Fabien Potencier
18863f0371
Check that the use tag is allowed before resolving trait templates
2026-09-07 09:29:38 +02:00
Fabien Potencier
cf971e1a59
Remove lazy macro import resolution
2026-08-27 12:17:08 +02:00
Fabien Potencier
b53e100444
Nested macro imports
2026-08-03 10:30:32 +02:00
Fabien Potencier
d7f8b4eb1c
Redesign macro calls and argument handling
2026-07-30 13:53:24 +02:00
Fabien Potencier
b762bc94b9
Make the sandbox a first-class citizen with a dedicated Sandbox class
2026-07-30 12:05:47 +02:00
Fabien Potencier
72da20aeb7
Add sandbox tests for methods routed through __call()
2026-07-12 15:45:50 +02:00
Fabien Potencier
9c6d76b61c
Add void return type hint even in tests
2026-07-12 13:43:08 +02:00
Fabien Potencier
612dc96c18
feature #4838 Allow calling a macro with a dynamic name via the dot operator (fabpot)
...
This PR was merged into the 3.x branch.
Discussion
----------
Allow calling a macro with a dynamic name via the dot operator
Closes #4715
Commits
-------
87093aab9e Allow calling a macro with a dynamic name via the dot operator
2026-06-07 09:36:06 +02:00
Fabien Potencier
87093aab9e
Allow calling a macro with a dynamic name via the dot operator
2026-06-06 17:10:52 +02:00
Fabien Potencier
416d07da1d
Add an allow-list for tests to the sandbox security policy
2026-06-06 11:08:56 +02:00
Fabien Potencier
29c4325afd
Bump version to 3.28.0 for the always_allowed_in_sandbox feature
2026-06-06 08:56:59 +02:00
Fabien Potencier
1c53b790fb
Add regression tests that always-allowed callables still enforce the sandbox __toString policy on arguments
2026-06-06 08:56:58 +02:00
Fabien Potencier
2d75c87d05
Add an always_allowed_in_sandbox flag for filters, functions, and tags
2026-06-06 08:56:58 +02:00
Fabien Potencier
a3eda4b1fd
Make the include() function return a Markup object
2026-06-04 21:32:12 +02:00
Fabien Potencier
8a4b77920a
Add PHPUnit attributes alongside annotations to silence doc-comment metadata deprecations on PHPUnit 11
2026-06-03 18:26:39 +02:00
Fabien Potencier
6d5ef30436
Skip the sandbox __toString check on arguments whose PHP parameter type cannot implicitly coerce to string
2026-06-02 13:58:24 +02:00
Fabien Potencier
4e58cb22e5
Fix CS
2026-06-01 09:00:03 +02:00
Fabien Potencier
d25f98f45b
Preserve IteratorAggregate identity in sandbox __toString walker
2026-05-29 09:31:03 +02:00
Fabien Potencier
118938b191
Fix tests
2026-05-29 09:30:54 +02:00
Fabien Potencier
23eb6eb126
Fix sandbox filter/tag/function allow-list bypass when sandbox state changes between renders
2026-05-27 14:59:42 +02:00
Fabien Potencier
635cea4789
Document new support for any expression as a dynamic mapping key
2026-05-27 14:54:58 +02:00
Fabien Potencier
9ff4101463
Fix sandbox __toString policy bypass via dynamic mapping keys
2026-05-27 14:54:34 +02:00
Fabien Potencier
e3f66654b8
Fix deprecation notices in tests
2026-05-27 14:53:02 +02:00
Fabien Potencier
475fb690ac
Guard sandbox __toString walker against self-referencing iterables
2026-05-27 14:53:02 +02:00
Fabien Potencier
e9e818cbfc
Fix sandbox __toString bypass via Stringable + Traversable containers
2026-05-27 14:53:01 +02:00
Fabien Potencier
8d6af0707b
Fix sandbox __toString bypass via the in and not in operators
2026-05-27 14:52:32 +02:00
Fabien Potencier
cc1e21a2a2
Fix sandbox __toString bypass via Traversable in join/replace filters
2026-05-27 14:52:30 +02:00
Fabien Potencier
afbaa2a9da
Mark new SourcePolicyInterface column filter tests as @group legacy
...
These tests pass a SourcePolicyInterface instance to SandboxExtension, which
triggers the 3.27 deprecation. Mark them legacy and assert the deprecation
to silence the PHPUnit "unhandled deprecation" report.
2026-05-27 14:49:53 +02:00
Fabien Potencier
09c6706407
Fix sandbox bypass in the "column" filter under SourcePolicyInterface
2026-05-27 14:49:52 +02:00
Fabien Potencier
af7bf5e181
Add a strict mode to SecurityPolicy to opt-in to the 4.0 sandbox behavior for the extends/use tags and the parent/block/attribute functions
2026-05-25 13:40:27 +02:00
Fabien Potencier
cfaa2fd030
Deprecate the fact that the parent, block, and attribute functions are always allowed in a sandboxed template
2026-05-24 21:19:56 +02:00
Fabien Potencier
33690a4a28
Fix PHP 8.1+ implicit float-to-int deprecation in sandboxed array access
2026-05-24 17:39:37 +02:00
Fabien Potencier
4fc0210084
Bump version
2026-05-23 08:32:22 +02:00
Fabien Potencier
bd924d5d33
Deprecate the "Twig\Sandbox\SourcePolicyInterface" interface
2026-05-23 08:30:05 +02:00
Fabien Potencier
a0a1f1d17d
Replace FQCN with use statements in SandboxTest
2026-05-22 12:08:11 +02:00
Fabien Potencier
4a64b5b486
Fix CS
2026-05-21 16:34:23 +02:00
Alexandre Daubois
f05c5011c2
Fix sandbox bypass in the "column" filter
2026-05-20 07:33:52 +02:00
Fabien Potencier
447d0b2331
Fix sandbox __toString bypasses
2026-05-20 00:18:59 +02:00
Alexandre Daubois
324fa60545
Fix sandbox bypass: PHP code injection via _self / import macro reference
2026-05-19 23:41:59 +02:00
Fabien Potencier
aeb37f4801
Fix deprecations in tests
2026-05-19 23:05:30 +02:00
Alexandre Daubois
819c6a89fe
Fix sandbox bypass in the {% sandbox %} tag when including a preloaded template
2026-05-19 23:00:58 +02:00
Fabien Potencier
e494400ce4
Fix deprecation
2026-05-19 22:05:26 +02:00
Fabien Potencier
a8eb5a8a74
security #cve-2026-46639 Fix sandbox bypass in object destructuring assignment (alexandre-daubois)
...
This PR was merged into the twig-3.x branch.
2026-05-19 21:37:04 +02:00
Fabien Potencier
c8dfd62064
security #cve-2026-24425 Fix sandbox bypass: propagate Source to checkArrow for source-policy sandboxing (fabpot)
...
This PR was merged into the twig-3.x branch.
2026-05-19 21:30:51 +02:00
Fabien Potencier
fd0760d972
feature #4795 Lazy load EscaperRuntime in EscaperExtension (GromNaN)
...
This PR was merged into the 3.x branch.
Discussion
----------
Lazy load `EscaperRuntime` in `EscaperExtension`
This allows overriding `EscaperRuntime` via a custom runtime loader.
Previously, `EscaperExtension::setEnvironment()` was calling `$environment->getRuntime(EscaperRuntime::class)` eagerly. Since this method is called from `Environment::__construct()`, the runtime was resolved before any custom runtime loader could be injected, making it impossible to override `EscaperRuntime`.
- Required by https://github.com/symfony/symfony/pull/63929
Commits
-------
b73ab8cfd9 Lazy load EscaperRuntime in EscaperExtension
2026-05-17 07:52:38 +01:00
Fabien Potencier
d0579ededc
Fix sandbox bypass: propagate sandbox state to checkArrow for source-policy sandboxing
2026-05-16 18:56:08 +01:00
Fabien Potencier
5462817da0
Add a needs_is_sandboxed option for filters, functions, and tests
2026-05-16 18:52:17 +01:00
Jérôme Tamarelle
b73ab8cfd9
Lazy load EscaperRuntime in EscaperExtension
...
Previously, setEnvironment() called getRuntime(EscaperRuntime::class) eagerly,
which prevented overriding EscaperRuntime via a custom runtime loader since
Environment::__construct() calls setEnvironment() before any loader can be injected.
2026-04-30 13:43:11 +02:00
Alexandre Daubois
3fe13f98f8
Fix sandbox bypass in object destructuring assignment
2026-04-28 12:59:06 +02:00
Younes ENNAJI
473653d19b
[Core] Fix cycle() with non-countable ArrayAccess+Traversable objects
2025-11-23 13:20:23 +01:00