Skip to content

Commit 9e4a00d

Browse files
committed
fix(audits): treat logical and conditional partialize returns of the whole state as leaks
1 parent 4322e38 commit 9e4a00d

1 file changed

Lines changed: 7 additions & 0 deletions

File tree

‎scripts/check-zustand-v5-selectors.ts‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -346,6 +346,13 @@ function isIdentifierNamed(node: unknown, name: string): boolean {
346346
function isWholeBinding(node: unknown, name: string): boolean {
347347
if (isIdentifierNamed(node, name)) return true
348348
const unwrapped = unwrapExpression(node)
349+
// `state || {}`, `state ?? {}`, and `cond ? state : {}` can each return the whole state.
350+
if (isSyntaxNode(unwrapped) && unwrapped.type === 'LogicalExpression') {
351+
return isWholeBinding(unwrapped.left, name) || isWholeBinding(unwrapped.right, name)
352+
}
353+
if (isSyntaxNode(unwrapped) && unwrapped.type === 'ConditionalExpression') {
354+
return isWholeBinding(unwrapped.consequent, name) || isWholeBinding(unwrapped.alternate, name)
355+
}
349356
if (!isSyntaxNode(unwrapped) || unwrapped.type !== 'ObjectExpression') return false
350357
const properties = Array.isArray(unwrapped.properties) ? unwrapped.properties : []
351358
return properties.some(

0 commit comments

Comments
 (0)