Remove support for taint_mode on ruby versions that don't support it

This commit is contained in:
Dylan Thacker-Smith
2019-12-19 11:12:51 -05:00
parent 6c6382ed69
commit 40c68c9c83
6 changed files with 60 additions and 37 deletions
+8 -1
View File
@@ -69,7 +69,14 @@ module Liquid
# :lax is the default, and ignores the taint flag completely # :lax is the default, and ignores the taint flag completely
# :warn adds a warning, but does not interrupt the rendering # :warn adds a warning, but does not interrupt the rendering
# :error raises an error when tainted output is used # :error raises an error when tainted output is used
attr_writer :taint_mode # @deprecated Since it is being deprecated in ruby itself.
def taint_mode=(mode)
taint_supported = Object.new.taint.tainted?
if mode != :lax && !taint_supported
raise NotImplementedError, "#{RUBY_ENGINE} #{RUBY_VERSION} doesn't support taint checking"
end
@taint_mode = mode
end
attr_accessor :default_exception_renderer attr_accessor :default_exception_renderer
Template.default_exception_renderer = lambda do |exception| Template.default_exception_renderer = lambda do |exception|
+1 -1
View File
@@ -143,8 +143,8 @@ module Liquid
end end
def taint_check(context, obj) def taint_check(context, obj)
return unless obj.tainted?
return if Template.taint_mode == :lax return if Template.taint_mode == :lax
return unless obj.tainted?
@markup =~ QuotedFragment @markup =~ QuotedFragment
name = Regexp.last_match(0) name = Regexp.last_match(0)
+2
View File
@@ -114,6 +114,7 @@ class DropsTest < Minitest::Test
assert_equal(' ', tpl.render!('product' => ProductDrop.new)) assert_equal(' ', tpl.render!('product' => ProductDrop.new))
end end
if taint_supported?
def test_rendering_raises_on_tainted_attr def test_rendering_raises_on_tainted_attr
with_taint_mode(:error) do with_taint_mode(:error) do
tpl = Liquid::Template.parse('{{ product.user_input }}') tpl = Liquid::Template.parse('{{ product.user_input }}')
@@ -139,6 +140,7 @@ class DropsTest < Minitest::Test
tpl.render!('product' => ProductDrop.new) tpl.render!('product' => ProductDrop.new)
end end
end end
end
def test_drop_does_only_respond_to_whitelisted_methods def test_drop_does_only_respond_to_whitelisted_methods
assert_equal("", Liquid::Template.parse("{{ product.inspect }}").render!('product' => ProductDrop.new)) assert_equal("", Liquid::Template.parse("{{ product.inspect }}").render!('product' => ProductDrop.new))
+2
View File
@@ -42,6 +42,7 @@ class RenderTagTest < Minitest::Test
assert_template_result('', "{% assign snippet = 'should not be visible' %}{% render 'snippet' %}") assert_template_result('', "{% assign snippet = 'should not be visible' %}{% render 'snippet' %}")
end end
if taint_supported?
def test_render_sets_the_correct_template_name_for_errors def test_render_sets_the_correct_template_name_for_errors
Liquid::Template.file_system = StubFileSystem.new('snippet' => '{{ unsafe }}') Liquid::Template.file_system = StubFileSystem.new('snippet' => '{{ unsafe }}')
@@ -67,6 +68,7 @@ class RenderTagTest < Minitest::Test
assert_equal 'snippet', context.warnings.first.template_name assert_equal 'snippet', context.warnings.first.template_name
end end
end end
end
def test_render_does_not_mutate_parent_scope def test_render_does_not_mutate_parent_scope
Liquid::Template.file_system = StubFileSystem.new('snippet' => '{% assign inner = 1 %}') Liquid::Template.file_system = StubFileSystem.new('snippet' => '{% assign inner = 1 %}')
+8
View File
@@ -361,4 +361,12 @@ class TemplateTest < Minitest::Test
result = t.render('x' => 1, 'y' => 5) result = t.render('x' => 1, 'y' => 5)
assert_equal('12345', result) assert_equal('12345', result)
end end
unless taint_supported?
def test_taint_mode
assert_raises(NotImplementedError) do
Template.taint_mode = :warn
end
end
end
end end
+4
View File
@@ -32,6 +32,10 @@ module Minitest
def fixture(name) def fixture(name)
File.join(File.expand_path(__dir__), "fixtures", name) File.join(File.expand_path(__dir__), "fixtures", name)
end end
def self.taint_supported?
Object.new.taint.tainted?
end
end end
module Assertions module Assertions