* 3.x:
Deprecate using parentheses when testing a macro with the defined test
# Conflicts:
# CHANGELOG
# doc/deprecated.rst
# src/ExpressionParser/Infix/DotExpressionParser.php
# src/ExpressionParser/Infix/FunctionExpressionParser.php
# src/ExpressionParser/Infix/IsExpressionParser.php
# tests/Fixtures/macros/call_without_parentheses.legacy.test
# tests/ParserTest.php
This PR was squashed before being merged into the 3.x branch.
Discussion
----------
Deprecate using parentheses when testing a macro with the defined test
Commits
-------
34d9c67d38 Deprecate using parentheses when testing a macro with the defined test
This PR was squashed before being merged into the 3.x branch.
Discussion
----------
Redesign macro calls and argument handling
This is my attempt to make macros "better". It uses modern PHP features that didn't exist when I designed macros a long time ago.
The first objective is to close the gap between their behavior and the behavior of Twig callables: functions, filters, and tests.
Here are some important changes:
* Calling a macro without passing a value for an argument that has no default value is deprecated; it is currently silently passed as `null`.
* Passing extra positional arguments or unknown named arguments to a macro without an explicit variadic argument is deprecated; these arguments are currently silently accepted through the implicit `varargs` variable.
* Explicit variadic macro arguments are now supported with `...name`.
* Macros are compiled as closures stored in the macro registry, instead of public generated `macro_*` methods.
The refactor introduces `TwigMacro` and `MacroArgument` to represent template-defined macros with an explicit signature, similar to the existing Twig callable model.
Commits
-------
d7f8b4eb1c Redesign macro calls and argument handling
* 3.x:
Make the sandbox a first-class citizen with a dedicated Sandbox class
# Conflicts:
# CHANGELOG
# doc/deprecated.rst
# doc/tags/sandbox.rst
# phpstan-baseline.neon
# src/Extension/CoreExtension.php
# src/Extension/SandboxExtension.php
# src/Sandbox/SecurityPolicy.php
This PR was squashed before being merged into the 3.x branch.
Discussion
----------
Make the sandbox a first-class citizen with a dedicated Sandbox class
I've been thinking about making the sabdbox feature as a first class citizen for years. With all the work that has been done recently on security issues, I spent some time on it again. Here is the result.
The main ideas:
* Currently, the sandbox is thigtly coupled to the "main" environment: `SandboxExtension` is registered on the environmen directly, so it instruments all compiled template, and adds runtime checks to all renders, trusted or not. As recommended in the docs, you should have a dedicated environment for sandboxes, different from the main one, but it's not really "enforced" nor natural to do.
* As a consequence, we store some state via `enableSandbox()`/`disableSandbox()` with try/finally patterns scattered across the codebase to support rendering sandboxed and non-sandboxed templates from a environment.
* When using one environment, a sandboxed template can `include` anything the loader can load, sees every application global, and inherits all extensions, this is a footgun (again, already not recommended in the docs).
* There are too maybe "knobs": global mode, `enableSandbox()`, `{% include(..., sandboxed: true) %}`, and `{% sandbox %}`.
The new `Twig\Sandbox\Sandbox` class renders untrusted templates through a dedicated, always-sandboxed environment crafted by the developer. Taht way, there is no state to toggle and nothing leaks between the main environment and the sandbox, in either direction.
Commits
-------
b762bc94b9 Make the sandbox a first-class citizen with a dedicated Sandbox class
This PR was merged into the 3.x branch.
Discussion
----------
Deprecate macro calls without parentheses
Commits
-------
ad305b414e Deprecate macro calls without parentheses
This PR was merged into the 3.x branch.
Discussion
----------
Rename macro variable AST nodes
The current name are just wrong as these classes are only used in the context of macros. They were confusing.
Commits
-------
be36fee09e Rename macro variable AST nodes
This PR was merged into the 3.x branch.
Discussion
----------
Clarify the security scope for untrusted templates
Commits
-------
222a7f3f9a Clarify the security scope for untrusted templates
* 3.x:
Reuse assignment targets parsed for the for tag
add shadowing example
Update for.rst
Fix IntlExtension ignoring explicit formats when a date formatter prototype is set
bump Twig version metadata
# Conflicts:
# CHANGELOG
# doc/tags/for.rst
# src/Environment.php
# src/TokenParser/ForTokenParser.php
This PR was merged into the 3.x branch.
Discussion
----------
Reuse assignment targets parsed for the for tag
`ForTokenParser` rebuilds the loop targets returned by `parseAssignmentExpression()` into new `AssignContextVariable` instances, copying only the name and line number. But the parsed targets are already `AssignContextVariable` nodes with exactly those values, so the rebuild is a no-op left over from older Twig versions where for-targets were parsed as general expressions and needed normalizing.
Reusing the parsed nodes directly removes dead code, and makes the parser more robust: any metadata attached to the targets during parsing (now or in the future) is preserved instead of being silently dropped.
Commits
-------
9408f2a3f1 Reuse assignment targets parsed for the for tag
This PR was merged into the 3.x branch.
Discussion
----------
Update for.rst
Add context and explanation about loop.parent.
Commits
-------
02382585e9 add shadowing example
7234d51ec8 Update for.rst
This PR was merged into the 4.x branch.
Discussion
----------
⚰️ Drop useless php comparisons
Commits
-------
f2e549a92b⚰️ Drop useless php comparisons
This PR was squashed before being merged into the 3.x branch.
Discussion
----------
Fix IntlExtension ignoring explicit formats when a date formatter prototype is set
Closes#3845
Commits
-------
083b6dcabe Fix IntlExtension ignoring explicit formats when a date formatter prototype is set
This PR was merged into the 3.x branch.
Discussion
----------
bump Twig version metadata
following #4852
Commits
-------
57905dab67 bump Twig version metadata
This PR was squashed before being merged into the 3.x branch.
Discussion
----------
Document and test sandbox __call support
Related to #1950
Commits
-------
29b66fd916 Document sandbox handling of magic __call() methods
72da20aeb7 Add sandbox tests for methods routed through __call()