151 Commits

Author SHA1 Message Date
Fabien Potencier 18863f0371 Check that the use tag is allowed before resolving trait templates 2026-09-07 09:29:38 +02:00
Fabien Potencier cf971e1a59 Remove lazy macro import resolution 2026-08-27 12:17:08 +02:00
Fabien Potencier b53e100444 Nested macro imports 2026-08-03 10:30:32 +02:00
Fabien Potencier d7f8b4eb1c Redesign macro calls and argument handling 2026-07-30 13:53:24 +02:00
Fabien Potencier b762bc94b9 Make the sandbox a first-class citizen with a dedicated Sandbox class 2026-07-30 12:05:47 +02:00
Fabien Potencier 72da20aeb7 Add sandbox tests for methods routed through __call() 2026-07-12 15:45:50 +02:00
Fabien Potencier 9c6d76b61c Add void return type hint even in tests 2026-07-12 13:43:08 +02:00
Fabien Potencier 612dc96c18 feature #4838 Allow calling a macro with a dynamic name via the dot operator (fabpot)
This PR was merged into the 3.x branch.

Discussion
----------

Allow calling a macro with a dynamic name via the dot operator

Closes #4715

Commits
-------

87093aab9e Allow calling a macro with a dynamic name via the dot operator
2026-06-07 09:36:06 +02:00
Fabien Potencier 87093aab9e Allow calling a macro with a dynamic name via the dot operator 2026-06-06 17:10:52 +02:00
Fabien Potencier 416d07da1d Add an allow-list for tests to the sandbox security policy 2026-06-06 11:08:56 +02:00
Fabien Potencier 29c4325afd Bump version to 3.28.0 for the always_allowed_in_sandbox feature 2026-06-06 08:56:59 +02:00
Fabien Potencier 1c53b790fb Add regression tests that always-allowed callables still enforce the sandbox __toString policy on arguments 2026-06-06 08:56:58 +02:00
Fabien Potencier 2d75c87d05 Add an always_allowed_in_sandbox flag for filters, functions, and tags 2026-06-06 08:56:58 +02:00
Fabien Potencier a3eda4b1fd Make the include() function return a Markup object 2026-06-04 21:32:12 +02:00
Fabien Potencier 8a4b77920a Add PHPUnit attributes alongside annotations to silence doc-comment metadata deprecations on PHPUnit 11 2026-06-03 18:26:39 +02:00
Fabien Potencier 6d5ef30436 Skip the sandbox __toString check on arguments whose PHP parameter type cannot implicitly coerce to string 2026-06-02 13:58:24 +02:00
Fabien Potencier 4e58cb22e5 Fix CS 2026-06-01 09:00:03 +02:00
Fabien Potencier d25f98f45b Preserve IteratorAggregate identity in sandbox __toString walker 2026-05-29 09:31:03 +02:00
Fabien Potencier 118938b191 Fix tests 2026-05-29 09:30:54 +02:00
Fabien Potencier 23eb6eb126 Fix sandbox filter/tag/function allow-list bypass when sandbox state changes between renders 2026-05-27 14:59:42 +02:00
Fabien Potencier 635cea4789 Document new support for any expression as a dynamic mapping key 2026-05-27 14:54:58 +02:00
Fabien Potencier 9ff4101463 Fix sandbox __toString policy bypass via dynamic mapping keys 2026-05-27 14:54:34 +02:00
Fabien Potencier e3f66654b8 Fix deprecation notices in tests 2026-05-27 14:53:02 +02:00
Fabien Potencier 475fb690ac Guard sandbox __toString walker against self-referencing iterables 2026-05-27 14:53:02 +02:00
Fabien Potencier e9e818cbfc Fix sandbox __toString bypass via Stringable + Traversable containers 2026-05-27 14:53:01 +02:00
Fabien Potencier 8d6af0707b Fix sandbox __toString bypass via the in and not in operators 2026-05-27 14:52:32 +02:00
Fabien Potencier cc1e21a2a2 Fix sandbox __toString bypass via Traversable in join/replace filters 2026-05-27 14:52:30 +02:00
Fabien Potencier afbaa2a9da Mark new SourcePolicyInterface column filter tests as @group legacy
These tests pass a SourcePolicyInterface instance to SandboxExtension, which
triggers the 3.27 deprecation. Mark them legacy and assert the deprecation
to silence the PHPUnit "unhandled deprecation" report.
2026-05-27 14:49:53 +02:00
Fabien Potencier 09c6706407 Fix sandbox bypass in the "column" filter under SourcePolicyInterface 2026-05-27 14:49:52 +02:00
Fabien Potencier af7bf5e181 Add a strict mode to SecurityPolicy to opt-in to the 4.0 sandbox behavior for the extends/use tags and the parent/block/attribute functions 2026-05-25 13:40:27 +02:00
Fabien Potencier cfaa2fd030 Deprecate the fact that the parent, block, and attribute functions are always allowed in a sandboxed template 2026-05-24 21:19:56 +02:00
Fabien Potencier 33690a4a28 Fix PHP 8.1+ implicit float-to-int deprecation in sandboxed array access 2026-05-24 17:39:37 +02:00
Fabien Potencier 4fc0210084 Bump version 2026-05-23 08:32:22 +02:00
Fabien Potencier bd924d5d33 Deprecate the "Twig\Sandbox\SourcePolicyInterface" interface 2026-05-23 08:30:05 +02:00
Fabien Potencier a0a1f1d17d Replace FQCN with use statements in SandboxTest 2026-05-22 12:08:11 +02:00
Fabien Potencier 4a64b5b486 Fix CS 2026-05-21 16:34:23 +02:00
Alexandre Daubois f05c5011c2 Fix sandbox bypass in the "column" filter 2026-05-20 07:33:52 +02:00
Fabien Potencier 447d0b2331 Fix sandbox __toString bypasses 2026-05-20 00:18:59 +02:00
Alexandre Daubois 324fa60545 Fix sandbox bypass: PHP code injection via _self / import macro reference 2026-05-19 23:41:59 +02:00
Fabien Potencier aeb37f4801 Fix deprecations in tests 2026-05-19 23:05:30 +02:00
Alexandre Daubois 819c6a89fe Fix sandbox bypass in the {% sandbox %} tag when including a preloaded template 2026-05-19 23:00:58 +02:00
Fabien Potencier e494400ce4 Fix deprecation 2026-05-19 22:05:26 +02:00
Fabien Potencier a8eb5a8a74 security #cve-2026-46639 Fix sandbox bypass in object destructuring assignment (alexandre-daubois)
This PR was merged into the twig-3.x branch.
2026-05-19 21:37:04 +02:00
Fabien Potencier c8dfd62064 security #cve-2026-24425 Fix sandbox bypass: propagate Source to checkArrow for source-policy sandboxing (fabpot)
This PR was merged into the twig-3.x branch.
2026-05-19 21:30:51 +02:00
Fabien Potencier fd0760d972 feature #4795 Lazy load EscaperRuntime in EscaperExtension (GromNaN)
This PR was merged into the 3.x branch.

Discussion
----------

Lazy load `EscaperRuntime` in `EscaperExtension`

This allows overriding `EscaperRuntime` via a custom runtime loader.

Previously, `EscaperExtension::setEnvironment()` was calling `$environment->getRuntime(EscaperRuntime::class)` eagerly. Since this method is called from `Environment::__construct()`, the runtime was resolved before any custom runtime loader could be injected, making it impossible to override `EscaperRuntime`.

- Required by https://github.com/symfony/symfony/pull/63929

Commits
-------

b73ab8cfd9 Lazy load EscaperRuntime in EscaperExtension
2026-05-17 07:52:38 +01:00
Fabien Potencier d0579ededc Fix sandbox bypass: propagate sandbox state to checkArrow for source-policy sandboxing 2026-05-16 18:56:08 +01:00
Fabien Potencier 5462817da0 Add a needs_is_sandboxed option for filters, functions, and tests 2026-05-16 18:52:17 +01:00
Jérôme Tamarelle b73ab8cfd9 Lazy load EscaperRuntime in EscaperExtension
Previously, setEnvironment() called getRuntime(EscaperRuntime::class) eagerly,
which prevented overriding EscaperRuntime via a custom runtime loader since
Environment::__construct() calls setEnvironment() before any loader can be injected.
2026-04-30 13:43:11 +02:00
Alexandre Daubois 3fe13f98f8 Fix sandbox bypass in object destructuring assignment 2026-04-28 12:59:06 +02:00
Younes ENNAJI 473653d19b [Core] Fix cycle() with non-countable ArrayAccess+Traversable objects 2025-11-23 13:20:23 +01:00