Conversation
|
@spokodev hi! Could you please explain your use case regarding global regular expressions? |
|
Fair question. I am not deliberately setting a global flag on a namespace regex; the value here is defensive. |
Disallow RegExp instances with the global or sticky flag in io.of(), as they mutate lastIndex and can make dynamic namespace matching unreliable. Related: #5519
|
Merged as 59f4f24. Thanks for the heads-up! |
|
Released in Release notes: https://github.com/socketio/socket.io/releases/tag/socket.io%404.8.4 |
A dynamic namespace registered with a
RegExpthat carries the global (g) orsticky (
y) flag rejects connections intermittently.Server.ofand the parent-namespace matcher call.test()on the user suppliedregex as if it were a stateless predicate. Per the ECMAScript spec,
RegExp.prototype.test()advanceslastIndexwhen the regex has thegoryflag and resumes from it on the next call, so a shared regex object returns
alternating results across connections.
Concretely,
io.of(/^\/room-\d+$/g)connects/room-1, then rejects/room-2with
connect_error: "Invalid namespace", then connects/room-3, and so on:The pattern is correct; only the leftover
lastIndexstate causes the rejection.The fix resets
lastIndexto 0 immediately before each.test()at both callsites. It is a no-op for regexes without the
goryflag, so existingbehavior is unchanged.