Comments (6)
This has a possible security issue: if you pass a user-provided string as the first child of a component without props, the user may be able to misuse your API, allowing them to insert any props theyโd like into the component.
from rfcs.
Here is user space solution:
const h = React.createElement;
React.createElement = (type, props, ...children) => {
if (typeof props !== 'object') {
children = [props, ...children];
props = {};
}
return h(type, props, ...children);
};
from rfcs.
There's a library directly linked to by the React documentation that offers the syntax you're looking for.
https://github.com/mlmorg/react-hyperscript
from rfcs.
@streamich Thank you for your code:
typeof == 'object'
does not distinguish between arrays and objects (both are true)- children can be an object as well
- my own user space solution checks if the first key in the object is
$$typeof
- this is still very crude, could you improve my code?
@dantman hyperscript needs the children to be in an array, createElement doesn't, so using it actually adds a bit more overhead, that's why I'm looking to use createElement itself, or is it easy to turn off arrays in hyperscript somehow?
from rfcs.
@Superpencil Seems like a pretty small difference, but it does look like there is an issue on the topic and there is a branch in the repo linked that implements the behaviour you want.
I'd think it would be easier to convince the library to implement the behaviour you want than to get React to change how the API works for a use case that React.createElement isn't intended for.
from rfcs.
@dantman you're right, it's a small difference, I'll pursue the issue there, thank you!
@j-f1 Thank you! I was sharing my code in the hope someone would be able to point out some security issue :)
from rfcs.
Related Issues (20)
- onScroll event propagation HOT 5
- [Feature Request]: distinguish "what" and "when" dependencies in useEffect HOT 2
- [Feature Request] Return ref rather than forwardRef HOT 1
- the ability to check if something is function or class or an arrow function HOT 5
- npx-create-react-app creating a folder tempnodejsnpm HOT 2
- [Feature Request] Can we do some Static Analysis for diff with babel ๏ผ HOT 6
- Improving the RFC workflow process HOT 18
- useIf: Conditional hooks HOT 6
- Is useReducer an overengineering? HOT 10
- Improve profiling react applications HOT 1
- Introduce GUI tooling to speed up web application development HOT 1
- [React Server Components] Idea to simplify overall design HOT 11
- psql: could not connect to server: No such file or directory HOT 1
- [Question] The new JSX transform HOT 1
- [Feature Request]: Add array of updated deps indices to `useEffect` hooks arg HOT 1
- [Feature Request]: React Hooks `Equality` **AKA:** `[isEqual]` Callback HOT 3
- Functional Attribute/Prop Node HOT 2
- [Feature Request][eslint-plugin-react-hooks] no-ref-checks, display error when using useRef's return value as condition HOT 1
- [Feature Request]: useStateRef HOT 5
- Typo: 'exiting' might be 'existing' HOT 2
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
๐ Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. ๐๐๐
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google โค๏ธ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from rfcs.