The result is a null-prototype map. state comes straight off the request
body on a dev server (POST /apps/:appName/users/:userId/sessions/:sessionId),
and JSON.parse makes __proto__ an own key, so copying it into a plain
object literal would invoke the inherited __proto__ setter: the entry is
dropped and the new state object is re-parented onto the attacker's object.
State.get/State.has use the in operator, so every key on that object
would then read back as session state.
Removes temporary state keys from the state.
The result is a null-prototype map.
statecomes straight off the request body on a dev server (POST /apps/:appName/users/:userId/sessions/:sessionId), andJSON.parsemakes__proto__an own key, so copying it into a plain object literal would invoke the inherited__proto__setter: the entry is dropped and the new state object is re-parented onto the attacker's object.State.get/State.hasuse theinoperator, so every key on that object would then read back as session state.