Reject an autoescape strategy that is neither a string nor false at compile time

This commit is contained in:
Fabien Potencier
2026-09-26 08:16:47 +02:00
parent 07b8427e26
commit 4fb86a896f
5 changed files with 12 additions and 6 deletions
+1
View File
@@ -1,5 +1,6 @@
# 4.0.0 (2026-XX-XX)
* Reject an `autoescape` tag strategy that is neither a string nor `false` at compile time instead of failing at runtime
* Remove support for cloning `Twig\Environment`; create a new environment instead
* Remove support for calling `TemplateWrapper::unwrap()` without an environment argument
* Stop detecting `echo` and `print` in compiled nodes; `yield` is the only supported mode and 3.x deprecates the alternative
-2
View File
@@ -18,8 +18,6 @@ use Twig\Compiler;
*
* The value is the escaping strategy (can be html, js, ...)
*
* The true value is equivalent to html.
*
* If autoescaping is disabled, then the value is false.
*
* @author Fabien Potencier <fabien@symfony.com>
+2 -3
View File
@@ -33,10 +33,9 @@ final class AutoEscapeTokenParser extends AbstractTokenParser
$value = 'html';
} else {
$expr = $this->parser->parseExpression();
if (!$expr instanceof ConstantExpression) {
throw new SyntaxError('An escaping strategy must be a string or false.', $stream->getCurrent()->getLine(), $stream->getSourceContext());
if (!$expr instanceof ConstantExpression || (!\is_string($value = $expr->getAttribute('value')) && false !== $value)) {
throw new SyntaxError('An escaping strategy must be a string or false.', $expr->getTemplateLine(), $stream->getSourceContext());
}
$value = $expr->getAttribute('value');
}
$stream->expect(Token::BLOCK_END_TYPE);
+1 -1
View File
@@ -7,7 +7,7 @@
{{ foo|e('html') -}}
{{ foo|e('js') }}
{% autoescape true %}
{% autoescape 'html' %}
{{ foo }}
{% endautoescape %}
--DATA--
@@ -0,0 +1,8 @@
--TEST--
"autoescape" tag rejects a strategy that is neither a string nor false
--TEMPLATE--
{% autoescape true %}
{{ var }}
{% endautoescape %}
--EXCEPTION--
Twig\Error\SyntaxError: An escaping strategy must be a string or false in "index.twig" at line 2.