Stop the escaping safe analysis from retaining every analyzed node

This commit is contained in:
Fabien Potencier
2026-09-22 16:47:34 +01:00
parent 4b7c937485
commit 8274571d04
3 changed files with 70 additions and 34 deletions
+18 -34
View File
@@ -29,9 +29,17 @@ use Twig\Node\Node;
*/
final class SafeAnalysisNodeVisitor implements NodeVisitorInterface
{
private $data = [];
/**
* @var \WeakMap<Node, array>
*/
private \WeakMap $data;
private $safeVars = [];
public function __construct()
{
$this->data = new \WeakMap();
}
public function setSafeVars(array $safeVars): void
{
$this->safeVars = $safeVars;
@@ -42,47 +50,23 @@ final class SafeAnalysisNodeVisitor implements NodeVisitorInterface
*/
public function getSafe(Node $node)
{
$hash = spl_object_id($node);
if (!isset($this->data[$hash])) {
return [];
$safe = $this->data[$node] ?? [];
if (\in_array('html_attr', $safe, true)) {
$safe[] = 'html';
$safe[] = 'html_attr_relaxed';
}
foreach ($this->data[$hash] as $bucket) {
if ($bucket['key'] !== $node) {
continue;
}
if (\in_array('html_attr', $bucket['value'], true)) {
$bucket['value'][] = 'html';
$bucket['value'][] = 'html_attr_relaxed';
}
if (\in_array('html_attr_relaxed', $bucket['value'], true)) {
$bucket['value'][] = 'html';
}
return $bucket['value'];
if (\in_array('html_attr_relaxed', $safe, true)) {
$safe[] = 'html';
}
return [];
return $safe;
}
private function setSafe(Node $node, array $safe): void
{
$hash = spl_object_id($node);
if (isset($this->data[$hash])) {
foreach ($this->data[$hash] as &$bucket) {
if ($bucket['key'] === $node) {
$bucket['value'] = $safe;
return;
}
}
}
$this->data[$hash][] = [
'key' => $node,
'value' => $safe,
];
$this->data[$node] = $safe;
}
public function enterNode(Node $node, Environment $env): Node