Merge pull request #1216 from Shopify/unsupported-taint-mode

Remove support for taint_mode on ruby versions that don't support it
This commit is contained in:
Dylan Thacker-Smith
2020-01-07 10:12:36 -05:00
committed by GitHub
7 changed files with 60 additions and 42 deletions
-5
View File
@@ -5,17 +5,12 @@ rvm:
- 2.4 - 2.4
- 2.5 - 2.5
- &latest_ruby 2.6 - &latest_ruby 2.6
- 2.7
- ruby-head
matrix: matrix:
include: include:
- rvm: *latest_ruby - rvm: *latest_ruby
script: bundle exec rake memory_profile:run script: bundle exec rake memory_profile:run
name: Profiling Memory Usage name: Profiling Memory Usage
allow_failures:
- rvm: ruby-head
- rvm: 2.7
branches: branches:
only: only:
+8 -1
View File
@@ -69,7 +69,14 @@ module Liquid
# :lax is the default, and ignores the taint flag completely # :lax is the default, and ignores the taint flag completely
# :warn adds a warning, but does not interrupt the rendering # :warn adds a warning, but does not interrupt the rendering
# :error raises an error when tainted output is used # :error raises an error when tainted output is used
attr_writer :taint_mode # @deprecated Since it is being deprecated in ruby itself.
def taint_mode=(mode)
taint_supported = Object.new.taint.tainted?
if mode != :lax && !taint_supported
raise NotImplementedError, "#{RUBY_ENGINE} #{RUBY_VERSION} doesn't support taint checking"
end
@taint_mode = mode
end
attr_accessor :default_exception_renderer attr_accessor :default_exception_renderer
Template.default_exception_renderer = lambda do |exception| Template.default_exception_renderer = lambda do |exception|
+1 -1
View File
@@ -143,8 +143,8 @@ module Liquid
end end
def taint_check(context, obj) def taint_check(context, obj)
return unless obj.tainted?
return if Template.taint_mode == :lax return if Template.taint_mode == :lax
return unless obj.tainted?
@markup =~ QuotedFragment @markup =~ QuotedFragment
name = Regexp.last_match(0) name = Regexp.last_match(0)
+2
View File
@@ -114,6 +114,7 @@ class DropsTest < Minitest::Test
assert_equal(' ', tpl.render!('product' => ProductDrop.new)) assert_equal(' ', tpl.render!('product' => ProductDrop.new))
end end
if taint_supported?
def test_rendering_raises_on_tainted_attr def test_rendering_raises_on_tainted_attr
with_taint_mode(:error) do with_taint_mode(:error) do
tpl = Liquid::Template.parse('{{ product.user_input }}') tpl = Liquid::Template.parse('{{ product.user_input }}')
@@ -139,6 +140,7 @@ class DropsTest < Minitest::Test
tpl.render!('product' => ProductDrop.new) tpl.render!('product' => ProductDrop.new)
end end
end end
end
def test_drop_does_only_respond_to_whitelisted_methods def test_drop_does_only_respond_to_whitelisted_methods
assert_equal("", Liquid::Template.parse("{{ product.inspect }}").render!('product' => ProductDrop.new)) assert_equal("", Liquid::Template.parse("{{ product.inspect }}").render!('product' => ProductDrop.new))
+2
View File
@@ -42,6 +42,7 @@ class RenderTagTest < Minitest::Test
assert_template_result('', "{% assign snippet = 'should not be visible' %}{% render 'snippet' %}") assert_template_result('', "{% assign snippet = 'should not be visible' %}{% render 'snippet' %}")
end end
if taint_supported?
def test_render_sets_the_correct_template_name_for_errors def test_render_sets_the_correct_template_name_for_errors
Liquid::Template.file_system = StubFileSystem.new('snippet' => '{{ unsafe }}') Liquid::Template.file_system = StubFileSystem.new('snippet' => '{{ unsafe }}')
@@ -67,6 +68,7 @@ class RenderTagTest < Minitest::Test
assert_equal 'snippet', context.warnings.first.template_name assert_equal 'snippet', context.warnings.first.template_name
end end
end end
end
def test_render_does_not_mutate_parent_scope def test_render_does_not_mutate_parent_scope
Liquid::Template.file_system = StubFileSystem.new('snippet' => '{% assign inner = 1 %}') Liquid::Template.file_system = StubFileSystem.new('snippet' => '{% assign inner = 1 %}')
+8
View File
@@ -361,4 +361,12 @@ class TemplateTest < Minitest::Test
result = t.render('x' => 1, 'y' => 5) result = t.render('x' => 1, 'y' => 5)
assert_equal('12345', result) assert_equal('12345', result)
end end
unless taint_supported?
def test_taint_mode
assert_raises(NotImplementedError) do
Template.taint_mode = :warn
end
end
end
end end
+4
View File
@@ -32,6 +32,10 @@ module Minitest
def fixture(name) def fixture(name)
File.join(File.expand_path(__dir__), "fixtures", name) File.join(File.expand_path(__dir__), "fixtures", name)
end end
def self.taint_supported?
Object.new.taint.tainted?
end
end end
module Assertions module Assertions