Conversation
Currently the result of an or-array is forgotten if anything comes after it. for example, this case fails with the relation `and`: `[[false, false], true]` As a logic expression it is expressed as `(false || false) && true`, which is `false` but the authentication process accepts it. I generated multiple tests to find more example of error cases and see if any other existed. And added it to the test cases to prevent regression. Signed-off-by: TitouanT <titouan.teyssier@gmail.com>
|
Failing cases of the tests I added before the fix (shortened the output): ✖ failing tests:
test at test/logic-gate.test.js:28:5
✖ Relation and for expression [true,[false,false],true,true] (1.651285ms)
AssertionError [ERR_ASSERTION]: true == false
{
generatedMessage: true,
code: 'ERR_ASSERTION',
actual: true,
expected: false,
operator: '==',
diff: 'simple'
}
test at test/logic-gate.test.js:28:5
✖ Relation and for expression [true,[false,false],true] (0.296815ms)
AssertionError [ERR_ASSERTION]: true == false
test at test/logic-gate.test.js:28:5
✖ Relation and for expression [true,[false,false],[false,true]] (0.332723ms)
AssertionError [ERR_ASSERTION]: true == false
test at test/logic-gate.test.js:28:5
✖ Relation and for expression [true,[false,false],[true,false]] (0.275936ms)
AssertionError [ERR_ASSERTION]: true == false
test at test/logic-gate.test.js:28:5
✖ Relation and for expression [true,[false,false],[true,true]] (0.330319ms)
AssertionError [ERR_ASSERTION]: true == false
test at test/logic-gate.test.js:28:5
✖ Relation and for expression [[false,false],true] (0.361428ms)
AssertionError [ERR_ASSERTION]: true == false
test at test/logic-gate.test.js:28:5
✖ Relation and for expression [[false,false],[false,true]] (0.359024ms)
AssertionError [ERR_ASSERTION]: true == false
test at test/logic-gate.test.js:28:5
✖ Relation and for expression [[false,false],[true,false]] (0.195352ms)
AssertionError [ERR_ASSERTION]: true == false
test at test/logic-gate.test.js:28:5
✖ Relation and for expression [[false,false],[true,true]] (0.189361ms)
AssertionError [ERR_ASSERTION]: true == false
test at test/logic-gate.test.js:28:5
✖ Relation and for expression [[false],true] (0.331511ms)
AssertionError [ERR_ASSERTION]: true == falseThey all fail only when the main relation is The test transforms a given boolean expression into a chain of auth functions that will pass if the boolean is true and fail if the boolean is false. |
|
Apparaently someone else 'found' that bug and fixed it in 5.1.1 |
|
Sorry! I received a vulnerability and I published the advisory. I had sol generate the test and most of the fix. If you want to send a fuzzer PR, go ahead! |
Currently the result of an or-array is forgotten if anything comes after it.
for example, this case fails with the relation
and:[[false, false], true]As a logic expression it is expressed as(false || false) && true, which isfalsebut the authentication process accepts it.I generated multiple tests to find more example of error cases and see if any other existed. And added it to the test cases to prevent regression.
Checklist
npm run test && npm run benchmark --if-presentand the Code of conduct