Stop passing the template source to the sandbox checks that no longer use it

This commit is contained in:
Fabien Potencier
2026-09-25 23:52:13 +02:00
parent a5abf30b19
commit bb0dbfc229
8 changed files with 16 additions and 17 deletions
-1
View File
@@ -1954,7 +1954,6 @@ final class CoreExtension extends AbstractExtension
}
if ($isSandboxed) {
// $isSandboxed is computed against the call-site source, so check the policy directly to honor that decision.
$policy = $env->getExtension(SandboxExtension::class)->getChecker()->getSecurityPolicy();
foreach ($array as $item) {
if (\is_object($item)) {
+3 -3
View File
@@ -45,9 +45,9 @@ final class SandboxExtension extends AbstractExtension
return $this->checker;
}
public function isSandboxed(?Source $source = null): bool
public function isSandboxed(): bool
{
return $this->checker->isSandboxed($source);
return $this->checker->isSandboxed();
}
public function setSecurityPolicy(SecurityPolicyInterface $policy): void
@@ -60,7 +60,7 @@ final class SandboxExtension extends AbstractExtension
return $this->checker->getSecurityPolicy();
}
public function checkSecurity($tags, $filters, $functions, $tests = [], ?Source $source = null): void
public function checkSecurity($tags, $filters, $functions, array $tests, Source $source): void
{
$this->checker->checkSecurity($tags, $filters, $functions, $tests, $source);
}
+2 -2
View File
@@ -47,7 +47,7 @@ class CheckSecurityNode extends Node
->write("protected function checkTraitsAllowed(): void\n")
->write("{\n")
->indent()
->write("if (!\$this->sandbox->isSandboxed(\$this->source)) {\n")
->write("if (!\$this->sandbox->isSandboxed()) {\n")
->indent()
->write("return;\n")
->outdent()
@@ -72,7 +72,7 @@ class CheckSecurityNode extends Node
->write("public function ensureSecurityChecked(): void\n")
->write("{\n")
->indent()
->write("if (\$this->sandbox->isSandboxed(\$this->source)) {\n")
->write("if (\$this->sandbox->isSandboxed()) {\n")
->indent()
->write("\$this->checkSecurity();\n")
->outdent()
@@ -23,7 +23,7 @@ class HasEveryBinary extends AbstractBinary implements ReturnBoolInterface
->subcompile($this->getNode('left'))
->raw(', ')
->subcompile($this->getNode('right'))
->raw(', $this->env->hasExtension(\Twig\Extension\SandboxExtension::class) && $this->env->getExtension(\Twig\Extension\SandboxExtension::class)->getChecker()->isSandboxed($this->source))')
->raw(', $this->env->hasExtension(\Twig\Extension\SandboxExtension::class) && $this->env->getExtension(\Twig\Extension\SandboxExtension::class)->getChecker()->isSandboxed())')
;
}
+1 -1
View File
@@ -23,7 +23,7 @@ class HasSomeBinary extends AbstractBinary implements ReturnBoolInterface
->subcompile($this->getNode('left'))
->raw(', ')
->subcompile($this->getNode('right'))
->raw(', $this->env->hasExtension(\Twig\Extension\SandboxExtension::class) && $this->env->getExtension(\Twig\Extension\SandboxExtension::class)->getChecker()->isSandboxed($this->source))')
->raw(', $this->env->hasExtension(\Twig\Extension\SandboxExtension::class) && $this->env->getExtension(\Twig\Extension\SandboxExtension::class)->getChecker()->isSandboxed())')
;
}
+1 -1
View File
@@ -94,7 +94,7 @@ abstract class CallExpression extends AbstractExpression
if (!$first) {
$compiler->raw(', ');
}
$compiler->raw('$this->env->hasExtension(\Twig\Extension\SandboxExtension::class) && $this->env->getExtension(\Twig\Extension\SandboxExtension::class)->getChecker()->isSandboxed($this->source)');
$compiler->raw('$this->env->hasExtension(\Twig\Extension\SandboxExtension::class) && $this->env->getExtension(\Twig\Extension\SandboxExtension::class)->getChecker()->isSandboxed()');
$first = false;
}
+6 -6
View File
@@ -32,7 +32,7 @@ final class SecurityChecker
) {
}
public function isSandboxed(?Source $source = null): bool
public function isSandboxed(): bool
{
return $this->sandboxed;
}
@@ -47,9 +47,9 @@ final class SecurityChecker
return $this->policy;
}
public function checkSecurity(array $tags, array $filters, array $functions, array $tests, ?Source $source): void
public function checkSecurity(array $tags, array $filters, array $functions, array $tests, Source $source): void
{
if (!$this->isSandboxed($source)) {
if (!$this->isSandboxed()) {
return;
}
@@ -64,7 +64,7 @@ final class SecurityChecker
public function checkMethodAllowed(mixed $obj, mixed $method, int $lineno = -1, ?Source $source = null): void
{
if ($this->isSandboxed($source)) {
if ($this->isSandboxed()) {
try {
$this->policy->checkMethodAllowed($obj, $method);
} catch (SecurityNotAllowedMethodError $e) {
@@ -78,7 +78,7 @@ final class SecurityChecker
public function checkPropertyAllowed(mixed $obj, mixed $property, int $lineno = -1, ?Source $source = null): void
{
if ($this->isSandboxed($source)) {
if ($this->isSandboxed()) {
try {
$this->policy->checkPropertyAllowed($obj, $property);
} catch (SecurityNotAllowedPropertyError $e) {
@@ -124,7 +124,7 @@ final class SecurityChecker
return $obj;
}
if (!$this->isSandboxed($source)) {
if (!$this->isSandboxed()) {
return $obj;
}
+2 -2
View File
@@ -89,11 +89,11 @@ class FilterTest extends NodeTestCase
// needs sandbox
$node = self::createFilter($environment, $string, 'bar_sandbox');
$tests[] = [$node, 'Twig\Tests\Node\Expression\twig_tests_filter_sandbox($this->env->hasExtension(\Twig\Extension\SandboxExtension::class) && $this->env->getExtension(\Twig\Extension\SandboxExtension::class)->getChecker()->isSandboxed($this->source), "abc")', $environment];
$tests[] = [$node, 'Twig\Tests\Node\Expression\twig_tests_filter_sandbox($this->env->hasExtension(\Twig\Extension\SandboxExtension::class) && $this->env->getExtension(\Twig\Extension\SandboxExtension::class)->getChecker()->isSandboxed(), "abc")', $environment];
// needs charset, environment, context, and sandbox
$node = self::createFilter($environment, $string, 'bar_all');
$tests[] = [$node, 'Twig\Tests\Node\Expression\twig_tests_filter_all($this->env->getCharset(), $this->env, $context, $this->env->hasExtension(\Twig\Extension\SandboxExtension::class) && $this->env->getExtension(\Twig\Extension\SandboxExtension::class)->getChecker()->isSandboxed($this->source), "abc")', $environment];
$tests[] = [$node, 'Twig\Tests\Node\Expression\twig_tests_filter_all($this->env->getCharset(), $this->env, $context, $this->env->hasExtension(\Twig\Extension\SandboxExtension::class) && $this->env->getExtension(\Twig\Extension\SandboxExtension::class)->getChecker()->isSandboxed(), "abc")', $environment];
// needs environment
$node = self::createFilter($environment, $string, 'bar');