mirror of
https://github.com/twigphp/Twig.git
synced 2026-10-10 05:45:50 +00:00
Reject an autoescape strategy that is neither a string nor false at compile time
This commit is contained in:
@@ -1,5 +1,6 @@
|
||||
# 4.0.0 (2026-XX-XX)
|
||||
|
||||
* Reject an `autoescape` tag strategy that is neither a string nor `false` at compile time instead of failing at runtime
|
||||
* Remove support for cloning `Twig\Environment`; create a new environment instead
|
||||
* Remove support for calling `TemplateWrapper::unwrap()` without an environment argument
|
||||
* Stop detecting `echo` and `print` in compiled nodes; `yield` is the only supported mode and 3.x deprecates the alternative
|
||||
|
||||
@@ -18,8 +18,6 @@ use Twig\Compiler;
|
||||
*
|
||||
* The value is the escaping strategy (can be html, js, ...)
|
||||
*
|
||||
* The true value is equivalent to html.
|
||||
*
|
||||
* If autoescaping is disabled, then the value is false.
|
||||
*
|
||||
* @author Fabien Potencier <fabien@symfony.com>
|
||||
|
||||
@@ -33,10 +33,9 @@ final class AutoEscapeTokenParser extends AbstractTokenParser
|
||||
$value = 'html';
|
||||
} else {
|
||||
$expr = $this->parser->parseExpression();
|
||||
if (!$expr instanceof ConstantExpression) {
|
||||
throw new SyntaxError('An escaping strategy must be a string or false.', $stream->getCurrent()->getLine(), $stream->getSourceContext());
|
||||
if (!$expr instanceof ConstantExpression || (!\is_string($value = $expr->getAttribute('value')) && false !== $value)) {
|
||||
throw new SyntaxError('An escaping strategy must be a string or false.', $expr->getTemplateLine(), $stream->getSourceContext());
|
||||
}
|
||||
$value = $expr->getAttribute('value');
|
||||
}
|
||||
|
||||
$stream->expect(Token::BLOCK_END_TYPE);
|
||||
|
||||
@@ -7,7 +7,7 @@
|
||||
|
||||
{{ foo|e('html') -}}
|
||||
{{ foo|e('js') }}
|
||||
{% autoescape true %}
|
||||
{% autoescape 'html' %}
|
||||
{{ foo }}
|
||||
{% endautoescape %}
|
||||
--DATA--
|
||||
|
||||
@@ -0,0 +1,8 @@
|
||||
--TEST--
|
||||
"autoescape" tag rejects a strategy that is neither a string nor false
|
||||
--TEMPLATE--
|
||||
{% autoescape true %}
|
||||
{{ var }}
|
||||
{% endautoescape %}
|
||||
--EXCEPTION--
|
||||
Twig\Error\SyntaxError: An escaping strategy must be a string or false in "index.twig" at line 2.
|
||||
Reference in New Issue
Block a user