microsoft / microsoft/TypeScript
Inconsistencies in ESM-style imports of accessibility-modified properties from CJS-exported classes
Nobody has claimed this yet.
- Dominant language
- Go
- Stars
- 111k
- Forks
- 14.3k
- Avg merge
- 2d 4h
- Merged PRs (30d)
- 132
Description
### Acknowledgement
- [x] I acknowledge that issues using this template may be closed without further explanation at the maintainer's discretion.
### Comment
#### Search terms
```sql
import AND class AND (protected OR private OR modifier)
```
#### Description
Given the following CJS module:
```ts
class X {
public static a = 1;
protected static b = 2;
private static c = 3;
}
export = X;
```
then the behaviour of the static properties when using ESM-style imports is variable. For example,
```ts
import { a, b, c } from "module.cjs";
```
is permitted, but
```ts
import * as m from "module.cjs";
const { a, b, c } = m;
```
is not (`m` is an alias to the CJS export `X`, so this counts as a class property access and is subject to accessibility checks).
Protected and private class properties are also offered by tsserver for Intellisense suggestions when using ESM-style imports, but are obviously hidden when offering properties of the "namespace" object created by `import *` (since it's just an alias to the exported class), and do not appear in its `keyof`.
(The same would also apply if the CJS export were an _instance_ of a class with accessibility-modified prototype properties, but exporting a class constructor is the more likely scenario encountered in the wild.)
Exposing intended-to-be-hidden properties in this way is almost always going to have been unintentional, and the alternative behaviour is fairly straightforward: add accessibility checks for NamedImports elements when the import target is a CJS export.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the CJS-exported class example in the issue and trace how TypeScript handles NamedImports versus an import-star namespace when the target is an exported class. Reproduce the differing accessibility behavior, then verify that named imports also enforce accessibility checks without exposing protected or private properties.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- typescript
- Domain
- compilers
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 38/100