fix: Improve ParseObject conformance to Hashable #176
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
New Pull Request Checklist
Issue Description
ParseObjects
are using a custom hashing method that depended onobjectId
,createdAt
, andupdatedAt
to determine if a hash was equal. This was a fairly weak implementation and only protected against values provided from the server. If a property on aParseObject
that wasn'tobjectId
,createdAt
, andupdatedAt
was changed locally, it would still hash to the same value.For ParseFile, the type currently uses a custom function for
Equatable
.Approach
Remove all custom hashing methods for
ParseObjects
and use the compiler level hasher which will hash all properties on an ParseObject assuming all of those objects areHashable
(which they should be). This moves in the direction of guaranteeing that collision attacks won't be possible (see discussion for details).If a developer decides to add their own implementation of the hashing function they are doing so at their own risk and risking collision attacks. In addition, if their
ParseObjects
are used in SwiftUI views they may see unexpected behavior as SwiftUI heavily depends onIdentifiable
,Hashable
, andEquatable
to determine when a view should be updated.For ParseFile, conforming to
Equatable
is improved by checking all properties are equal.TODOs before merging