value, unresolved) {
let uid = 1;
entry.serialized = devalue.uneval(entry.value, (value, uneval) => {
/** @type {UnevalReplacer} */
const replacer = (value, js) => {
if (is_promise(value)) {
// we serialize promises as `"${i}"`, because it's impossible for that string
// to occur 'naturally' (since the quote marks would have to be escaped)
// this placeholder is returned synchronously from `uneval`, which includes it in the
// serialized string. Later (at least one microtask from now), when `p.then` runs, it'll
// be replaced.
const placeholder = `"${uid++}"`;
const placeholder = `${uid++}`;
const quoted = devalue.uneval(placeholder);
const p = value
.then((v) => {
entry.serialized = entry.serialized.replace(
placeholder,
quoted,
// use the function form here to prevent any string replacement characters from being interpreted
// in `v`, as it's potentially user-controlled and therefore potentially malicious.
// https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/String/replace#specifying_a_string_as_the_replacement
() => `r(${uneval(v)})`
() => `r(${devalue.uneval(v, replacer)})`
);
})
.catch((devalue_error) =>
@ -84,9 +87,11 @@ function encode(key, value, unresolved) {
p.catch(() => {}).finally(() => unresolved?.delete(p));
(entry.promises ??= []).push(p);
return placeholder;
return js`${placeholder}`;
}
});
};
entry.serialized = devalue.uneval(entry.value, replacer);
return entry;
}

@ -93,8 +93,8 @@ importers:
specifier: ^2.1.1
version: 2.1.1
devalue:
specifier: ^5.9.2
version: 5.9.2
specifier: ^6.0.2
version: 6.0.2
esm-env:
specifier: ^1.2.1
version: 1.2.1
@ -1282,8 +1282,9 @@ packages:
engines: {node: '>=0.10'}
hasBin: true
devalue@5.9.2:
resolution: {integrity: sha512-po4PAY5c53tw5XMocSnf8A/5OHhbbUftpr93aEN6BBoAdntUmK7vu7wOATqvt7cXO7m1Cl4gMVn6p7n6n4mj0w==}
devalue@6.0.2:
resolution: {integrity: sha512-6V1HzU4to74skg//ScZR2mp9bdz+rESC9jQzVIIG/ha0HYgymHcXIQQCjH0+ivRaSuY82fa9fZ7Ro6QZT4s4uw==}
engines: {node: '>=22.17'}
dir-glob@3.0.1:
resolution: {integrity: sha512-WkrWp9GR4KXfKGYzOLmTuGVi1UWFfws377n9cc55/tb6DuqyF6pcQ5AbiHEshaDpY9v6oaSr2XCDidGmMwdzIA==}
@ -3433,7 +3434,7 @@ snapshots:
detect-libc@1.0.3:
optional: true
devalue@5.9.2: {}
devalue@6.0.2: {}
dir-glob@3.0.1:
dependencies:

Loading…
Cancel
Save