
Research
Security News
The Growing Risk of Malicious Browser Extensions
Socket researchers uncover how browser extensions in trusted stores are used to hijack sessions, redirect traffic, and manipulate user behavior.
proxy-polyfill
Advanced tools
This is a polyfill for the Proxy
object, part of ES6.
See the MDN docs or Introducing ES2015 Proxies for more information on Proxy
itself.
Unlike other polyfills, this does not require Object.observe
, which is deprecated.
The polyfill supports just a limited number of proxy 'traps'.
It also works by calling seal on the object passed to Proxy
.
This means that the properties you want to proxy must be known at creation time.
Additionally, your objects' prototypes will be snapshotted at the time a proxy is created. The properties of your objects can still change - you're just unable to define new ones. For example, proxying unrestricted dictionaries is not a good use-case for this polyfill.
Currently, the following traps are supported-
The Proxy.revocable
method is also supported, but only for calls to the above traps.
This has no external dependencies. Skip down to usage to get started.
The most compelling use case for Proxy
is to provide change notifications.
function observe(o, fn) {
return new Proxy(o, {
set(target, property, value) {
fn(property, value);
target[property] = value;
},
})
}
let x = {'name': 'BB-8'};
let p = observe(x, function(property, value) { console.info(property, value) });
p.name = 'BB-9';
// name BB-9
You can extend this to generate change notifications for anywhere in an object tree-
function observe(o, fn) {
function buildProxy(prefix, o) {
return new Proxy(o, {
set(target, property, value) {
// same as before, but add prefix
fn(prefix + property, value);
target[property] = value;
},
get(target, property) {
// return a new proxy if possible, add to prefix
let out = target[property];
if (out instanceof Object) {
return buildProxy(prefix + property + '.', out);
}
return out; // primitive, ignore
},
});
}
return buildProxy('', o);
}
let x = {'model': {name: 'Falcon'}};
let p = observe(x, function(property, value) { console.info(property, value) });
p.model.name = 'Commodore';
// model.name Commodore
The following line will fail (with a TypeError
in strict mode) with the polyfill, as it's unable to intercept new properties-
p.model.year = 2016; // error in polyfill
However, you can replace the entire object at once - once you access it again, your code will see the proxied version.
p.model = {name: 'Falcon', year: 2016};
// model Object {name: "Falcon", year: 2016}
Include the JavaScript at the start of your page, as an ES6 module (although browsers that support ES6 modules support Proxy
natively) or include it as a dependency to your build steps.
The source is in ES6, but the included, minified version is ES5.
Available via NPM or Bower-
$ npm install proxy-polyfill
$ bower install proxy-polyfill
If this is imported as a Node module, it will polyfill the global namespace rather than returning the Proxy
object.
The polyfill supports browsers that implement the full ES5 spec, such as IE9+ and Safari 6+.
Firefox, Chrome, Safari 10+ and Edge support Proxy
natively.
Compile code with Closure Compiler.
// ==ClosureCompiler==
// @compilation_level ADVANCED_OPTIMIZATIONS
// @output_file_name proxy.min.js
// ==/ClosureCompiler==
// code here
FAQs
Polyfill for the Proxy object
We found that proxy-polyfill demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover how browser extensions in trusted stores are used to hijack sessions, redirect traffic, and manipulate user behavior.
Research
Security News
An in-depth analysis of credential stealers, crypto drainers, cryptojackers, and clipboard hijackers abusing open source package registries to compromise Web3 development environments.
Security News
pnpm 10.12.1 introduces a global virtual store for faster installs and new options for managing dependencies with version catalogs.