ADK for TypeScript: API Reference
    Preparing search index...

    Function trimTempState

    • Removes temporary state keys from the state.

      The result is a null-prototype map. state comes straight off the request body on a dev server (POST /apps/:appName/users/:userId/sessions/:sessionId), and JSON.parse makes __proto__ an own key, so copying it into a plain object literal would invoke the inherited __proto__ setter: the entry is dropped and the new state object is re-parented onto the attacker's object. State.get/State.has use the in operator, so every key on that object would then read back as session state.

      Parameters

      • state: Record<string, unknown>

      Returns Record<string, unknown>