Files
Twig/src/Util/ReflectionCallable.php
T
Fabien Potencier 19099de78e Merge branch '3.x' into 4.x
* 3.x:
  Skip the sandbox `__toString` check on arguments whose PHP parameter type cannot implicitly coerce to string
  Fix  CS
  Bump version
  Prepare the 3.27.1 release
  Fix inconsistent array access with a Stringable key
  Preserve IteratorAggregate identity in sandbox __toString walker
  Fix tests
  Bump version
  Prepare the 3.27.0 release
  Fix sandbox filter/tag/function allow-list bypass when sandbox state changes between renders
  Document new support for any expression as a dynamic mapping key
  Fix sandbox __toString policy bypass via dynamic mapping keys
  Fix deprecation notices in tests
  Guard sandbox `__toString` walker against self-referencing iterables
  Fix sandbox `__toString` bypass via `Stringable` + `Traversable` containers
  Fix sandbox `__toString` bypass via the `in` and `not in` operators
  Fix sandbox __toString bypass via Traversable in join/replace filters
  Mark new SourcePolicyInterface column filter tests as @group legacy
  Fix sandbox bypass in the "column" filter under SourcePolicyInterface
  Fix sandbox bypass in deprecated internal wrappers

# Conflicts:
#	CHANGELOG
#	src/Environment.php
#	src/Node/Expression/ArrayExpression.php
#	src/Node/Expression/CallExpression.php
#	src/Resources/core.php
#	src/Template.php
#	src/Util/CallableArgumentsExtractor.php
#	src/Util/ReflectionCallable.php
#	tests/Extension/SandboxTest.php
#	tests/Resources/LegacyCoreTest.php
#	tests/TemplateTest.php
2026-06-02 14:05:57 +02:00

125 lines
3.7 KiB
PHP

<?php
/*
* This file is part of Twig.
*
* (c) Fabien Potencier
*
* For the full copyright and license information, please view the LICENSE
* file that was distributed with this source code.
*/
namespace Twig\Util;
use Twig\TwigCallableInterface;
/**
* @author Fabien Potencier <fabien@symfony.com>
*
* @internal
*/
final class ReflectionCallable
{
private \ReflectionFunctionAbstract $reflector;
private \Closure|string|array $callable;
private string $name;
public function __construct(
private TwigCallableInterface $twigCallable,
) {
$callable = $twigCallable->getCallable();
if (\is_string($callable) && false !== $pos = strpos($callable, '::')) {
$callable = [substr($callable, 0, $pos), substr($callable, 2 + $pos)];
}
if (\is_array($callable) && method_exists($callable[0], $callable[1])) {
$this->reflector = $r = new \ReflectionMethod($callable[0], $callable[1]);
$this->callable = $callable;
$this->name = $r->class.'::'.$r->name;
return;
}
$checkVisibility = $callable instanceof \Closure;
try {
$closure = \Closure::fromCallable($callable);
} catch (\TypeError $e) {
throw new \LogicException(\sprintf('Callback for %s "%s" is not callable in the current scope.', $twigCallable->getType(), $twigCallable->getName()), 0, $e);
}
$this->reflector = $r = new \ReflectionFunction($closure);
if (str_contains($r->name, '{closure')) {
$this->callable = $callable;
$this->name = 'Closure';
return;
}
if ($object = $r->getClosureThis()) {
$callable = [$object, $r->name];
$this->name = get_debug_type($object).'::'.$r->name;
} elseif ($class = $r->getClosureCalledClass()) {
$callable = [$class->name, $r->name];
$this->name = $class->name.'::'.$r->name;
} else {
$callable = $this->name = $r->name;
}
if ($checkVisibility && \is_array($callable) && method_exists(...$callable) && !(new \ReflectionMethod(...$callable))->isPublic()) {
$callable = $r->getClosure();
}
$this->callable = $callable;
}
public function getReflector(): \ReflectionFunctionAbstract
{
return $this->reflector;
}
/**
* Returns the PHP parameters that map to the callable's template-level
* arguments.
*
* The parameters Twig injects automatically (the piped input value when
* $stripInput is true, then needs_charset/environment/context/is_sandboxed)
* and the bound arguments are stripped.
*
* @return list<\ReflectionParameter>
*/
public function getTwigParameters(bool $stripInput = false): array
{
$parameters = $this->reflector->getParameters();
if ($stripInput) {
array_shift($parameters);
}
if ($this->twigCallable->needsCharset()) {
array_shift($parameters);
}
if ($this->twigCallable->needsEnvironment()) {
array_shift($parameters);
}
if ($this->twigCallable->needsContext()) {
array_shift($parameters);
}
if ($this->twigCallable->needsIsSandboxed()) {
array_shift($parameters);
}
foreach ($this->twigCallable->getArguments() as $argument) {
array_shift($parameters);
}
return array_values($parameters);
}
public function getCallable(): \Closure|string|array
{
return $this->callable;
}
public function getName(): string
{
return $this->name;
}
}