mirror of
https://github.com/Shopify/liquid.git
synced 2026-10-03 00:55:11 -07:00
Remove use of ruby taint API for ruby 3.2 compatibility
This commit is contained in:
@@ -39,7 +39,7 @@ module Liquid
|
|||||||
end
|
end
|
||||||
|
|
||||||
def escape(input)
|
def escape(input)
|
||||||
CGI.escapeHTML(input.to_s).untaint unless input.nil?
|
CGI.escapeHTML(input.to_s) unless input.nil?
|
||||||
end
|
end
|
||||||
alias_method :h, :escape
|
alias_method :h, :escape
|
||||||
|
|
||||||
|
|||||||
@@ -63,10 +63,7 @@ module Liquid
|
|||||||
# :strict will enforce correct syntax.
|
# :strict will enforce correct syntax.
|
||||||
attr_writer :error_mode
|
attr_writer :error_mode
|
||||||
|
|
||||||
# Sets how strict the taint checker should be.
|
# Deprecated. No longer used. Removed in version 5
|
||||||
# :lax is the default, and ignores the taint flag completely
|
|
||||||
# :warn adds a warning, but does not interrupt the rendering
|
|
||||||
# :error raises an error when tainted output is used
|
|
||||||
attr_writer :taint_mode
|
attr_writer :taint_mode
|
||||||
|
|
||||||
attr_accessor :default_exception_renderer
|
attr_accessor :default_exception_renderer
|
||||||
@@ -94,6 +91,7 @@ module Liquid
|
|||||||
@error_mode ||= :lax
|
@error_mode ||= :lax
|
||||||
end
|
end
|
||||||
|
|
||||||
|
# Deprecated. Removed in version 5
|
||||||
def taint_mode
|
def taint_mode
|
||||||
@taint_mode ||= :lax
|
@taint_mode ||= :lax
|
||||||
end
|
end
|
||||||
|
|||||||
+1
-24
@@ -84,11 +84,7 @@ module Liquid
|
|||||||
context.invoke(filter_name, output, *filter_args)
|
context.invoke(filter_name, output, *filter_args)
|
||||||
end
|
end
|
||||||
|
|
||||||
obj = context.apply_global_filter(obj)
|
context.apply_global_filter(obj)
|
||||||
|
|
||||||
taint_check(context, obj)
|
|
||||||
|
|
||||||
obj
|
|
||||||
end
|
end
|
||||||
|
|
||||||
private
|
private
|
||||||
@@ -120,25 +116,6 @@ module Liquid
|
|||||||
parsed_args
|
parsed_args
|
||||||
end
|
end
|
||||||
|
|
||||||
def taint_check(context, obj)
|
|
||||||
return unless obj.tainted?
|
|
||||||
return if Template.taint_mode == :lax
|
|
||||||
|
|
||||||
@markup =~ QuotedFragment
|
|
||||||
name = Regexp.last_match(0)
|
|
||||||
|
|
||||||
error = TaintedError.new("variable '#{name}' is tainted and was not escaped")
|
|
||||||
error.line_number = line_number
|
|
||||||
error.template_name = context.template_name
|
|
||||||
|
|
||||||
case Template.taint_mode
|
|
||||||
when :warn
|
|
||||||
context.warnings << error
|
|
||||||
when :error
|
|
||||||
raise error
|
|
||||||
end
|
|
||||||
end
|
|
||||||
|
|
||||||
class ParseTreeVisitor < Liquid::ParseTreeVisitor
|
class ParseTreeVisitor < Liquid::ParseTreeVisitor
|
||||||
def children
|
def children
|
||||||
[@node.name] + @node.filters.flatten
|
[@node.name] + @node.filters.flatten
|
||||||
|
|||||||
@@ -48,7 +48,7 @@ class ProductDrop < Liquid::Drop
|
|||||||
end
|
end
|
||||||
|
|
||||||
def user_input
|
def user_input
|
||||||
"foo".taint
|
"foo"
|
||||||
end
|
end
|
||||||
|
|
||||||
protected
|
protected
|
||||||
@@ -112,32 +112,6 @@ class DropsTest < Minitest::Test
|
|||||||
assert_equal ' ', tpl.render!('product' => ProductDrop.new)
|
assert_equal ' ', tpl.render!('product' => ProductDrop.new)
|
||||||
end
|
end
|
||||||
|
|
||||||
def test_rendering_raises_on_tainted_attr
|
|
||||||
with_taint_mode(:error) do
|
|
||||||
tpl = Liquid::Template.parse('{{ product.user_input }}')
|
|
||||||
assert_raises TaintedError do
|
|
||||||
tpl.render!('product' => ProductDrop.new)
|
|
||||||
end
|
|
||||||
end
|
|
||||||
end
|
|
||||||
|
|
||||||
def test_rendering_warns_on_tainted_attr
|
|
||||||
with_taint_mode(:warn) do
|
|
||||||
tpl = Liquid::Template.parse('{{ product.user_input }}')
|
|
||||||
context = Context.new('product' => ProductDrop.new)
|
|
||||||
tpl.render!(context)
|
|
||||||
assert_equal [Liquid::TaintedError], context.warnings.map(&:class)
|
|
||||||
assert_equal "variable 'product.user_input' is tainted and was not escaped", context.warnings.first.to_s(false)
|
|
||||||
end
|
|
||||||
end
|
|
||||||
|
|
||||||
def test_rendering_doesnt_raise_on_escaped_tainted_attr
|
|
||||||
with_taint_mode(:error) do
|
|
||||||
tpl = Liquid::Template.parse('{{ product.user_input | escape }}')
|
|
||||||
tpl.render!('product' => ProductDrop.new)
|
|
||||||
end
|
|
||||||
end
|
|
||||||
|
|
||||||
def test_drop_does_only_respond_to_whitelisted_methods
|
def test_drop_does_only_respond_to_whitelisted_methods
|
||||||
assert_equal "", Liquid::Template.parse("{{ product.inspect }}").render!('product' => ProductDrop.new)
|
assert_equal "", Liquid::Template.parse("{{ product.inspect }}").render!('product' => ProductDrop.new)
|
||||||
assert_equal "", Liquid::Template.parse("{{ product.pretty_inspect }}").render!('product' => ProductDrop.new)
|
assert_equal "", Liquid::Template.parse("{{ product.pretty_inspect }}").render!('product' => ProductDrop.new)
|
||||||
|
|||||||
@@ -69,14 +69,6 @@ module Minitest
|
|||||||
Liquid::Strainer.class_variable_set(:@@global_strainer, original_global_strainer)
|
Liquid::Strainer.class_variable_set(:@@global_strainer, original_global_strainer)
|
||||||
end
|
end
|
||||||
|
|
||||||
def with_taint_mode(mode)
|
|
||||||
old_mode = Liquid::Template.taint_mode
|
|
||||||
Liquid::Template.taint_mode = mode
|
|
||||||
yield
|
|
||||||
ensure
|
|
||||||
Liquid::Template.taint_mode = old_mode
|
|
||||||
end
|
|
||||||
|
|
||||||
def with_error_mode(mode)
|
def with_error_mode(mode)
|
||||||
old_mode = Liquid::Template.error_mode
|
old_mode = Liquid::Template.error_mode
|
||||||
Liquid::Template.error_mode = mode
|
Liquid::Template.error_mode = mode
|
||||||
|
|||||||
Reference in New Issue
Block a user