{"record":{"id":"d429942e5365e626","repo":"sidorares/node-mysql2","slug":"the-field-name-field-can-t-be-the-same-as-an","errorCode":null,"errorMessage":"The field name (${field}) can't be the same as an object's private property.","messagePattern":"The field name \\((.+?)\\) can't be the same as an object's private property\\.","errorType":"validation","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"lib/helpers.js","lineNumber":76,"sourceCode":"\n  return !!list;\n}\n\nexports.typeMatch = typeMatch;\n\nconst privateObjectProps = new Set([\n  '__defineGetter__',\n  '__defineSetter__',\n  '__lookupGetter__',\n  '__lookupSetter__',\n  '__proto__',\n]);\n\nexports.privateObjectProps = privateObjectProps;\n\nconst fieldEscape = (field, isEval = true) => {\n  if (privateObjectProps.has(field)) {\n    throw new Error(\n      `The field name (${field}) can't be the same as an object's private property.`\n    );\n  }\n\n  return isEval ? srcEscape(field) : field;\n};\nexports.fieldEscape = fieldEscape;\n","sourceCodeStart":58,"sourceCodeEnd":84,"githubUrl":"https://github.com/sidorares/node-mysql2/blob/8b1f829d3706404ab372cf97bd77ebcf86578d97/lib/helpers.js#L58-L84","documentation":"fieldEscape (lib/helpers.js:74-82) guards a blocklist of private object property names (__defineGetter__, __defineSetter__, __lookupGetter__, __lookupSetter__, __proto__). If a field name being escaped matches one of these, the driver throws, because emitting such a field name into SQL would collide with object internals and risk prototype-pollution-shaped behavior in downstream row-as-object mapping.","triggerScenarios":"A query that nests tables (nestTables) or aliases a column whose name is __proto__ or one of the legacy accessors; user-controlled input used as a column/field identifier without sanitization; a schema that legitimately has a column named __proto__.","commonSituations":"Accepting untrusted column names from a query string or request body; legacy schemas with reserved-shaped column names; ORM-generated aliases that collide.","solutions":["Rename the column in SQL via AS with a safe alias: SELECT __proto__ AS proto_val FROM t.","Reject/sanitize user-supplied identifiers against the privateObjectProps blocklist before building queries.","Use rowsAsArray to receive rows as arrays and avoid object-property mapping entirely."],"exampleFix":"// before\nconst rows = conn.query('SELECT __proto__ FROM t');\n\n// after\nconst rows = conn.query('SELECT `__proto__` AS proto_val FROM t');","handlingStrategy":"validation","validationCode":"const privateObjectProps = new Set(['__defineGetter__','__defineSetter__','__lookupGetter__','__lookupSetter__','__proto__']);\nfunction assertSafeField(name) {\n  if (privateObjectProps.has(name)) throw new Error(`Refusing to use private-shaped field name: ${name}`);\n}","typeGuard":"const isSafeFieldName = (name) => !privateObjectProps.has(name);","tryCatchPattern":null,"preventionTips":["Never use untrusted input as a field/column identifier without an allowlist.","Alias reserved-shaped columns with AS in the SELECT.","Use rowsAsArray when the schema may contain odd column names."],"tags":["security","prototype-pollution","query-builder","validation"],"backgroundTag":null,"analyzedSha":"8b1f829d3706404ab372cf97bd77ebcf86578d97","analyzedAt":"2026-08-11T02:54:28.964Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}