fixed .. (range operator) in sandbox policy

This commit is contained in:
Fabien Potencier
2018-03-04 10:12:13 -08:00
parent caf2caa8f4
commit 6f45fcf519
3 changed files with 25 additions and 1 deletions
+1 -1
View File
@@ -1,6 +1,6 @@
* 1.35.2 (2018-XX-XX) * 1.35.2 (2018-XX-XX)
* n/a * fixed .. (range operator) in sandbox policy
* 1.35.1 (2018-03-02) * 1.35.1 (2018-03-02)
+5
View File
@@ -48,6 +48,11 @@ class Twig_NodeVisitor_Sandbox extends Twig_BaseNodeVisitor
$this->functions[$node->getAttribute('name')] = $node; $this->functions[$node->getAttribute('name')] = $node;
} }
// the .. operator is equivalent to the range() function
if ($node instanceof Twig_Node_Expression_Binary_Range && !isset($this->functions['range'])) {
$this->functions['range'] = $node;
}
// wrap print to check __toString() calls // wrap print to check __toString() calls
if ($node instanceof Twig_Node_Print) { if ($node instanceof Twig_Node_Print) {
return new Twig_Node_SandboxedPrint($node->getNode('expr'), $node->getTemplateLine(), $node->getNodeTag()); return new Twig_Node_SandboxedPrint($node->getNode('expr'), $node->getTemplateLine(), $node->getNodeTag());
+19
View File
@@ -36,6 +36,7 @@ class Twig_Tests_Extension_SandboxTest extends \PHPUnit\Framework\TestCase
'1_layout' => '{% block content %}{% endblock %}', '1_layout' => '{% block content %}{% endblock %}',
'1_child' => "{% extends \"1_layout\" %}\n{% block content %}\n{{ \"a\"|json_encode }}\n{% endblock %}", '1_child' => "{% extends \"1_layout\" %}\n{% block content %}\n{{ \"a\"|json_encode }}\n{% endblock %}",
'1_include' => '{{ include("1_basic1", sandboxed=true) }}', '1_include' => '{{ include("1_basic1", sandboxed=true) }}',
'1_range_operator' => '{{ (1..2)[0] }}',
); );
} }
@@ -143,6 +144,18 @@ class Twig_Tests_Extension_SandboxTest extends \PHPUnit\Framework\TestCase
} }
} }
public function testSandboxUnallowedRangeOperator()
{
$twig = $this->getEnvironment(true, array(), self::$templates);
try {
$twig->loadTemplate('1_range_operator')->render(self::$params);
$this->fail('Sandbox throws a SecurityError exception if the unallowed range operator is called');
} catch (Twig_Sandbox_SecurityError $e) {
$this->assertInstanceOf('Twig_Sandbox_SecurityNotAllowedFunctionError', $e, 'Exception should be an instance of Twig_Sandbox_SecurityNotAllowedFunctionError');
$this->assertEquals('range', $e->getFunctionName(), 'Exception should be raised on the "range" function');
}
}
public function testSandboxAllowMethodFoo() public function testSandboxAllowMethodFoo()
{ {
$twig = $this->getEnvironment(true, array(), self::$templates, array(), array(), array('FooObject' => 'foo')); $twig = $this->getEnvironment(true, array(), self::$templates, array(), array(), array('FooObject' => 'foo'));
@@ -191,6 +204,12 @@ class Twig_Tests_Extension_SandboxTest extends \PHPUnit\Framework\TestCase
$this->assertEquals('bar', $twig->loadTemplate('1_basic7')->render(self::$params), 'Sandbox allow some functions'); $this->assertEquals('bar', $twig->loadTemplate('1_basic7')->render(self::$params), 'Sandbox allow some functions');
} }
public function testSandboxAllowRangeOperator()
{
$twig = $this->getEnvironment(true, array(), self::$templates, array(), array(), array(), array(), array('range'));
$this->assertEquals('1', $twig->loadTemplate('1_range_operator')->render(self::$params), 'Sandbox allow the range operator');
}
public function testSandboxAllowFunctionsCaseInsensitive() public function testSandboxAllowFunctionsCaseInsensitive()
{ {
foreach (array('getfoobar', 'getFoobar', 'getFooBar') as $name) { foreach (array('getfoobar', 'getFoobar', 'getFooBar') as $name) {