fix: protect method names from token registration collisions - #359
Open
baima365-web wants to merge 2 commits into
Open
fix: protect method names from token registration collisions#359baima365-web wants to merge 2 commits into
baima365-web wants to merge 2 commits into
Conversation
Prevent token registration from overwriting module methods (token,
format, compile) by making them non-writable. Previously, calling
morgan.token('token', fn) would overwrite the morgan.token() method,
breaking subsequent token registrations.
Fixes expressjs#265
UlisesGascon
approved these changes
Aug 26, 2026
UlisesGascon
left a comment
Member
There was a problem hiding this comment.
LGTM! WDYT @jonchurch @bjohansebas ?
Merged
bjohansebas
approved these changes
Aug 27, 2026
bjohansebas
left a comment
Member
There was a problem hiding this comment.
LGTM, should we add tests?
krzysdz
reviewed
Aug 27, 2026
krzysdz
left a comment
There was a problem hiding this comment.
While this prevents accidentally overwriting important functions, there are still some rather unexpected behaviours:
- There is completely no information that the given token or format cannot be defined (this will become clear if someone tries to use it, but may be hard to debug).
- Formats and tokens can overwrite each other. While overwriting a token with a different token with the same name or overwriting a format with a different format using the same name (like I have previously suggested in #303 (comment), so #377 now depends on this behaviour) is something that IMO should be possible, format-token collisions should not happen.
Would it be a breaking change if formats and tokens were not defined directly as morgan properties, but instead lived separately as morgan.tokens and morgan.formats or something similar? This would allow using any names (no conflicts with the morgan functions) and get rid of collisions.
Lines 492 to 495 in 51007f9
Lines 579 to 582 in 51007f9
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Calling
morgan.token('token', fn)overwrites themorgan.token()method itself, breaking all subsequent token registrations. This is becausemorganserves as both the module export (with methodstoken,format,compile) and the token registry.Example:
Fix
Make the
token,format, andcompilemethods non-writable usingObject.defineProperties. This prevents user token registrations from overwriting the module API while maintaining full backward compatibility.Test plan