Fix sandbox __toString bypasses

This commit is contained in:
Fabien Potencier
2026-05-19 16:49:38 +02:00
parent 7f3056a28e
commit 447d0b2331
35 changed files with 516 additions and 67 deletions
+7 -1
View File
@@ -22,7 +22,7 @@ use Twig\Node\Expression\AbstractExpression;
* @author Fabien Potencier <fabien@symfony.com>
*/
#[YieldReady]
class IncludeNode extends Node implements NodeOutputInterface
class IncludeNode extends Node implements NodeOutputInterface, CoercesChildrenToStringInterface
{
public function __construct(AbstractExpression $expr, ?AbstractExpression $variables, bool $only, bool $ignoreMissing, int $lineno)
{
@@ -130,4 +130,10 @@ class IncludeNode extends Node implements NodeOutputInterface
$compiler->raw(')');
}
}
public function getStringCoercedChildNames(): array
{
// the loader resolves the template-name expression by coercing it to a string
return ['expr'];
}
}