feature #4910 Reject template wrappers from another environment (fabpot)

This PR was squashed before being merged into the 3.x branch.

Discussion
----------

Reject template wrappers from another environment

Twig now rejects `TemplateWrapper` instances created by another `Environment`.

This prevents templates from unexpectedly using another environment's loader, extensions, globals, or sandbox policy.

Commits
-------

83e8f7e123 Reject cross-environment template wrappers in block chains
c1fc112047 Reject cross-environment template wrappers
This commit is contained in:
Fabien Potencier
2026-09-14 14:11:48 +02:00
11 changed files with 90 additions and 24 deletions
+3 -3
View File
@@ -355,7 +355,7 @@ class BlockChainTest extends TestCase
{
$twig = new Environment(new ArrayLoader(['theme' => '']));
$other = new Environment(new ArrayLoader(['theme' => '']));
$wrapper = new TemplateWrapper($twig, $other->load('theme')->unwrap());
$wrapper = new TemplateWrapper($twig, $other->load('theme')->unwrap($other));
$this->expectException(\LogicException::class);
$this->expectExceptionMessage('A block chain cannot contain templates from different Twig environments.');
@@ -369,8 +369,8 @@ class BlockChainTest extends TestCase
$other = new Environment(new ArrayLoader(['parent' => '']));
$chain = new BlockChain($twig, ['theme'], ['parent' => $other->load('parent')]);
$this->expectException(\LogicException::class);
$this->expectExceptionMessage('A block chain cannot contain templates from different Twig environments.');
$this->expectException(RuntimeError::class);
$this->expectExceptionMessage('A "Twig\TemplateWrapper" can only be used with the "Twig\Environment" that created it in "theme" at line 1.');
$chain->getBlockNames();
}