Files
Twig/tests/Node/Expression/MacroReferenceTest.php
T
Fabien Potencier ea3f7a2844 Validate macro name in MacroReferenceExpression constructor
The name passed to MacroReferenceExpression is emitted as raw PHP in
compile() via "->{$name}(...)". Callers were expected to validate
the name, but a missing check led to CVE-2026-XXXXX (PHP code injection
via _self / import macro reference): defense-in-depth, validate the
name in the constructor so the class is safe by construction.
2026-05-19 23:42:31 +02:00

42 lines
1.2 KiB
PHP

<?php
/*
* This file is part of Twig.
*
* (c) Fabien Potencier
*
* For the full copyright and license information, please view the LICENSE
* file that was distributed with this source code.
*/
namespace Twig\Tests\Node\Expression;
use PHPUnit\Framework\TestCase;
use Twig\Node\Expression\ArrayExpression;
use Twig\Node\Expression\MacroReferenceExpression;
use Twig\Node\Expression\Variable\TemplateVariable;
class MacroReferenceTest extends TestCase
{
/**
* @dataProvider provideInvalidMacroNames
*/
public function testConstructorRejectsNonIdentifierName(string $name)
{
$this->expectException(\LogicException::class);
$this->expectExceptionMessage(\sprintf('Macro name "%s" is not a valid PHP identifier.', $name));
new MacroReferenceExpression(new TemplateVariable('foo', 1), $name, new ArrayExpression([], 1), 1);
}
public static function provideInvalidMacroNames(): iterable
{
yield 'empty' => [''];
yield 'starts with digit' => ['1foo'];
yield 'contains space' => ['foo bar'];
yield 'contains semicolon' => ['foo;bar'];
yield 'PHP injection payload' => ['macro_foo + 1; trigger_error("BAD") //'];
yield 'contains NUL byte' => ["foo\x00bar"];
}
}