This PR was merged into the 3.x branch.
Discussion
----------
Clarify documentation for escape filter
It was somewhat unclear from the documentation what the intended purpose of the 'js' escape strategy is. I wasn't certain *where* exactly in JavaScript such strings were intended to be output. Someone (by that I mean me--though maybe I'm just an idiot...) might inadvertently think the filter was meant to be used somewhere in actual JavaScript code, rather than simply in strings.
Commits
-------
728b361e9d Clarify documentation for escape filter
* 3.14.x:
Improve detection of recursion
Fix recursion when arrays contain self-references in sandboxed mode
Fix code
Prepare the 3.11.2 release
Update CHANGELOG
Sandbox ArrayAccess and do sandbox checks before isset() checks
Fix sandbox handling for __toString()
Prepare the 3.14.1 release
Update CHANGELOG
Sandbox ArrayAccess and do sandbox checks before isset() checks
Fix sandbox handling for __toString()
Prepare the 3.11.1 release
Fix a security issue when an included sandboxed template has been loaded before without the sandbox context
* 3.11.x:
Improve detection of recursion
Fix recursion when arrays contain self-references in sandboxed mode
Fix code
Prepare the 3.11.2 release
Update CHANGELOG
Sandbox ArrayAccess and do sandbox checks before isset() checks
Fix sandbox handling for __toString()
Prepare the 3.11.1 release
Fix a security issue when an included sandboxed template has been loaded before without the sandbox context
This PR was squashed before being merged into the 3.x branch.
Discussion
----------
Fix mistake in docs for `keys` filter
Commits
-------
deb37c30c4 Fix mistake in docs for `keys` filter
This PR was merged into the 3.x branch.
Discussion
----------
Rename Node classes related to variables
Whenever I work on Twig internals, it's always complicated to reason about variable names, probably because the class names are confusing. This PR is an attempt to find "better" and more explicit names.
This PR does the following renaming:
* `NameExpression` to `Variable\ContextVariable`
Represents the value of a context variable like `$context[VAR] ?? null`
* `AssignNameExpression` to `Variable\AssignContextVariable`
Represents a context variable assignment like in `$context[VAR] = `
* `TempNameExpression` to `Variable\LocalVariable`
Represents a "private" local variable like `$_l111`
Commits
-------
fc15e7ccbc Rename Node classes related to variables
This PR was squashed before being merged into the 3.x branch.
Discussion
----------
Documentation for types tag uses Twig types in examples instead of PHP
Specifically, "bool" => "boolean" and "int" => "number".
This aligns the `types` documentation with templates.rst. See #4362
Thanks, `@alexander`-schranz!
Commits
-------
f3e0a00cf0 Documentation for types tag uses Twig types in examples instead of PHP
This PR was merged into the 3.x branch.
Discussion
----------
Move sandbox docs to its own chapter in the docs
I've also added more information about potential security issues when exposing something that takes a callable as an argument.
Commits
-------
6688a8df16 Move sandbox docs to its own chapter in the docs
This PR was merged into the 3.x branch.
Discussion
----------
Deprecate passing a string or an array to Twig callable arguments accepting arrow functions (pass a Closure)
Instead of restricting callable arguments only in sandbox mode, let's deprecate using functions/arrays as callables.
Commits
-------
5e9448310d Deprecate passing a string or an array to Twig callable arguments accepting arrow functions (pass a Closure)
This PR was squashed before being merged into the 3.x branch.
Discussion
----------
Trigger deprecations when using "??" and "not" without explicit parentheses when precedence will change in 4.0
Closes#3387Closes#3642
Commits
-------
2081b1ff74 Deprecate using the not unary operator without parenthesis
f4aacafd78 Deprecate using ?? without explicit parentheses
This PR was merged into the 3.x branch.
Discussion
----------
Document Twig vs PHP types
Refs #4256
Commits
-------
9690e7bbbf Document Twig vs PHP types
This PR was merged into the 3.x branch.
Discussion
----------
Add more information about the filter and the negative operators
Refs #974
Refs #1368
Refs #1634
Refs #2470
Commits
-------
fae6cfc32f Add more information about the filter and the negative operators