diff --git a/index.js b/index.js index 8ddc89b..43a0be9 100644 --- a/index.js +++ b/index.js @@ -319,7 +319,7 @@ module.exports = function serialize(obj, options) { if (type === 'D') { // Validate ISO string format to prevent code injection via spoofed toISOString() var isoStr = String(dates[valueIndex].toISOString()); - if (!/^\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}(\.\d{3})?Z$/.test(isoStr)) { + if (!/^(?:\d{4}|[+-]\d{6})-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}(\.\d{3})?Z$/.test(isoStr)) { throw new TypeError('Invalid Date ISO string'); } return "new Date(\"" + isoStr + "\")"; diff --git a/test/unit/expanded-date-years.js b/test/unit/expanded-date-years.js new file mode 100644 index 0000000..b2a86ef --- /dev/null +++ b/test/unit/expanded-date-years.js @@ -0,0 +1,14 @@ +const { describe, it } = require('node:test'); +const { strictEqual } = require('node:assert'); +const serialize = require('../../'); + +describe('Dates with expanded ISO years', function () { + for (const timestamp of [-8640000000000000, -62198755200000, 253402300800000, 8640000000000000]) { + it('round trips timestamp ' + timestamp, function () { + const date = new Date(timestamp); + const decoded = eval('(' + serialize(date) + ')'); + strictEqual(decoded.getTime(), date.getTime()); + strictEqual(decoded.toISOString(), date.toISOString()); + }); + } +});