diff --git a/CHANGELOG b/CHANGELOG index 1b3773345..70dcabcdb 100644 --- a/CHANGELOG +++ b/CHANGELOG @@ -1,5 +1,6 @@ # 4.0.0 (2026-XX-XX) + * Reject an `autoescape` tag strategy that is neither a string nor `false` at compile time instead of failing at runtime * Remove support for cloning `Twig\Environment`; create a new environment instead * Remove support for calling `TemplateWrapper::unwrap()` without an environment argument * Stop detecting `echo` and `print` in compiled nodes; `yield` is the only supported mode and 3.x deprecates the alternative diff --git a/src/Node/AutoEscapeNode.php b/src/Node/AutoEscapeNode.php index a285b1581..f576814b4 100644 --- a/src/Node/AutoEscapeNode.php +++ b/src/Node/AutoEscapeNode.php @@ -18,8 +18,6 @@ use Twig\Compiler; * * The value is the escaping strategy (can be html, js, ...) * - * The true value is equivalent to html. - * * If autoescaping is disabled, then the value is false. * * @author Fabien Potencier diff --git a/src/TokenParser/AutoEscapeTokenParser.php b/src/TokenParser/AutoEscapeTokenParser.php index ae6b04c57..819f361d9 100644 --- a/src/TokenParser/AutoEscapeTokenParser.php +++ b/src/TokenParser/AutoEscapeTokenParser.php @@ -33,10 +33,9 @@ final class AutoEscapeTokenParser extends AbstractTokenParser $value = 'html'; } else { $expr = $this->parser->parseExpression(); - if (!$expr instanceof ConstantExpression) { - throw new SyntaxError('An escaping strategy must be a string or false.', $stream->getCurrent()->getLine(), $stream->getSourceContext()); + if (!$expr instanceof ConstantExpression || (!\is_string($value = $expr->getAttribute('value')) && false !== $value)) { + throw new SyntaxError('An escaping strategy must be a string or false.', $expr->getTemplateLine(), $stream->getSourceContext()); } - $value = $expr->getAttribute('value'); } $stream->expect(Token::BLOCK_END_TYPE); diff --git a/tests/Fixtures/filters/force_escape.test b/tests/Fixtures/filters/force_escape.test index 7efbe3200..0fedb13f6 100644 --- a/tests/Fixtures/filters/force_escape.test +++ b/tests/Fixtures/filters/force_escape.test @@ -7,7 +7,7 @@ {{ foo|e('html') -}} {{ foo|e('js') }} -{% autoescape true %} +{% autoescape 'html' %} {{ foo }} {% endautoescape %} --DATA-- diff --git a/tests/Fixtures/tags/autoescape/invalid_strategy.test b/tests/Fixtures/tags/autoescape/invalid_strategy.test new file mode 100644 index 000000000..8cc3798a5 --- /dev/null +++ b/tests/Fixtures/tags/autoescape/invalid_strategy.test @@ -0,0 +1,8 @@ +--TEST-- +"autoescape" tag rejects a strategy that is neither a string nor false +--TEMPLATE-- +{% autoescape true %} +{{ var }} +{% endautoescape %} +--EXCEPTION-- +Twig\Error\SyntaxError: An escaping strategy must be a string or false in "index.twig" at line 2.