mirror of
https://github.com/twigphp/Twig.git
synced 2026-10-06 11:57:11 +00:00
Fix sandbox __toString bypasses
This commit is contained in:
@@ -22,7 +22,7 @@ use Twig\Node\Expression\AbstractExpression;
|
||||
* @author Fabien Potencier <fabien@symfony.com>
|
||||
*/
|
||||
#[YieldReady]
|
||||
class IncludeNode extends Node implements NodeOutputInterface
|
||||
class IncludeNode extends Node implements NodeOutputInterface, CoercesChildrenToStringInterface
|
||||
{
|
||||
public function __construct(AbstractExpression $expr, ?AbstractExpression $variables, bool $only, bool $ignoreMissing, int $lineno)
|
||||
{
|
||||
@@ -130,4 +130,10 @@ class IncludeNode extends Node implements NodeOutputInterface
|
||||
$compiler->raw(')');
|
||||
}
|
||||
}
|
||||
|
||||
public function getStringCoercedChildNames(): array
|
||||
{
|
||||
// the loader resolves the template-name expression by coercing it to a string
|
||||
return ['expr'];
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user