Commit Graph

60 Commits

Author SHA1 Message Date
Fabien Potencier 19099de78e Merge branch '3.x' into 4.x
* 3.x:
  Skip the sandbox `__toString` check on arguments whose PHP parameter type cannot implicitly coerce to string
  Fix  CS
  Bump version
  Prepare the 3.27.1 release
  Fix inconsistent array access with a Stringable key
  Preserve IteratorAggregate identity in sandbox __toString walker
  Fix tests
  Bump version
  Prepare the 3.27.0 release
  Fix sandbox filter/tag/function allow-list bypass when sandbox state changes between renders
  Document new support for any expression as a dynamic mapping key
  Fix sandbox __toString policy bypass via dynamic mapping keys
  Fix deprecation notices in tests
  Guard sandbox `__toString` walker against self-referencing iterables
  Fix sandbox `__toString` bypass via `Stringable` + `Traversable` containers
  Fix sandbox `__toString` bypass via the `in` and `not in` operators
  Fix sandbox __toString bypass via Traversable in join/replace filters
  Mark new SourcePolicyInterface column filter tests as @group legacy
  Fix sandbox bypass in the "column" filter under SourcePolicyInterface
  Fix sandbox bypass in deprecated internal wrappers

# Conflicts:
#	CHANGELOG
#	src/Environment.php
#	src/Node/Expression/ArrayExpression.php
#	src/Node/Expression/CallExpression.php
#	src/Resources/core.php
#	src/Template.php
#	src/Util/CallableArgumentsExtractor.php
#	src/Util/ReflectionCallable.php
#	tests/Extension/SandboxTest.php
#	tests/Resources/LegacyCoreTest.php
#	tests/TemplateTest.php
2026-06-02 14:05:57 +02:00
Fabien Potencier 6d5ef30436 Skip the sandbox __toString check on arguments whose PHP parameter type cannot implicitly coerce to string 2026-06-02 13:58:24 +02:00
Fabien Potencier 638869ee9e Fix CS 2026-05-23 11:32:44 +02:00
Fabien Potencier 0c515667d2 Merge remote-tracking branch 'origin/3.x' into 4.x
* origin/3.x:
  Add a `needs_is_sandboxed` option for filters, functions, and tests
  Bump version
  Make embeds deterministic
  [Doc] Document loose comparison in the `in` operator
  [Doc] Reword whitespace control note about first-newline removal
  Stop publishing extra package minor versions with no changes
  Lazy load EscaperRuntime in EscaperExtension
  Fix typo
  Replace parent-child analogy in `doc/tags/extends.rst`
  doc: Add missing toctree entries and fix ordering
  Fix CHANGELOG
  Bump version
  Prepare the 3.24.0 release
2026-05-17 08:18:04 +01:00
Fabien Potencier 5462817da0 Add a needs_is_sandboxed option for filters, functions, and tests 2026-05-16 18:52:17 +01:00
Fabien Potencier b3cbcedced Move to PHPStan level 5 2026-02-23 15:07:49 +01:00
Fabien Potencier 0facb551b0 Merge branch '3.x' into 4.x
* 3.x:
  Fix CS
2026-02-07 09:12:05 +01:00
Fabien Potencier 861215c507 Fix CS 2026-02-07 09:07:38 +01:00
Fabien Potencier 3e97fc610f Merge branch '3.x' into 4.x
* 3.x:
  re-add mixed return type
2025-02-14 14:08:09 +01:00
Christian Flothmann 5f6c67f838 re-add mixed return type 2025-02-14 13:47:07 +01:00
Fabien Potencier 151aa4ecda Fix CS 2025-02-14 12:57:03 +01:00
Simon André 82be13429c Add return type annotations on Twig 3 to prepare Twig 4 2025-01-24 11:32:59 +01:00
Vincent Langlet 29fce6de1e Bump Phpstan to level 4 2024-12-02 20:49:24 +01:00
Fabien Potencier 70d9cec591 Remove deprecated features 2024-09-21 09:19:32 +02:00
Fabien Potencier 4074410313 Merge branch '3.x' into 4.x
* 3.x:
  [Doc] Document about `html` and `html_attr` strategies
  Improve date methods phpdoc
  Fix deprecation messages
  Use a more precise return type in AbstractTwigCallable
  fix the handling of predefined arguments in CallExpression
  Allow Twig callable arguments to use camel or snake names
  fix intl-extra tests
  fix typo
2024-09-21 09:17:48 +02:00
Fabien Potencier 52ded207d3 Allow Twig callable arguments to use camel or snake names 2024-09-18 19:19:20 +02:00
Fabien Potencier 9700212005 Merge branch '3.x' into 4.x
* 3.x:
  Rename a variable for more clarity
  Set IteratorAggregate generics for Node
  Add cross-link
  Let's no deprecate the attribute function yet
  Add more precise types for the registration of safe classes
  Clarify coding standards
  Fix markup
  Fix markup
  Clarify docs for the u filter
  Allow to use a dynamic attribute on the . operator via ()
  Remove most usage of foo/bar/baz in the docs
  Tweak docs
  Add StringCastUnary
2024-09-14 10:51:19 +02:00
Fabien Potencier 4c9526a31d Rename a variable for more clarity 2024-09-14 10:31:13 +02:00
Fabien Potencier fa1c9f0bf9 Merge branch '3.x' into 4.x
* 3.x:
  Remove obsolete code
  Deprecate Environment::mergeGlobals()
  Bump version
  Prepare the 3.13.0 release
  Fix wrong format of `Environment::VERSION_ID` constant
  Fix minor things
  Fix CS
  Fix isset in ForLoopNode
  Fix iterable return type
  Improve exception expectations reliability
2024-09-07 17:03:10 +02:00
Fabien Potencier 978f749b43 Fix minor things 2024-09-06 12:58:38 +02:00
Christian Flothmann 038d70f2aa remove no longer needed PHP version checks 2024-09-02 15:38:31 +02:00
Fabien Potencier 61aa645a30 Merge branch '3.x' into 4.x
* 3.x:
  Fix doc markup
  Add an example on how to iterate over a string
  Remove NodeCaptureInterface from TypesNode
  Use CPP in full code base
  Add types tag
  Bump version
  Bump version
  Prepare the 3.12.0 release
  Fix CS
  Add conditional return types to `ensureTraversable`
  Add return type `isTraitable`
2024-08-30 12:38:56 +02:00
andreybolonin1989@gmail.com 28923f4269 Use CPP in full code base 2024-08-29 19:29:39 +02:00
Fabien Potencier b5372f5764 Merge branch '3.x' into 4.x
* 3.x:
  Fix CS
  Remove obsolete comment
  Resolves #4200
2024-08-20 18:12:56 +02:00
Fabien Potencier 302971f34e Fix CS 2024-08-20 18:10:26 +02:00
Fabien Potencier 5678ee080d Merge branch '3.x' into 4.x
* 3.x:
  Refactor code
  Add a test
2024-08-20 17:21:22 +02:00
Fabien Potencier 31037d0e51 Refactor code 2024-08-20 15:39:54 +02:00
Fabien Potencier 15c0adb3ed Merge branch '3.x' into 4.x
* 3.x:
  Fix CS
2024-08-18 19:26:04 +02:00
Fabien Potencier 675cb2d141 Fix CS 2024-08-18 19:25:19 +02:00
Fabien Potencier 22ff3f4f22 Merge branch '3.x' into 4.x
* 3.x:
  Fix typos in CHANGELOG
  Fix typo
  Fix some minor issues
  Add support for named arguments on special functions
2024-08-17 18:03:35 +02:00
Fabien Potencier 2e43eaa4ad Fix some minor issues 2024-08-16 22:51:19 +02:00
Fabien Potencier d051ccde20 Merge branch '3.x' into 4.x
* 3.x:
  Throw a SyntaxError exception at compile time when a Twig callable has not the minimum number of required arguments
2024-08-16 08:12:37 +02:00
Fabien Potencier 0823d23488 Throw a SyntaxError exception at compile time when a Twig callable has not the minimum number of required arguments 2024-08-15 23:00:02 +02:00
Fabien Potencier 4bade436a4 Merge branch '3.x' into 4.x
* 3.x:
  Extract a new CallableArgumentsExtractor class
  Make Node::__toString() more readable
2024-08-15 20:57:57 +02:00
Fabien Potencier e1705f8831 Extract a new CallableArgumentsExtractor class 2024-08-15 20:37:59 +02:00
Fabien Potencier 7324404f27 Merge branch '3.x' into 4.x
* 3.x:
  Fix various phpstan errors
  Fix EscaperRuntime namespace
2024-07-31 09:34:53 +02:00
Fabien Potencier ae4f284043 Fix various phpstan errors 2024-07-30 11:17:22 +02:00
Fabien Potencier fcb36ec18a Merge branch '3.x' into 4.x
* 3.x:
  Add support for first class callables
2024-07-14 13:59:52 +02:00
Fabien Potencier d2eab12e70 Add support for first class callables 2024-07-14 13:56:14 +02:00
Fabien Potencier 21cd159ff2 Revert "Make compatible with PHP<8"
This reverts commit bb967b3dd3.
2024-07-14 12:17:49 +02:00
Fabien Potencier 4afc66cc82 Merge branch '3.x' into 4.x
* 3.x:
  Make compatible with PHP<8
  Extract ReflectionCallable to make it reusable
  Make a small optimization
  [Doc] Fix `do` tag label in link
2024-07-14 12:17:41 +02:00
Fabien Potencier bb967b3dd3 Make compatible with PHP<8 2024-07-14 12:13:12 +02:00
Fabien Potencier 093f51a8b9 Extract ReflectionCallable to make it reusable 2024-07-14 12:06:15 +02:00
Fabien Potencier 13e57cb3fe Remove usage of ReturnTypeWillChange 2023-12-24 11:22:05 +01:00
Fabien Potencier 35640b6d2d Add type hints to private properties 2023-12-14 20:43:37 +01:00
Christian Flothmann 41f1b0370a restore return type annotations 2023-10-08 20:59:56 +02:00
Fabien Potencier 5193653ecb Fix CS 2023-10-08 09:05:22 +02:00
Fabien Potencier 464842c41f Merge branch '2.x' into 3.x
* 2.x:
  Add explicit `@return` type next to `#[ReturnTypeWillChange]`
2021-08-11 09:52:24 +02:00
Nicolas Grekas 1d0bab9d63 Add explicit @return type next to #[ReturnTypeWillChange] 2021-08-10 18:49:26 +02:00
Fabien Potencier 13e360972a Merge branch '2.x' into 3.x
* 2.x:
  Fix CS
  Fix CS
  Migrate to the new PHP CS Fixer config file
  Fixing links
2021-05-12 09:45:40 +02:00