Commit Graph

960 Commits

Author SHA1 Message Date
Fabien Potencier 42735a2cad Always allow the loop variable in sandboxed templates 2026-09-26 13:46:24 +02:00
Fabien Potencier 42a5ec12f5 Merge branch '3.x' into 4.x 2026-09-26 10:46:04 +02:00
Fabien Potencier 7bf3a6b3f5 feature #4967 Render the for else clause when the loop condition skips every item (fabpot)
This PR was merged into the 4.x branch.

Discussion
----------

Render the for else clause when the loop condition skips every item

Commits
-------

67b4491eda Render the for else clause when the loop condition skips every item
2026-09-26 10:44:51 +02:00
Fabien Potencier d5011f4654 Discard what the non-selected branch of a guard tag registers on the parser 2026-09-26 10:43:21 +02:00
Fabien Potencier 39642e4cdf Reset the escaping state when compiling a new template after a compilation error 2026-09-26 10:41:54 +02:00
Fabien Potencier f2ba4ec53f bug #4961 Reject an autoescape strategy that is neither a string nor false at compile time (fabpot)
This PR was merged into the 4.x branch.

Discussion
----------

Reject an autoescape strategy that is neither a string nor false at compile time

A left over from 2.0

Commits
-------

4fb86a896f Reject an autoescape strategy that is neither a string nor false at compile time
2026-09-26 10:39:17 +02:00
Fabien Potencier 6ec06d1883 bug #4959 Reject a Template instance created by another environment when resolving templates (fabpot)
This PR was merged into the 3.x branch.

Discussion
----------

Reject a Template instance created by another environment when resolving templates

Commits
-------

605b1278f7 Reject a Template instance created by another environment when resolving templates
2026-09-26 10:38:49 +02:00
Fabien Potencier b1d6b51183 Fix the sandbox not reporting the line of a rejected guard tag 2026-09-26 10:22:21 +02:00
Fabien Potencier 67b4491eda Render the for else clause when the loop condition skips every item 2026-09-26 09:33:24 +02:00
Fabien Potencier 4fb86a896f Reject an autoescape strategy that is neither a string nor false at compile time 2026-09-26 08:21:56 +02:00
Fabien Potencier bb0dbfc229 Stop passing the template source to the sandbox checks that no longer use it 2026-09-25 23:52:13 +02:00
Fabien Potencier 605b1278f7 Reject a Template instance created by another environment when resolving templates 2026-09-25 23:34:59 +02:00
Fabien Potencier 40b0349558 Run the attribute function fixtures as regular integration tests 2026-09-25 23:31:09 +02:00
Fabien Potencier 07b8427e26 Merge branch '3.x' into 4.x 2026-09-25 18:04:23 +02:00
Fabien Potencier ddd9045b5c Skip the property checker call and memoize the class constant probe when reading an object attribute 2026-09-25 16:00:51 +02:00
Fabien Potencier 3417f483bf Fetch the escaper runtime once in the constructor of templates that escape 2026-09-25 12:44:56 +02:00
Fabien Potencier 00861d50ab Fix split trailing newline 2026-09-25 12:39:38 +02:00
Fabien Potencier c8d782ea0b Deprecate calling TemplateWrapper::unwrap() without arguments as of 3.30 and list the fix in the CHANGELOG 2026-09-25 07:44:32 +02:00
Fabien Potencier 9c3d58e638 Fix coding standards 2026-09-25 07:44:12 +02:00
Nicolas Grekas d3d13f9b1a Speed up adding extensions to an environment 2026-09-24 18:47:14 +02:00
Fabien Potencier 3c89f82d4a Cleanup 4.x - Stop detecting echo and print in compiled nodes 2026-09-23 10:50:26 +01:00
Fabien Potencier 4d5d233776 Compile the generator guard as an unreachable yield instead of a yield from 2026-09-22 22:00:07 +01:00
Fabien Potencier 10adb67bcf Remove deprecated code 2026-09-22 21:17:13 +01:00
Fabien Potencier a38543b5a3 Fix merge conflict resolution 2026-09-22 21:14:25 +01:00
Fabien Potencier f3bacf3877 Merge branch '3.x' into 4.x
* 3.x:
  Reuse the template wrapper of an already loaded template
  Stop the escaping safe analysis from retaining every analyzed node
  Allow to call TemplateWrapper::unwrap() without arguments
  Expose the escaping strategy a template was compiled with
  Improve macro call performance
  Fix IntlExtension inheriting values derived by ICU from a date formatter prototype
  Fix array access with a Stringable key on subclasses of ArrayObject and ArrayIterator
  Ignore the PHPUnit 10+ cache directory
  Cover and document the matches operator throwing on an invalid UTF-8 subject
  Report a clear error when a string cannot be split into characters
  Deprecate cloning a Twig environment
  Report the macro call parentheses deprecation once per call site and name the macro
  Bump version
  Prepare the 3.29.0 release
  Update CHANGELOG

# Conflicts:
#	.gitignore
#	CHANGELOG
#	doc/deprecated.rst
#	src/Environment.php
#	src/NodeVisitor/CorrectnessNodeVisitor.php
#	src/NodeVisitor/SafeAnalysisNodeVisitor.php
#	src/Template.php
#	tests/Fixtures/macros/call_without_parentheses.legacy.test
#	tests/ParserTest.php
#	tests/TemplateTest.php
#	tests/TwigMacroTest.php
2026-09-22 21:10:53 +01:00
Fabien Potencier 6f94a47ce1 Reuse the template wrapper of an already loaded template 2026-09-22 21:02:38 +01:00
Fabien Potencier ff4a1c6575 bug #4937 Stop the escaping safe analysis from retaining every analyzed node (fabpot)
This PR was merged into the 3.x branch.

Discussion
----------

Stop the escaping safe analysis from retaining every analyzed node

Commits
-------

8274571d04 Stop the escaping safe analysis from retaining every analyzed node
2026-09-22 20:42:55 +01:00
Fabien Potencier 8274571d04 Stop the escaping safe analysis from retaining every analyzed node 2026-09-22 16:47:34 +01:00
Alexander M. Turek bfbe89e3a3 Allow to call TemplateWrapper::unwrap() without arguments 2026-09-22 09:22:57 +02:00
Fabien Potencier 26812ebc0d Expose the escaping strategy a template was compiled with 2026-09-21 11:30:11 +01:00
Fabien Potencier a8ee6dd762 Improve macro call performance 2026-09-20 21:28:03 +01:00
Fabien Potencier d722e8af93 bug #4931 Fix array access with a Stringable key on subclasses of ArrayObject and ArrayIterator (fabpot)
This PR was squashed before being merged into the 3.x branch.

Discussion
----------

Fix array access with a Stringable key on subclasses of ArrayObject and ArrayIterator

Commits
-------

4aae99e92c Fix array access with a Stringable key on subclasses of ArrayObject and ArrayIterator
2026-09-20 20:17:49 +01:00
Fabien Potencier 4aae99e92c Fix array access with a Stringable key on subclasses of ArrayObject and ArrayIterator 2026-09-20 20:17:42 +01:00
Fabien Potencier 1ee9dae55a Cover and document the matches operator throwing on an invalid UTF-8 subject 2026-09-18 17:15:53 +01:00
Fabien Potencier 5c1be030c5 Report a clear error when a string cannot be split into characters 2026-09-18 17:15:50 +01:00
Fabien Potencier 55afb2e084 Deprecate cloning a Twig environment 2026-09-18 16:52:58 +01:00
Fabien Potencier 40d57c6445 Report the macro call parentheses deprecation once per call site and name the macro 2026-09-18 12:17:08 +02:00
Fabien Potencier c4146f8ba2 Fix merge conflict resolution 2026-09-14 14:14:21 +02:00
Fabien Potencier 6123bfe4ee Merge branch '3.x' into 4.x
* 3.x:
  Reject cross-environment template wrappers in block chains
  Reject cross-environment template wrappers

# Conflicts:
#	CHANGELOG
#	tests/TemplateTest.php
2026-09-14 14:13:36 +02:00
Fabien Potencier dea0483027 feature #4910 Reject template wrappers from another environment (fabpot)
This PR was squashed before being merged into the 3.x branch.

Discussion
----------

Reject template wrappers from another environment

Twig now rejects `TemplateWrapper` instances created by another `Environment`.

This prevents templates from unexpectedly using another environment's loader, extensions, globals, or sandbox policy.

Commits
-------

83e8f7e123 Reject cross-environment template wrappers in block chains
c1fc112047 Reject cross-environment template wrappers
2026-09-14 14:11:48 +02:00
Fabien Potencier 3d70559df3 Fix two block chain tests referencing a removed data provider 2026-09-14 14:09:55 +02:00
Fabien Potencier 11ff7bf08f Merge branch '3.x' into 4.x
* 3.x:
  Clarify the exception message for nested block chains from another environment
  Report a clear error when using macros imported in a template body that was not rendered

# Conflicts:
#	CHANGELOG
#	src/Template.php
#	tests/CallMacroTest.php
2026-09-14 14:07:14 +02:00
Fabien Potencier 0f5c902d85 bug #4927 Report a clear error when using macros imported in a template body that was not rendered (fabpot)
This PR was merged into the 3.x branch.

Discussion
----------

Report a clear error when using macros imported in a template body that was not rendered

Commits
-------

72c2f669bd Report a clear error when using macros imported in a template body that was not rendered
2026-09-14 14:05:45 +02:00
Fabien Potencier 56e5c0794b Clarify the exception message for nested block chains from another environment 2026-09-14 11:59:20 +02:00
Fabien Potencier 6b5e02f47d Merge branch '3.x' into 4.x
* 3.x:
  Allow block chains to be composed of other block chains
2026-09-14 11:27:09 +02:00
Fabien Potencier d6b81f9074 Allow block chains to be composed of other block chains 2026-09-14 11:17:44 +02:00
Fabien Potencier 72c2f669bd Report a clear error when using macros imported in a template body that was not rendered 2026-09-12 12:17:17 +02:00
Fabien Potencier 620783d2b1 Fix merge conflict resolution 2026-09-12 10:00:48 +02:00
Fabien Potencier 44eb4242ad Merge branch '3.x' into 4.x
* 3.x:
  Resolve block chains against the render context instead of freezing lineages
  Resolve constant parent templates once instead of on every lookup
  Template runtime and block composition
  Fix wrapping the Twig cache pool in a second tag aware adapter
  Check that the use tag is allowed before resolving trait templates

# Conflicts:
#	CHANGELOG
#	extra/twig-extra-bundle/TwigExtraBundle.php
#	src/Template.php
2026-09-12 09:57:39 +02:00
Fabien Potencier 83e8f7e123 Reject cross-environment template wrappers in block chains 2026-09-12 09:57:01 +02:00