From c698474abc9ab004812f78b8adee4d5c16e9f7b1 Mon Sep 17 00:00:00 2001 From: Guilherme Carreiro Date: Wed, 6 May 2026 09:49:30 +0200 Subject: [PATCH] Prevent `SelfDrop` context mutation across render boundaries --- lib/liquid/self_drop.rb | 8 ++-- test/integration/self_drop_test.rb | 71 ++++++++++++++++++++++++++++++ 2 files changed, 75 insertions(+), 4 deletions(-) create mode 100644 test/integration/self_drop_test.rb diff --git a/lib/liquid/self_drop.rb b/lib/liquid/self_drop.rb index 35781465..fa3fa27a 100644 --- a/lib/liquid/self_drop.rb +++ b/lib/liquid/self_drop.rb @@ -16,19 +16,19 @@ module Liquid # then the local value takes precedence over the `self` object. # @liquid_access global class SelfDrop < Drop - def initialize(context) + def initialize(self_context) super() - @context = context + @self_context = self_context end def [](key) - @context.find_variable(key) + @self_context.find_variable(key) rescue UndefinedVariable nil end def key?(key) - @context.variable_defined?(key) + @self_context.variable_defined?(key) end def to_liquid diff --git a/test/integration/self_drop_test.rb b/test/integration/self_drop_test.rb new file mode 100644 index 00000000..39775546 --- /dev/null +++ b/test/integration/self_drop_test.rb @@ -0,0 +1,71 @@ +# frozen_string_literal: true + +require 'test_helper' + +class SelfDropTest < Minitest::Test + include Liquid + + def test_self_drop_passed_as_render_param_preserves_original_scope + source = <<~LIQUID + {%- assign var = 42 -%} + {%- assign s = self -%} + {%- render "snippet1", other_self: s -%} + LIQUID + + partials = { + 'snippet1' => <<~LIQUID, + {%- assign var = 43 -%} + {{- other_self.var }}|{{ self.var -}} + LIQUID + } + + assert_template_result('42|43', source, partials: partials) + end + + def test_self_drop_in_render_without_passing_resolves_inner_scope + source = <<~LIQUID + {%- assign var = 42 -%} + {%- render "snippet1" -%} + LIQUID + + partials = { + 'snippet1' => <<~LIQUID, + {%- assign var = 99 -%} + {{- self.var -}} + LIQUID + } + + assert_template_result('99', source, partials: partials) + end + + def test_self_drop_passed_to_nested_renders_preserves_each_level + source = <<~LIQUID + {%- assign a = 1 -%} + {%- assign s1 = self -%} + {%- render "snippet1", outer: s1 -%} + LIQUID + + partials = { + 'snippet1' => <<~LIQUID, + {%- assign a = 2 -%} + {%- assign s2 = self -%} + {%- render "snippet2", outer: outer, middle: s2 -%} + LIQUID + 'snippet2' => <<~LIQUID, + {%- assign a = 3 -%} + {{- outer.a }}|{{ middle.a }}|{{ self.a -}} + LIQUID + } + + assert_template_result('1|2|3', source, partials: partials) + end + + def test_self_drop_reflects_variables_assigned_after_creation + source = <<~LIQUID + {%- assign s = self -%} + {%- assign x = 42 %}{{ s.x -}} + LIQUID + + assert_template_result('42', source) + end +end