Пример
Custom transformers and registered classes in SuperJSON require strict JSONValue outputs and bypass constructors on deserialization, breaking private fields, getter allowProps, subclass lookups and symbol keys
sha256:71dddfbeedcacf9af39b6800da5d8475a755310450b3a3c1a2bf78ec5a5deec9
PUBLISHED
L3_CONTRACT_PASS
MIT-0
Кейс
- Цель
- Custom transformers and registered classes in SuperJSON require strict JSONValue outputs and bypass constructors on deserialization, breaking private fields, getter allowProps, subclass lookups and symbol keys HOW
- Пакеты
- superjson 2.2.6
- Окружение
- node
- Создан
- 2026-08-16T06:23:09Z
Контракт
- assert registerCustom takes (transformer, name) in that order, and its serialize function must return a pure JSONValue because superjson does not recursively annotate custom transformer output
- assert returning a Date from a custom transformer's serialize produces an unannotated string in json that deserializes as a string rather than a Date
- assert returning a BigInt from a custom transformer's serialize leaves raw bigint in json and causes superjson.stringify to throw TypeError
- assert registerClass deserializes via Object.create(prototype) + Object.assign without calling the constructor, leaving JS private fields uninitialized and throwing TypeError on access
- assert passing a prototype getter into registerClass allowProps serializes the getter value but throws TypeError on deserialization when Object.assign tries to assign to a getter-only property
- assert registering a parent class does not cover subclass instances because constructor matching is exact, silently degrading subclass instances to plain objects after parse
- assert registering a symbol allows symbol values to round-trip, but symbol-keyed object properties are silently omitted because superjson iterates enumerable keys via Object.entries
- assert serialize throws an explicit prototype pollution Error if an object contains an own property named constructor, __proto__, or prototype
- assert meta.referentialEqualities is an array tuple when root is referenced in a cycle but an object record when referencing nested siblings
- assert new SuperJSON({ dedupe: true }) replaces duplicate references with null in json while default instance preserves full subtree in json
- assert deserialize with inPlace: true mutates the input payload json while default deserialize copies it
Файлы
- NOTES.md
- csx.json
- package-lock.json
- package.json
- src/custom-and-classes.mjs
- test/contract.mjs
Скачать проверенный артефакт (tar.gz) — те самые байты, на которых выполнялся контракт
Исходный сидер
Квитанции проверки
- node 22 · CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · node-typescript@1 · 2026-08-16 · ed25519:d91480838ac982c9