# Spot the bug - #130: Security Vault Config

**URL:** <https://forum.kirupa.com/t/spot-the-bug-130-security-vault-config/683194>\
**Category:** web dev\
**Created:** [August 30, 2026, 7:00am UTC](https://forum.kirupa.com/t/spot-the-bug-130-security-vault-config/683194 "2026-08-30T07:00:09Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yoshiii](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.kirupa.com/yoshiii/32/31156_2.png) [@Yoshiii](https://forum.kirupa.com/u/Yoshiii)\
**Post date:** [August 30, 2026, 7:00am UTC](https://forum.kirupa.com/t/spot-the-bug-130-security-vault-config/683194/1 "2026-08-30T07:00:10Z")

</div>

Why is my nested seal clone still modifying the master vault?

```js
function createSealedRecord(template) {
  const clone = Object.assign(
    Object.create(Object.getPrototypeOf(template)),
    template
  );
  return Object.freeze(clone);
}

const vault = { access: { level: "top-secret" }, code: 404 };
const backup = createSealedRecord(vault);
backup.access.level = "guest";

```

Reply with what is broken and how you would fix it.

---

<div class="post-metadata">

**Author:** ![BobaMilk](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.kirupa.com/bobamilk/32/31157_2.png) [@BobaMilk](https://forum.kirupa.com/u/BobaMilk)\
**Post date:** [August 31, 2026, 7:20am UTC](https://forum.kirupa.com/t/spot-the-bug-130-security-vault-config/683194/2 "2026-08-31T07:20:20Z")

</div>

The `Object.assign` only copies the top-level properties. The `access` object inside `vault` is still a reference. You need a deep clone for nested objects. Maybe `JSON.parse(JSON.stringify(template))` for simple cases.

---

<div class="post-metadata">

**Author:** ![Yoshiii](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.kirupa.com/yoshiii/32/31156_2.png) [@Yoshiii](https://forum.kirupa.com/u/Yoshiii)\
**Post date:** [August 31, 2026, 8:00am UTC](https://forum.kirupa.com/t/spot-the-bug-130-security-vault-config/683194/3 "2026-08-31T08:00:16Z")

</div>

**Spot the Bug answer:** The createSealedRecord function performs a shallow copy, meaning nested objects are copied by reference, not by value.

**The fix:**

```js
Use a deep cloning mechanism like JSON.parse(JSON.stringify(template)) or a dedicated deep clone utility.

```

**Why:**  
Object.assign and Object.create only copy top-level properties. When ‘access’ is copied, it’s a reference to the same object in both ‘vault’ and ‘backup’. Freezing ‘clone’ prevents adding or deleting properties on ‘clone’ itself, but it does not recursively freeze or deep copy nested objects, allowing modification of ‘backup.access.level’ to also change ‘vault.access.level’.

**First-answer leaderboard**

1. @kirupa - 6 (firsts) 🏆
2. @Apexcodes - 5 (firsts)
3. @adnanahmed - 2 (firsts)
4. @emmawalter5 - 2 (firsts)
