mirror of
https://github.com/twigphp/Twig.git
synced 2026-09-16 12:26:30 +00:00
fixed .. (range operator) in sandbox policy
This commit is contained in:
@@ -1,6 +1,6 @@
|
|||||||
* 1.35.2 (2018-XX-XX)
|
* 1.35.2 (2018-XX-XX)
|
||||||
|
|
||||||
* n/a
|
* fixed .. (range operator) in sandbox policy
|
||||||
|
|
||||||
* 1.35.1 (2018-03-02)
|
* 1.35.1 (2018-03-02)
|
||||||
|
|
||||||
|
|||||||
@@ -48,6 +48,11 @@ class Twig_NodeVisitor_Sandbox extends Twig_BaseNodeVisitor
|
|||||||
$this->functions[$node->getAttribute('name')] = $node;
|
$this->functions[$node->getAttribute('name')] = $node;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// the .. operator is equivalent to the range() function
|
||||||
|
if ($node instanceof Twig_Node_Expression_Binary_Range && !isset($this->functions['range'])) {
|
||||||
|
$this->functions['range'] = $node;
|
||||||
|
}
|
||||||
|
|
||||||
// wrap print to check __toString() calls
|
// wrap print to check __toString() calls
|
||||||
if ($node instanceof Twig_Node_Print) {
|
if ($node instanceof Twig_Node_Print) {
|
||||||
return new Twig_Node_SandboxedPrint($node->getNode('expr'), $node->getTemplateLine(), $node->getNodeTag());
|
return new Twig_Node_SandboxedPrint($node->getNode('expr'), $node->getTemplateLine(), $node->getNodeTag());
|
||||||
|
|||||||
@@ -36,6 +36,7 @@ class Twig_Tests_Extension_SandboxTest extends \PHPUnit\Framework\TestCase
|
|||||||
'1_layout' => '{% block content %}{% endblock %}',
|
'1_layout' => '{% block content %}{% endblock %}',
|
||||||
'1_child' => "{% extends \"1_layout\" %}\n{% block content %}\n{{ \"a\"|json_encode }}\n{% endblock %}",
|
'1_child' => "{% extends \"1_layout\" %}\n{% block content %}\n{{ \"a\"|json_encode }}\n{% endblock %}",
|
||||||
'1_include' => '{{ include("1_basic1", sandboxed=true) }}',
|
'1_include' => '{{ include("1_basic1", sandboxed=true) }}',
|
||||||
|
'1_range_operator' => '{{ (1..2)[0] }}',
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -143,6 +144,18 @@ class Twig_Tests_Extension_SandboxTest extends \PHPUnit\Framework\TestCase
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
public function testSandboxUnallowedRangeOperator()
|
||||||
|
{
|
||||||
|
$twig = $this->getEnvironment(true, array(), self::$templates);
|
||||||
|
try {
|
||||||
|
$twig->loadTemplate('1_range_operator')->render(self::$params);
|
||||||
|
$this->fail('Sandbox throws a SecurityError exception if the unallowed range operator is called');
|
||||||
|
} catch (Twig_Sandbox_SecurityError $e) {
|
||||||
|
$this->assertInstanceOf('Twig_Sandbox_SecurityNotAllowedFunctionError', $e, 'Exception should be an instance of Twig_Sandbox_SecurityNotAllowedFunctionError');
|
||||||
|
$this->assertEquals('range', $e->getFunctionName(), 'Exception should be raised on the "range" function');
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
public function testSandboxAllowMethodFoo()
|
public function testSandboxAllowMethodFoo()
|
||||||
{
|
{
|
||||||
$twig = $this->getEnvironment(true, array(), self::$templates, array(), array(), array('FooObject' => 'foo'));
|
$twig = $this->getEnvironment(true, array(), self::$templates, array(), array(), array('FooObject' => 'foo'));
|
||||||
@@ -191,6 +204,12 @@ class Twig_Tests_Extension_SandboxTest extends \PHPUnit\Framework\TestCase
|
|||||||
$this->assertEquals('bar', $twig->loadTemplate('1_basic7')->render(self::$params), 'Sandbox allow some functions');
|
$this->assertEquals('bar', $twig->loadTemplate('1_basic7')->render(self::$params), 'Sandbox allow some functions');
|
||||||
}
|
}
|
||||||
|
|
||||||
|
public function testSandboxAllowRangeOperator()
|
||||||
|
{
|
||||||
|
$twig = $this->getEnvironment(true, array(), self::$templates, array(), array(), array(), array(), array('range'));
|
||||||
|
$this->assertEquals('1', $twig->loadTemplate('1_range_operator')->render(self::$params), 'Sandbox allow the range operator');
|
||||||
|
}
|
||||||
|
|
||||||
public function testSandboxAllowFunctionsCaseInsensitive()
|
public function testSandboxAllowFunctionsCaseInsensitive()
|
||||||
{
|
{
|
||||||
foreach (array('getfoobar', 'getFoobar', 'getFooBar') as $name) {
|
foreach (array('getfoobar', 'getFoobar', 'getFooBar') as $name) {
|
||||||
|
|||||||
Reference in New Issue
Block a user