Home | History | Annotate | Download | only in number-format
      1 // Copyright 2013 the V8 project authors. All rights reserved.
      2 // Redistribution and use in source and binary forms, with or without
      3 // modification, are permitted provided that the following conditions are
      4 // met:
      5 //
      6 //     * Redistributions of source code must retain the above copyright
      7 //       notice, this list of conditions and the following disclaimer.
      8 //     * Redistributions in binary form must reproduce the above
      9 //       copyright notice, this list of conditions and the following
     10 //       disclaimer in the documentation and/or other materials provided
     11 //       with the distribution.
     12 //     * Neither the name of Google Inc. nor the names of its
     13 //       contributors may be used to endorse or promote products derived
     14 //       from this software without specific prior written permission.
     15 //
     16 // THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
     17 // "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
     18 // LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
     19 // A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
     20 // OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
     21 // SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
     22 // LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
     23 // DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
     24 // THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
     25 // (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
     26 // OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
     27 
     28 // Checks for security holes introduced by Object.property overrides.
     29 // For example:
     30 // Object.defineProperty(Array.prototype, 'locale', {
     31 //   set: function(value) {
     32 //     throw new Error('blah');
     33 //   },
     34 //   configurable: true,
     35 //   enumerable: false
     36 // });
     37 //
     38 // would throw in case of (JS) x.locale = 'us' or (C++) x->Set('locale', 'us').
     39 //
     40 // Update both number-format.js and number-format.cc so they have the same
     41 // list of properties.
     42 
     43 // First get supported properties.
     44 var properties = [];
     45 // Some properties are optional and won't show up in resolvedOptions if
     46 // they were not requested - currency, currencyDisplay,
     47 // minimumSignificantDigits and maximumSignificantDigits - so we request them.
     48 var options = Intl.NumberFormat(
     49   undefined, {style: 'currency', currency: 'USD', currencyDisplay: 'name',
     50               minimumSignificantDigits: 1, maximumSignificantDigits: 5}).
     51     resolvedOptions();
     52 for (var prop in options) {
     53   if (options.hasOwnProperty(prop)) {
     54     properties.push(prop);
     55   }
     56 }
     57 
     58 var expectedProperties = [
     59   'style', 'locale', 'numberingSystem',
     60   'currency', 'currencyDisplay', 'useGrouping',
     61   'minimumIntegerDigits', 'minimumFractionDigits',
     62   'maximumFractionDigits', 'minimumSignificantDigits',
     63   'maximumSignificantDigits'
     64 ];
     65 
     66 assertEquals(expectedProperties.length, properties.length);
     67 
     68 properties.forEach(function(prop) {
     69   assertFalse(expectedProperties.indexOf(prop) === -1);
     70 });
     71 
     72 taintProperties(properties);
     73 
     74 var locale = Intl.NumberFormat(undefined,
     75                                {currency: 'USD', currencyDisplay: 'name',
     76                                 minimumIntegerDigits: 2,
     77                                 numberingSystem: 'latn'}).
     78     resolvedOptions().locale;
     79