Commit Graph

557 Commits

Author SHA1 Message Date
Fabien Potencier 279fe13b22 Fix nested block() resolution when a directly rendered block calls parent() 2026-06-03 22:13:40 +02:00
Fabien Potencier 89f886e324 Skip the string cast in PrintNode when the expression is already a string and add tests 2026-06-03 19:56:27 +02:00
Fabien Potencier 8a4b77920a Add PHPUnit attributes alongside annotations to silence doc-comment metadata deprecations on PHPUnit 11 2026-06-03 18:26:39 +02:00
Fabien Potencier ee8ab447d7 Make IntegrationTestCase and NodeTestCase compatible with PHPUnit 11 2026-06-03 18:17:03 +02:00
Fabien Potencier 6d5ef30436 Skip the sandbox __toString check on arguments whose PHP parameter type cannot implicitly coerce to string 2026-06-02 13:58:24 +02:00
Fabien Potencier 4e58cb22e5 Fix CS 2026-06-01 09:00:03 +02:00
Fabien Potencier 8ec9530732 Fix inconsistent array access with a Stringable key 2026-05-29 10:06:57 +02:00
Fabien Potencier d25f98f45b Preserve IteratorAggregate identity in sandbox __toString walker 2026-05-29 09:31:03 +02:00
Fabien Potencier 118938b191 Fix tests 2026-05-29 09:30:54 +02:00
Fabien Potencier 23eb6eb126 Fix sandbox filter/tag/function allow-list bypass when sandbox state changes between renders 2026-05-27 14:59:42 +02:00
Fabien Potencier 7d55aa838c security #cve-2026-48805 Fix sandbox bypass in deprecated internal wrappers (fabpot)
This PR was merged into the twig-3.x branch.
2026-05-27 14:55:54 +02:00
Fabien Potencier 635cea4789 Document new support for any expression as a dynamic mapping key 2026-05-27 14:54:58 +02:00
Fabien Potencier 9ff4101463 Fix sandbox __toString policy bypass via dynamic mapping keys 2026-05-27 14:54:34 +02:00
Fabien Potencier e3f66654b8 Fix deprecation notices in tests 2026-05-27 14:53:02 +02:00
Fabien Potencier 475fb690ac Guard sandbox __toString walker against self-referencing iterables 2026-05-27 14:53:02 +02:00
Fabien Potencier e9e818cbfc Fix sandbox __toString bypass via Stringable + Traversable containers 2026-05-27 14:53:01 +02:00
Fabien Potencier 8d6af0707b Fix sandbox __toString bypass via the in and not in operators 2026-05-27 14:52:32 +02:00
Fabien Potencier cc1e21a2a2 Fix sandbox __toString bypass via Traversable in join/replace filters 2026-05-27 14:52:30 +02:00
Fabien Potencier afbaa2a9da Mark new SourcePolicyInterface column filter tests as @group legacy
These tests pass a SourcePolicyInterface instance to SandboxExtension, which
triggers the 3.27 deprecation. Mark them legacy and assert the deprecation
to silence the PHPUnit "unhandled deprecation" report.
2026-05-27 14:49:53 +02:00
Fabien Potencier 09c6706407 Fix sandbox bypass in the "column" filter under SourcePolicyInterface 2026-05-27 14:49:52 +02:00
Fabien Potencier af7bf5e181 Add a strict mode to SecurityPolicy to opt-in to the 4.0 sandbox behavior for the extends/use tags and the parent/block/attribute functions 2026-05-25 13:40:27 +02:00
Fabien Potencier cfaa2fd030 Deprecate the fact that the parent, block, and attribute functions are always allowed in a sandboxed template 2026-05-24 21:19:56 +02:00
Fabien Potencier 33690a4a28 Fix PHP 8.1+ implicit float-to-int deprecation in sandboxed array access 2026-05-24 17:39:37 +02:00
Fabien Potencier e235cae3a1 Fix sandbox bypass in deprecated internal wrappers 2026-05-24 11:10:36 +02:00
Fabien Potencier f6aca309d8 Escape root profile name in HtmlDumper 2026-05-23 09:39:26 +02:00
Fabien Potencier 4c1dae5e71 Restrict allowed classes in Profile::unserialize() 2026-05-23 09:09:19 +02:00
Fabien Potencier 4fc0210084 Bump version 2026-05-23 08:32:22 +02:00
Fabien Potencier bd924d5d33 Deprecate the "Twig\Sandbox\SourcePolicyInterface" interface 2026-05-23 08:30:05 +02:00
Fabien Potencier 0a80d1a9aa Remove Drupal integration tests 2026-05-22 12:38:21 +02:00
Fabien Potencier a0a1f1d17d Replace FQCN with use statements in SandboxTest 2026-05-22 12:08:11 +02:00
Fabien Potencier 4a64b5b486 Fix CS 2026-05-21 16:34:23 +02:00
Fabien Potencier 3190b9ae12 Pre-escape HTML input on the spaceless filter 2026-05-20 08:29:48 +02:00
Alexandre Daubois f05c5011c2 Fix sandbox bypass in the "column" filter 2026-05-20 07:33:52 +02:00
Fabien Potencier 2e4b6d286e security #cve-2026-47732 [Sandbox] Fix __toString() support (fabpot)
This PR was merged into the twig-3.x branch.
2026-05-20 07:31:34 +02:00
Fabien Potencier 3464990a51 security #cve-2026-47730 [Profiler] Escape template and profile names in HtmlDumper (nicolas-grekas)
This PR was merged into the twig-3.x branch.
2026-05-20 07:31:01 +02:00
Fabien Potencier 447d0b2331 Fix sandbox __toString bypasses 2026-05-20 00:18:59 +02:00
Fabien Potencier ea3f7a2844 Validate macro name in MacroReferenceExpression constructor
The name passed to MacroReferenceExpression is emitted as raw PHP in
compile() via "->{$name}(...)". Callers were expected to validate
the name, but a missing check led to CVE-2026-XXXXX (PHP code injection
via _self / import macro reference): defense-in-depth, validate the
name in the constructor so the class is safe by construction.
2026-05-19 23:42:31 +02:00
Alexandre Daubois 324fa60545 Fix sandbox bypass: PHP code injection via _self / import macro reference 2026-05-19 23:41:59 +02:00
Fabien Potencier aeb37f4801 Fix deprecations in tests 2026-05-19 23:05:30 +02:00
Alexandre Daubois 819c6a89fe Fix sandbox bypass in the {% sandbox %} tag when including a preloaded template 2026-05-19 23:00:58 +02:00
Fabien Potencier 679447fa29 Encode single quotes as \x27 in Compiler::string()
This is a defense-in-depth measure: callers must always concatenate the
result into a double-quoted PHP context, but if one ever (mistakenly)
embeds it inside a single-quoted PHP literal, an attacker-controlled
single quote in the source value could break out of that context. The
previous commit fixed exactly such a bug in ModuleNode for the {% use %}
template name.

Encoding ' as the hex escape \x27 guarantees that the emitted PHP source
never contains a literal single quote derived from user input, while the
decoded runtime value is unchanged. \' is not used because it is not a
recognized escape sequence in PHP double-quoted strings (the backslash
would be kept literally).
2026-05-19 22:58:27 +02:00
Alexandre Daubois e9ff55f691 Fix sandbox bypass: PHP code injection via {% use %} template name 2026-05-19 22:50:45 +02:00
Fabien Potencier e494400ce4 Fix deprecation 2026-05-19 22:05:26 +02:00
Fabien Potencier a8eb5a8a74 security #cve-2026-46639 Fix sandbox bypass in object destructuring assignment (alexandre-daubois)
This PR was merged into the twig-3.x branch.
2026-05-19 21:37:04 +02:00
Fabien Potencier c8dfd62064 security #cve-2026-24425 Fix sandbox bypass: propagate Source to checkArrow for source-policy sandboxing (fabpot)
This PR was merged into the twig-3.x branch.
2026-05-19 21:30:51 +02:00
Nicolas Grekas a5f6e8793e [Profiler] Escape template and profile names in HtmlDumper
The HtmlDumper output is intended to be rendered in a browser, and the
template and macro/block names it interpolates are loader-controlled
(e.g. the key for ArrayLoader or a database row id), so they can carry
arbitrary HTML when an application stores templates under user-supplied
identifiers.
2026-05-19 18:54:32 +02:00
Fabien Potencier fd0760d972 feature #4795 Lazy load EscaperRuntime in EscaperExtension (GromNaN)
This PR was merged into the 3.x branch.

Discussion
----------

Lazy load `EscaperRuntime` in `EscaperExtension`

This allows overriding `EscaperRuntime` via a custom runtime loader.

Previously, `EscaperExtension::setEnvironment()` was calling `$environment->getRuntime(EscaperRuntime::class)` eagerly. Since this method is called from `Environment::__construct()`, the runtime was resolved before any custom runtime loader could be injected, making it impossible to override `EscaperRuntime`.

- Required by https://github.com/symfony/symfony/pull/63929

Commits
-------

b73ab8cfd9 Lazy load EscaperRuntime in EscaperExtension
2026-05-17 07:52:38 +01:00
Fabien Potencier d0579ededc Fix sandbox bypass: propagate sandbox state to checkArrow for source-policy sandboxing 2026-05-16 18:56:08 +01:00
Fabien Potencier 5462817da0 Add a needs_is_sandboxed option for filters, functions, and tests 2026-05-16 18:52:17 +01:00
itsalmostchristmas 2b4aa4458a Make embeds deterministic 2026-05-16 09:48:23 +01:00