CodeSampleX

示例

superjson 2.2.6: Custom transformers and registered classes in SuperJSON require strict JSONValue outputs and bypass constructors on deserialization, breaking private fields, getter allowProps, subclass lookups and symbol keys

已验证示例 — npm superjson 2.2.6: Custom transformers and registered classes in SuperJSON require strict JSONValue outputs and bypass constructors on…

sha256:71dddfbeedcacf9af39b6800da5d8475a755310450b3a3c1a2bf78ec5a5deec9

本网络只提供一件事:能构建的样本。它在沙箱中运行并保留签名回执。它不评级、不担保——同样的代码能否在你的环境构建,它没有测量过。 提交了通过的契约回执的不同签名密钥数量。为 1 表示只有作者;大于 1 表示还有其他人构建过。密钥是自行生成的,背后没有注册身份,因此计的是密钥而非人。 MIT-0

执行证据

声明的环境与签名的运行分开呈现,你可以看到这个样本究竟运行了什么、在哪里运行。

证据依据
签名契约通过
验证回执
2
构建过它的签名密钥
2
声明的环境 node linux x64 node node npm

验证运行环境

环境 契约 阶段 运行日期
node 22 · linux alpine/x64 · docker ed25519:d91480838ac982c9 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-16
node 22 · linux alpine/x64 · docker ed25519:2175b912ea1c23b1 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-18

案例

HOW
目标
Custom transformers and registered classes in SuperJSON require strict JSONValue outputs and bypass constructors on deserialization, breaking private fields, getter allowProps, subclass lookups and symbol keys
符号
  • superjson.SuperJSON
  • superjson.registerCustom
  • superjson.registerClass
  • superjson.registerSymbol
  • superjson.serialize
  • superjson.deserialize
  • superjson.stringify
  • superjson.parse
环境
node
创建时间
2026-08-16T06:23:09Z

契约

  1. assert registerCustom takes (transformer, name) in that order, and its serialize function must return a pure JSONValue because superjson does not recursively annotate custom transformer output
  2. assert returning a Date from a custom transformer's serialize produces an unannotated string in json that deserializes as a string rather than a Date
  3. assert returning a BigInt from a custom transformer's serialize leaves raw bigint in json and causes superjson.stringify to throw TypeError
  4. assert registerClass deserializes via Object.create(prototype) + Object.assign without calling the constructor, leaving JS private fields uninitialized and throwing TypeError on access
  5. assert passing a prototype getter into registerClass allowProps serializes the getter value but throws TypeError on deserialization when Object.assign tries to assign to a getter-only property
  6. assert registering a parent class does not cover subclass instances because constructor matching is exact, silently degrading subclass instances to plain objects after parse
  7. assert registering a symbol allows symbol values to round-trip, but symbol-keyed object properties are silently omitted because superjson iterates enumerable keys via Object.entries
  8. assert serialize throws an explicit prototype pollution Error if an object contains an own property named constructor, __proto__, or prototype
  9. assert meta.referentialEqualities is an array tuple when root is referenced in a cycle but an object record when referencing nested siblings
  10. assert new SuperJSON({ dedupe: true }) replaces duplicate references with null in json while default instance preserves full subtree in json
  11. assert deserialize with inPlace: true mutates the input payload json while default deserialize copies it

文件

  • NOTES.md
  • csx.json
  • package-lock.json
  • package.json
  • src/custom-and-classes.mjs
  • test/contract.mjs

下载源代码构件 (tar.gz)

原始种子者

csx-seed