mirror of
https://github.com/twigphp/Twig.git
synced 2026-09-13 10:56:38 +00:00
fix duplicate call of methods if using sandbox
This commit is contained in:
@@ -91,6 +91,15 @@ class Twig_Extension_Sandbox extends Twig_Extension
|
||||
}
|
||||
}
|
||||
|
||||
public function ensureToStringAllowed($obj)
|
||||
{
|
||||
if (is_object($obj)) {
|
||||
$this->policy->checkMethodAllowed($obj, '__toString');
|
||||
}
|
||||
|
||||
return $obj;
|
||||
}
|
||||
|
||||
/**
|
||||
* Returns the name of the extension.
|
||||
*
|
||||
|
||||
@@ -36,18 +36,10 @@ class Twig_Node_SandboxedPrint extends Twig_Node_Print
|
||||
{
|
||||
$compiler
|
||||
->addDebugInfo($this)
|
||||
->write('if (is_object(')
|
||||
->raw('$_tmp = ')
|
||||
->subcompile($this->removeNodeFilter($this->getNode('expr')))
|
||||
->raw(')) {'."\n")
|
||||
->indent()
|
||||
->write('$this->env->getExtension(\'sandbox\')->checkMethodAllowed(')
|
||||
->raw('$_tmp, \'__toString\');'."\n")
|
||||
->outdent()
|
||||
->write('}'."\n")
|
||||
->write('echo $this->env->getExtension(\'sandbox\')->ensureToStringAllowed(')
|
||||
->subcompile($this->getNode('expr'))
|
||||
->raw(");\n")
|
||||
;
|
||||
|
||||
parent::compile($compiler);
|
||||
}
|
||||
|
||||
/**
|
||||
|
||||
@@ -37,10 +37,7 @@ class Twig_Tests_Node_SandboxedPrintTest extends Twig_Tests_Node_TestCase
|
||||
$tests = array();
|
||||
|
||||
$tests[] = array(new Twig_Node_SandboxedPrint(new Twig_Node_Expression_Constant('foo', 0), 0), <<<EOF
|
||||
if (is_object(\$_tmp = "foo")) {
|
||||
\$this->env->getExtension('sandbox')->checkMethodAllowed(\$_tmp, '__toString');
|
||||
}
|
||||
echo "foo";
|
||||
echo \$this->env->getExtension('sandbox')->ensureToStringAllowed("foo");
|
||||
EOF
|
||||
);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user