This PR was squashed before being merged into the 3.x branch.
Discussion
----------
[Doc] Update the docs about attribute() function
I Was fixing `filter` -> `function` error, but I realized that we could expand the docs of `attribute()` a bit, even if it's deprecated 🙏
Commits
-------
84daad9a27 [Doc] Update the docs about attribute() function
This PR was merged into the 3.x branch.
Discussion
----------
Add a way to stream template rendering
Even if we're using `yield` internally, there is no easy way to stream template rendering. This new method can be used like this to HTTP stream a template with Symfony:
```php
use Symfony\Component\HttpFoundation\StreamedResponse;
use Twig\Environment;
$twig = new Environment(/* ... */);
$response = new StreamedResponse($twig->load('index')->stream([]));
$response->send();
```
Commits
-------
1915ee2812 Add a way to stream template rendering
This PR was squashed before being merged into the 3.x branch.
Discussion
----------
Support underscores in number literals
```twig
{{ 1000 == 1_000 ? 'yes' : 'no' }}
# now: syntax error
# this PR: "yes"
```
> As of PHP 7.4.0, integer literals may contain underscores (_) between digits, for better readability of literals. These underscores are removed by PHP's scanner.
https://www.php.net/manual/en/language.types.integer.php
This PR replicates that behaviour, using the regexp to match the literals and then remove the "_".
I'm targeting **Twig4** but maybe 3.x would be ok?
I cannot think of a real case that
- does not trigger an error currently
- would work differently after this PR
Commits
-------
da4d96692a Support underscores in number literals
This PR was merged into the 3.x branch.
Discussion
----------
Clarify documentation for escape filter
It was somewhat unclear from the documentation what the intended purpose of the 'js' escape strategy is. I wasn't certain *where* exactly in JavaScript such strings were intended to be output. Someone (by that I mean me--though maybe I'm just an idiot...) might inadvertently think the filter was meant to be used somewhere in actual JavaScript code, rather than simply in strings.
Commits
-------
728b361e9d Clarify documentation for escape filter
* 3.14.x:
Improve detection of recursion
Fix recursion when arrays contain self-references in sandboxed mode
Fix code
Prepare the 3.11.2 release
Update CHANGELOG
Sandbox ArrayAccess and do sandbox checks before isset() checks
Fix sandbox handling for __toString()
Prepare the 3.14.1 release
Update CHANGELOG
Sandbox ArrayAccess and do sandbox checks before isset() checks
Fix sandbox handling for __toString()
Prepare the 3.11.1 release
Fix a security issue when an included sandboxed template has been loaded before without the sandbox context
* 3.11.x:
Improve detection of recursion
Fix recursion when arrays contain self-references in sandboxed mode
Fix code
Prepare the 3.11.2 release
Update CHANGELOG
Sandbox ArrayAccess and do sandbox checks before isset() checks
Fix sandbox handling for __toString()
Prepare the 3.11.1 release
Fix a security issue when an included sandboxed template has been loaded before without the sandbox context
This PR was squashed before being merged into the 3.x branch.
Discussion
----------
Fix mistake in docs for `keys` filter
Commits
-------
deb37c30c4 Fix mistake in docs for `keys` filter
This PR was merged into the 3.x branch.
Discussion
----------
Rename Node classes related to variables
Whenever I work on Twig internals, it's always complicated to reason about variable names, probably because the class names are confusing. This PR is an attempt to find "better" and more explicit names.
This PR does the following renaming:
* `NameExpression` to `Variable\ContextVariable`
Represents the value of a context variable like `$context[VAR] ?? null`
* `AssignNameExpression` to `Variable\AssignContextVariable`
Represents a context variable assignment like in `$context[VAR] = `
* `TempNameExpression` to `Variable\LocalVariable`
Represents a "private" local variable like `$_l111`
Commits
-------
fc15e7ccbc Rename Node classes related to variables
This PR was squashed before being merged into the 3.x branch.
Discussion
----------
Documentation for types tag uses Twig types in examples instead of PHP
Specifically, "bool" => "boolean" and "int" => "number".
This aligns the `types` documentation with templates.rst. See #4362
Thanks, `@alexander`-schranz!
Commits
-------
f3e0a00cf0 Documentation for types tag uses Twig types in examples instead of PHP
This PR was merged into the 3.x branch.
Discussion
----------
Move sandbox docs to its own chapter in the docs
I've also added more information about potential security issues when exposing something that takes a callable as an argument.
Commits
-------
6688a8df16 Move sandbox docs to its own chapter in the docs
This PR was merged into the 3.x branch.
Discussion
----------
Deprecate passing a string or an array to Twig callable arguments accepting arrow functions (pass a Closure)
Instead of restricting callable arguments only in sandbox mode, let's deprecate using functions/arrays as callables.
Commits
-------
5e9448310d Deprecate passing a string or an array to Twig callable arguments accepting arrow functions (pass a Closure)