Fix sandbox bypass in the {% sandbox %} tag when including a preloaded template

This commit is contained in:
Alexandre Daubois
2026-05-05 10:31:55 +02:00
committed by Fabien Potencier
parent ea7879a67f
commit 819c6a89fe
3 changed files with 51 additions and 2 deletions
+20 -1
View File
@@ -38,6 +38,8 @@ class IncludeNode extends Node implements NodeOutputInterface
{
$compiler->addDebugInfo($this);
$sandboxed = $this->hasAttribute('sandboxed') && $this->getAttribute('sandboxed');
if ($this->getAttribute('ignore_missing')) {
$template = $compiler->getVarName();
@@ -60,15 +62,32 @@ class IncludeNode extends Node implements NodeOutputInterface
->write("}\n")
->write(\sprintf("if ($%s) {\n", $template))
->indent()
->write(\sprintf('yield from $%s->unwrap()->yield(', $template))
;
if ($sandboxed) {
$compiler->write(\sprintf("\$%s->unwrap()->checkSecurity();\n", $template));
}
$compiler->write(\sprintf('yield from $%s->unwrap()->yield(', $template));
$this->addTemplateArguments($compiler);
$compiler
->raw(");\n")
->outdent()
->write("}\n")
;
} elseif ($sandboxed) {
$template = $compiler->getVarName();
$compiler->write(\sprintf('$%s = ', $template));
$this->addGetTemplate($compiler);
$compiler
->raw(";\n")
->write(\sprintf("\$%s->unwrap()->checkSecurity();\n", $template))
->write(\sprintf('yield from $%s->unwrap()->yield(', $template))
;
$this->addTemplateArguments($compiler);
$compiler->raw(");\n");
} else {
$compiler->write('yield from ');
$this->addGetTemplate($compiler);