mirror of
https://github.com/twigphp/Twig.git
synced 2026-10-11 14:25:51 +00:00
19099de78e
* 3.x: Skip the sandbox `__toString` check on arguments whose PHP parameter type cannot implicitly coerce to string Fix CS Bump version Prepare the 3.27.1 release Fix inconsistent array access with a Stringable key Preserve IteratorAggregate identity in sandbox __toString walker Fix tests Bump version Prepare the 3.27.0 release Fix sandbox filter/tag/function allow-list bypass when sandbox state changes between renders Document new support for any expression as a dynamic mapping key Fix sandbox __toString policy bypass via dynamic mapping keys Fix deprecation notices in tests Guard sandbox `__toString` walker against self-referencing iterables Fix sandbox `__toString` bypass via `Stringable` + `Traversable` containers Fix sandbox `__toString` bypass via the `in` and `not in` operators Fix sandbox __toString bypass via Traversable in join/replace filters Mark new SourcePolicyInterface column filter tests as @group legacy Fix sandbox bypass in the "column" filter under SourcePolicyInterface Fix sandbox bypass in deprecated internal wrappers # Conflicts: # CHANGELOG # src/Environment.php # src/Node/Expression/ArrayExpression.php # src/Node/Expression/CallExpression.php # src/Resources/core.php # src/Template.php # src/Util/CallableArgumentsExtractor.php # src/Util/ReflectionCallable.php # tests/Extension/SandboxTest.php # tests/Resources/LegacyCoreTest.php # tests/TemplateTest.php
125 lines
3.7 KiB
PHP
125 lines
3.7 KiB
PHP
<?php
|
|
|
|
/*
|
|
* This file is part of Twig.
|
|
*
|
|
* (c) Fabien Potencier
|
|
*
|
|
* For the full copyright and license information, please view the LICENSE
|
|
* file that was distributed with this source code.
|
|
*/
|
|
|
|
namespace Twig\Util;
|
|
|
|
use Twig\TwigCallableInterface;
|
|
|
|
/**
|
|
* @author Fabien Potencier <fabien@symfony.com>
|
|
*
|
|
* @internal
|
|
*/
|
|
final class ReflectionCallable
|
|
{
|
|
private \ReflectionFunctionAbstract $reflector;
|
|
private \Closure|string|array $callable;
|
|
private string $name;
|
|
|
|
public function __construct(
|
|
private TwigCallableInterface $twigCallable,
|
|
) {
|
|
$callable = $twigCallable->getCallable();
|
|
if (\is_string($callable) && false !== $pos = strpos($callable, '::')) {
|
|
$callable = [substr($callable, 0, $pos), substr($callable, 2 + $pos)];
|
|
}
|
|
|
|
if (\is_array($callable) && method_exists($callable[0], $callable[1])) {
|
|
$this->reflector = $r = new \ReflectionMethod($callable[0], $callable[1]);
|
|
$this->callable = $callable;
|
|
$this->name = $r->class.'::'.$r->name;
|
|
|
|
return;
|
|
}
|
|
|
|
$checkVisibility = $callable instanceof \Closure;
|
|
try {
|
|
$closure = \Closure::fromCallable($callable);
|
|
} catch (\TypeError $e) {
|
|
throw new \LogicException(\sprintf('Callback for %s "%s" is not callable in the current scope.', $twigCallable->getType(), $twigCallable->getName()), 0, $e);
|
|
}
|
|
$this->reflector = $r = new \ReflectionFunction($closure);
|
|
|
|
if (str_contains($r->name, '{closure')) {
|
|
$this->callable = $callable;
|
|
$this->name = 'Closure';
|
|
|
|
return;
|
|
}
|
|
|
|
if ($object = $r->getClosureThis()) {
|
|
$callable = [$object, $r->name];
|
|
$this->name = get_debug_type($object).'::'.$r->name;
|
|
} elseif ($class = $r->getClosureCalledClass()) {
|
|
$callable = [$class->name, $r->name];
|
|
$this->name = $class->name.'::'.$r->name;
|
|
} else {
|
|
$callable = $this->name = $r->name;
|
|
}
|
|
|
|
if ($checkVisibility && \is_array($callable) && method_exists(...$callable) && !(new \ReflectionMethod(...$callable))->isPublic()) {
|
|
$callable = $r->getClosure();
|
|
}
|
|
|
|
$this->callable = $callable;
|
|
}
|
|
|
|
public function getReflector(): \ReflectionFunctionAbstract
|
|
{
|
|
return $this->reflector;
|
|
}
|
|
|
|
/**
|
|
* Returns the PHP parameters that map to the callable's template-level
|
|
* arguments.
|
|
*
|
|
* The parameters Twig injects automatically (the piped input value when
|
|
* $stripInput is true, then needs_charset/environment/context/is_sandboxed)
|
|
* and the bound arguments are stripped.
|
|
*
|
|
* @return list<\ReflectionParameter>
|
|
*/
|
|
public function getTwigParameters(bool $stripInput = false): array
|
|
{
|
|
$parameters = $this->reflector->getParameters();
|
|
if ($stripInput) {
|
|
array_shift($parameters);
|
|
}
|
|
if ($this->twigCallable->needsCharset()) {
|
|
array_shift($parameters);
|
|
}
|
|
if ($this->twigCallable->needsEnvironment()) {
|
|
array_shift($parameters);
|
|
}
|
|
if ($this->twigCallable->needsContext()) {
|
|
array_shift($parameters);
|
|
}
|
|
if ($this->twigCallable->needsIsSandboxed()) {
|
|
array_shift($parameters);
|
|
}
|
|
foreach ($this->twigCallable->getArguments() as $argument) {
|
|
array_shift($parameters);
|
|
}
|
|
|
|
return array_values($parameters);
|
|
}
|
|
|
|
public function getCallable(): \Closure|string|array
|
|
{
|
|
return $this->callable;
|
|
}
|
|
|
|
public function getName(): string
|
|
{
|
|
return $this->name;
|
|
}
|
|
}
|