Remove use of ruby taint API for ruby 3.2 compatibility

This commit is contained in:
Dylan Thacker-Smith
2023-01-10 13:11:18 -05:00
parent f2f467bdbc
commit 01d52d72d9
5 changed files with 5 additions and 64 deletions
+1 -1
View File
@@ -39,7 +39,7 @@ module Liquid
end end
def escape(input) def escape(input)
CGI.escapeHTML(input.to_s).untaint unless input.nil? CGI.escapeHTML(input.to_s) unless input.nil?
end end
alias_method :h, :escape alias_method :h, :escape
+2 -4
View File
@@ -63,10 +63,7 @@ module Liquid
# :strict will enforce correct syntax. # :strict will enforce correct syntax.
attr_writer :error_mode attr_writer :error_mode
# Sets how strict the taint checker should be. # Deprecated. No longer used. Removed in version 5
# :lax is the default, and ignores the taint flag completely
# :warn adds a warning, but does not interrupt the rendering
# :error raises an error when tainted output is used
attr_writer :taint_mode attr_writer :taint_mode
attr_accessor :default_exception_renderer attr_accessor :default_exception_renderer
@@ -94,6 +91,7 @@ module Liquid
@error_mode ||= :lax @error_mode ||= :lax
end end
# Deprecated. Removed in version 5
def taint_mode def taint_mode
@taint_mode ||= :lax @taint_mode ||= :lax
end end
+1 -24
View File
@@ -84,11 +84,7 @@ module Liquid
context.invoke(filter_name, output, *filter_args) context.invoke(filter_name, output, *filter_args)
end end
obj = context.apply_global_filter(obj) context.apply_global_filter(obj)
taint_check(context, obj)
obj
end end
private private
@@ -120,25 +116,6 @@ module Liquid
parsed_args parsed_args
end end
def taint_check(context, obj)
return unless obj.tainted?
return if Template.taint_mode == :lax
@markup =~ QuotedFragment
name = Regexp.last_match(0)
error = TaintedError.new("variable '#{name}' is tainted and was not escaped")
error.line_number = line_number
error.template_name = context.template_name
case Template.taint_mode
when :warn
context.warnings << error
when :error
raise error
end
end
class ParseTreeVisitor < Liquid::ParseTreeVisitor class ParseTreeVisitor < Liquid::ParseTreeVisitor
def children def children
[@node.name] + @node.filters.flatten [@node.name] + @node.filters.flatten
+1 -27
View File
@@ -48,7 +48,7 @@ class ProductDrop < Liquid::Drop
end end
def user_input def user_input
"foo".taint "foo"
end end
protected protected
@@ -112,32 +112,6 @@ class DropsTest < Minitest::Test
assert_equal ' ', tpl.render!('product' => ProductDrop.new) assert_equal ' ', tpl.render!('product' => ProductDrop.new)
end end
def test_rendering_raises_on_tainted_attr
with_taint_mode(:error) do
tpl = Liquid::Template.parse('{{ product.user_input }}')
assert_raises TaintedError do
tpl.render!('product' => ProductDrop.new)
end
end
end
def test_rendering_warns_on_tainted_attr
with_taint_mode(:warn) do
tpl = Liquid::Template.parse('{{ product.user_input }}')
context = Context.new('product' => ProductDrop.new)
tpl.render!(context)
assert_equal [Liquid::TaintedError], context.warnings.map(&:class)
assert_equal "variable 'product.user_input' is tainted and was not escaped", context.warnings.first.to_s(false)
end
end
def test_rendering_doesnt_raise_on_escaped_tainted_attr
with_taint_mode(:error) do
tpl = Liquid::Template.parse('{{ product.user_input | escape }}')
tpl.render!('product' => ProductDrop.new)
end
end
def test_drop_does_only_respond_to_whitelisted_methods def test_drop_does_only_respond_to_whitelisted_methods
assert_equal "", Liquid::Template.parse("{{ product.inspect }}").render!('product' => ProductDrop.new) assert_equal "", Liquid::Template.parse("{{ product.inspect }}").render!('product' => ProductDrop.new)
assert_equal "", Liquid::Template.parse("{{ product.pretty_inspect }}").render!('product' => ProductDrop.new) assert_equal "", Liquid::Template.parse("{{ product.pretty_inspect }}").render!('product' => ProductDrop.new)
-8
View File
@@ -69,14 +69,6 @@ module Minitest
Liquid::Strainer.class_variable_set(:@@global_strainer, original_global_strainer) Liquid::Strainer.class_variable_set(:@@global_strainer, original_global_strainer)
end end
def with_taint_mode(mode)
old_mode = Liquid::Template.taint_mode
Liquid::Template.taint_mode = mode
yield
ensure
Liquid::Template.taint_mode = old_mode
end
def with_error_mode(mode) def with_error_mode(mode)
old_mode = Liquid::Template.error_mode old_mode = Liquid::Template.error_mode
Liquid::Template.error_mode = mode Liquid::Template.error_mode = mode