you are viewing a single comment's thread
view the rest of the comments
[–] 46 points 2 years ago* (last edited 2 years ago) (11 children)

I still don't understand the === operator

Edit: I think a more type strict ==? Pretty sure I understand the point of typescript now.

  • source
  • hideshow 22 child comments
  • [–] 126 points 2 years ago* (1 child)

    So in JavaScript there’s the assignment

    =
    

    and the comparator is

    ==
    

    Since there’s no types JS will do implicit conversion before comparison when using == in a case like this

    if(false == '0'){
        //this is true
    }
    

    But with === it doesn’t. It means literally compare these

    if(false === '0'){
        //this is false
    }else{
        //so this will execute instead 
    }
    

    But this, however, will

    var someState = false;
     if(someState === false){
        //this is true
    }
    
  • source
  • parent
  • hideshow 2 child comments
  • [–] 19 points 2 years ago (1 child)

    JS's == has some gotchas and you almost never want to use it. So === is what == should have been.

    All examples are true:

    "1" == true
    [1, 2] == "1,2" 
    " " == false
    null == undefined 
    

    It isn't that insane. But some invariants that you may expect don't hold.

    "" == 0
    "0" == 0
    "" != "0" 
    
  • source
  • parent
  • hideshow 2 child comments
  • [–] 5 points 2 years ago (1 child)

    One neat feature is you can compare to both null and undefined at the same time, without other falsey values giving false positives. Although that's not necessary as often now that we have nullish coalescing and optional chaining.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 2 years ago (1 child)

    I just tested and Terser will convert v === null || v === undefined to null==v. Personally I would prefer to read the code that explicitly shows that it is checking for both and let my minifier/optimizer worry about generating compact code.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 0 points 2 years ago (1 child)

    Try changing to const === variable. That’s most likely what’s it doing to minimize the risk of accidental assignment.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 3 points 2 years ago (1 child)

    Wut? This is an automated optimizer. It is not worried about accidental assignment.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 2 years ago (1 child)

    I agree it shouldn’t. But I’ve seen linters that automatically change it since they seem to be forcing practical conventions sometimes.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 18 points 2 years ago* (2 children)

    It's also important if you're checking hashes (at least, it was - if you're using correct hashing algorithm that isn't ancient, you will not have this problem).

    Because if you take for example "0e462097431906509019562988736854" (which is md5("240610708"), but also applicable to most other hashing algorithms that hash to a hex string), if("0e462097431906509019562988736854" == 0) is true. So any other data that hashes to any variantion of "0e[1-9]+" will pass the check, for example:

    md5("240610708") == md5("hashcatqlffzszeRcrt")

    that equals to

    "0e462097431906509019562988736854" == "0e242700999142460696437005736231"

    which thanks to scientific notation and no strict type checking can also mean

    0^462097431906509019562988736854^ == 0^242700999142460696437005736231^

    which is

    0 == 0 `

    I did use md5 as an example because the strings are pretty short, but it's applicable to a whole lot of other hashes. And the problem is that if you use one of the strings that hash to a magic hash in a vulnerable site, it will pass the password check for any user who's password also hashes to a magic hash. There's not really a high chance of that happening, but there's still a lot of hashes that do hash to it.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 6 points 2 years ago (1 child)

    The other comments explains it in pretty good detail, but when I was learning my teacher explained it sort of like a mnemonic.

    1 + 1 = 2 is read "one plus one equals two"

    1 + 1 == 2 is read "one plus one is equal to two"

    1 + 1 === 2 is read "one plus one is really equal to two"

    And you hit the nail on the head, is that === is type explicit while == is implicit.

  • source
  • parent
  • hideshow 2 child comments