don't parse nodes inside a comment tag

Co-authored-by Alex Coco <[email protected]>
This commit is contained in:
Michael Go
2023-11-07 17:52:10 -04:00
parent 0b9318222b
commit 9123859a2a
2 changed files with 135 additions and 0 deletions
+53
View File
@@ -25,6 +25,59 @@ module Liquid
def blank?
true
end
private
def parse_body(body, tokens)
if parse_context.depth >= MAX_DEPTH
raise StackLevelError, "Nesting too deep"
end
parse_context.depth += 1
comment_tag_depth = 1
begin
# Consume tokens without creating child nodes.
# The children tag doesn't require to be a valid Liquid except the comment and raw tag.
# The child comment and raw tag must be closed.
while token = tokens.send(:shift)
tag_name_match = BlockBody::FullToken.match(token)
next if tag_name_match.nil?
tag_name = tag_name_match[2]
if tag_name == "raw"
# raw tags are required to be closed
raw_tag_closed = false
while token = tokens.send(:shift)
if token =~ Raw::FullTokenPossiblyInvalid && "endraw" == Regexp.last_match(2)
raw_tag_closed = true
break
end
end
raise_tag_never_closed("raw") unless raw_tag_closed
next
end
if tag_name_match[2] == "comment"
comment_tag_depth += 1
next
elsif tag_name_match[2] == "endcomment"
comment_tag_depth -= 1
return false if comment_tag_depth.zero?
end
end
raise_tag_never_closed(block_name)
ensure
parse_context.depth -= 1
end
false
end
end
Template.register_tag('comment', Comment)
+82
View File
@@ -0,0 +1,82 @@
# frozen_string_literal: true
require 'test_helper'
class CommentTagUnitTest < Minitest::Test
def test_does_not_parse_nodes_inside_a_comment
template = Template.parse(<<~LIQUID.chomp, line_numbers: true)
{% comment %}
{% if true %}
{% if ... %}
{%- for ? -%}
{% while true %}
{%
unless if
%}
{% endcase %}
{% endcomment %}
LIQUID
assert_equal("", template.render)
end
def test_child_comment_tags_need_to_be_closed
template = Template.parse(<<~LIQUID.chomp, line_numbers: true)
{% comment %}
{% comment %}
{% comment %}{% endcomment %}
{% endcomment %}
{% endcomment %}
LIQUID
assert_equal("", template.render)
assert_raises(SyntaxError) do
Template.parse(<<~LIQUID.chomp, line_numbers: true)
{% comment %}
{% comment %}
{% comment %}
{% endcomment %}
{% endcomment %}
LIQUID
end
end
def test_child_raw_tags_need_to_be_closed
template = Template.parse(<<~LIQUID.chomp, line_numbers: true)
{% comment %}
{% raw %}
{% endcomment %}
{% endraw %}
{% endcomment %}
LIQUID
assert_equal("", template.render)
assert_raises(SyntaxError) do
Template.parse(<<~LIQUID.chomp, line_numbers: true)
{% comment %}
{% raw %}
{% endcomment %}
{% endcomment %}
LIQUID
end
end
def test_error_line_number_is_correct
template = Template.parse(<<~LIQUID.chomp, line_numbers: true)
{% comment %}
{% if true %}
{% endcomment %}
{{ errors.standard_error }}
LIQUID
output = template.render('errors' => ErrorDrop.new)
expected = <<~TEXT.chomp
Liquid error (line 4): standard error
TEXT
assert_equal(expected, output)
end
end