You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何替换eval实现Category对象属性关联Product对象数组

替代eval实现Category与Product对象关联的方案

目前我通过eval(name)实现了Category对象与Product对象的关联,即this.prodLine = eval(name),该方式功能正常,但eval存在安全风险,希望找到替代实现方案。

原代码

function product(name, price) {
    this.name = name;
    this.price = price;
    return this;
}
function category(name, description) {
    this.name = name;
    this.description = description;
    this.prodLine = eval(name); // 通过eval获取对应产品数组
    return this;
}

Apps = new Array(new product("Dryer", 100), new product("Hairdryer", 200), new product("Oven", 300));
Cars = new Array(new product("audi", 400), new product("bmw", 500), new product("citroen", 600), new product("dacia", 9000));

categorySet = new Array(
    new category("Apps", "handy home appliances"),
    new category("Cars", "tedious four wheelers")
);
var Produkty = new Array();

var count_prod = categorySet[0].prodLine.length; alert('cat[0] : count_prod='+count_prod);
for (var j = 0; j < count_prod; j++) {
    Produkty[Produkty.length] = new Array(0, j);
    alert('KAT[0] count_prod='+count_prod+' : Produkty.length = '+Produkty.length+' j = '+j);
}
var count_prod = categorySet[1].prodLine.length; alert('cat[1] : count_prod='+count_prod);
for (var j = 0; j < count_prod; j++) {
    Produkty[Produkty.length] = new Array(1, j);
    alert('KAT[1] count_prod='+count_prod+' : Produkty.length = '+Produkty.length)+' j = '+j;
}

console.table(Produkty);

替代方案:使用对象映射替代eval

核心思路是将全局的产品数组(Apps、Cars)统一存入一个对象中,通过对象的键值访问来替代eval,既保留原有功能,又避免了eval的安全风险。

修改后的完整代码如下:

function product(name, price) {
    this.name = name;
    this.price = price;
    return this;
}

// 创建产品集合对象,存储所有分类对应的产品数组
const productCollections = {
    Apps: new Array(new product("Dryer", 100), new product("Hairdryer", 200), new product("Oven", 300)),
    Cars: new Array(new product("audi", 400), new product("bmw", 500), new product("citroen", 600), new product("dacia", 9000))
};

function category(name, description) {
    this.name = name;
    this.description = description;
    // 通过对象键名获取对应产品数组,替代eval
    this.prodLine = productCollections[name];
    return this;
}

categorySet = new Array(
    new category("Apps", "handy home appliances"),
    new category("Cars", "tedious four wheelers")
);
var Produkty = new Array();

var count_prod = categorySet[0].prodLine.length; alert('cat[0] : count_prod='+count_prod);
for (var j = 0; j < count_prod; j++) {
    Produkty[Produkty.length] = new Array(0, j);
    alert('KAT[0] count_prod='+count_prod+' : Produkty.length = '+Produkty.length+' j = '+j);
}
var count_prod = categorySet[1].prodLine.length; alert('cat[1] : count_prod='+count_prod);
for (var j = 0; j < count_prod; j++) {
    Produkty[Produkty.length] = new Array(1, j);
    alert('KAT[1] count_prod='+count_prod+' : Produkty.length = '+Produkty.length)+' j = '+j;
}

console.table(Produkty);

方案说明

  • 将分散的全局产品数组整合到productCollections对象中,避免污染全局作用域。
  • 通过productCollections[name]的方式获取对应产品数组,本质是对象属性的动态访问,完全规避了eval执行任意代码的安全风险。
  • 代码逻辑与原实现保持一致,功能不受影响。

内容的提问来源于stack exchange,提问作者user2279628

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.08 08:40:57