mirror of
https://github.com/lancedikson/bowser
synced 2026-09-22 20:14:20 +00:00
Both from Qodo review on #632. `Parser.getBrandVersion()` called `Array.prototype.find` directly. That is ES6, and `es5.js` ships no polyfills, so a documented public API threw `TypeError: this._hints.brands.find is not a function` on exactly the browsers that bundle exists to serve. `bundled.js` was unaffected because core-js polyfills it. Every other lookup in parser.js already goes through `Utils.find`, which guards on `Array.prototype.find` and falls back to a loop; this one call site had missed it. `hasBrand()` next to it uses `Array.prototype.some`, which is ES5, and is fine. The ES5 runtime guard added alongside it did not catch this because nothing exercised the Client Hints path. It now does, for both bundles. That test builds its hints object from a script evaluated *inside* the vm context rather than assigning one onto it. A first attempt assigned a host-realm object and passed against the live bug: an array created in the host realm keeps the host's `Array.prototype`, so its `find` survives the sandbox's delete. A real browser hands the parser a same-realm array. `pnpm test:types` passed no tarball, and check.mjs exited 1 when the argument was absent, so the advertised command could never run — CI only passed because it packs and invokes the file directly. The argument is now optional: without one the package is assembled from the `files` allowlist in the working tree. `npm pack` cannot be used for this, as package.json carries no `version` until release time and npm refuses to pack without one. Missing build output is reported as such rather than as a type error. Verified by reverting the parser fix: the es5.js Client Hints test fails with the original TypeError while the bundled.js one still passes, which is the correct split. Parse output is unchanged — all four artifacts still agree across the 270-UA corpus, and Client Hints still resolve on modern runtimes.