Skip to content

Commit ea807a7

Browse files
bajrangCoderclaude
andcommitted
fix: validate worker action with Map.has and a function check
Follow CodeQL's recommended pattern for js/unvalidated-dynamic-method-call: check the name with Map.prototype.has and verify the handler is a function before calling it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 parent d1d79da commit ea807a7

2 files changed

Lines changed: 4 additions & 2 deletions

File tree

‎plugin.zip‎

49 Bytes
Binary file not shown.

‎src/worker.js‎

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -123,9 +123,11 @@ __builtins__.input = input
123123
);
124124

125125
self.onmessage = async (e) => {
126-
const handler = actions.get(e.data.action);
126+
const { action } = e.data;
127+
if (!actions.has(action)) return;
127128

128-
if (handler) {
129+
const handler = actions.get(action);
130+
if (typeof handler === "function") {
129131
await handler(e.data);
130132
}
131133
};

0 commit comments

Comments
 (0)