
Research
/Security News
Critical Vulnerability in NestJS Devtools: Localhost RCE via Sandbox Escape
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
clean-element
Advanced tools
React HOC for removing styled-system props from underlying DOM elements
npm i clean-element
Styled-components and other libraries attempt to remove invalid HTML attributes from props using a whitelist, but do not remove width, fontSize, color, or other valid HTML attributes when used as props.
To ensure that style props are not passed on to the underlying DOM element, even in cases where a prop is a valid HTML attribute, like width or align, use the cleanElement higher order component to create a base component that remove props defined in propTypes.
import styled from 'styled-components'
import { textAlign, propTypes } from 'styled-system'
import cleanElement from 'clean-element'
const CleanDiv = cleanElement('div')
// props that are defined as propTypes are removed
CleanDiv.propTypes = {
...propTypes.textAlign
}
const Box = styled(CleanDiv)`
${textAlign}
`
// <Box align='center' />
// `align` prop is picked up by styled-components,
// but not passed on to the HTML element
Manually omitting props
As an alternative to using the cleanElement
function, removing style props from styled-components can be done manually, with a more React-like approach.
import React from 'react'
import styled from 'styled-components'
import { width, color } from' styled-system'
const Box = styled(({
width,
color,
bg,
...props
}) => <div {...props} />)`
${width}
${color}
`
See this discussion for more information: https://github.com/styled-components/styled-components/issues/439
FAQs
React HOC for removing styled-system props from underlying DOM elements
The npm package clean-element receives a total of 926 weekly downloads. As such, clean-element popularity was classified as not popular.
We found that clean-element demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
Product
Customize license detection with Socket’s new license overlays: gain control, reduce noise, and handle edge cases with precision.
Product
Socket now supports Rust and Cargo, offering package search for all users and experimental SBOM generation for enterprise projects.