mirror of
https://github.com/twigphp/Twig.git
synced 2026-10-09 21:35:40 +00:00
Validate macro name in MacroReferenceExpression constructor
The name passed to MacroReferenceExpression is emitted as raw PHP in
compile() via "->{$name}(...)". Callers were expected to validate
the name, but a missing check led to CVE-2026-XXXXX (PHP code injection
via _self / import macro reference): defense-in-depth, validate the
name in the constructor so the class is safe by construction.
This commit is contained in:
@@ -0,0 +1,41 @@
|
||||
<?php
|
||||
|
||||
/*
|
||||
* This file is part of Twig.
|
||||
*
|
||||
* (c) Fabien Potencier
|
||||
*
|
||||
* For the full copyright and license information, please view the LICENSE
|
||||
* file that was distributed with this source code.
|
||||
*/
|
||||
|
||||
namespace Twig\Tests\Node\Expression;
|
||||
|
||||
use PHPUnit\Framework\TestCase;
|
||||
use Twig\Node\Expression\ArrayExpression;
|
||||
use Twig\Node\Expression\MacroReferenceExpression;
|
||||
use Twig\Node\Expression\Variable\TemplateVariable;
|
||||
|
||||
class MacroReferenceTest extends TestCase
|
||||
{
|
||||
/**
|
||||
* @dataProvider provideInvalidMacroNames
|
||||
*/
|
||||
public function testConstructorRejectsNonIdentifierName(string $name)
|
||||
{
|
||||
$this->expectException(\LogicException::class);
|
||||
$this->expectExceptionMessage(\sprintf('Macro name "%s" is not a valid PHP identifier.', $name));
|
||||
|
||||
new MacroReferenceExpression(new TemplateVariable('foo', 1), $name, new ArrayExpression([], 1), 1);
|
||||
}
|
||||
|
||||
public static function provideInvalidMacroNames(): iterable
|
||||
{
|
||||
yield 'empty' => [''];
|
||||
yield 'starts with digit' => ['1foo'];
|
||||
yield 'contains space' => ['foo bar'];
|
||||
yield 'contains semicolon' => ['foo;bar'];
|
||||
yield 'PHP injection payload' => ['macro_foo + 1; trigger_error("BAD") //'];
|
||||
yield 'contains NUL byte' => ["foo\x00bar"];
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user