mirror of
https://github.com/Shopify/liquid.git
synced 2026-10-03 09:05:13 -07:00
Address code review comments
- clean up comment wording - fix potentially leaky tests
This commit is contained in:
@@ -61,7 +61,7 @@ module Liquid
|
|||||||
attr_writer :error_mode
|
attr_writer :error_mode
|
||||||
|
|
||||||
# Sets how strict the taint checker should be.
|
# Sets how strict the taint checker should be.
|
||||||
# :lax ignores the taint flag completely (like previous liquid versions)
|
# :lax is the default, and ignores the taint flag completely
|
||||||
# :warn adds a warning, but does not interrupt the rendering
|
# :warn adds a warning, but does not interrupt the rendering
|
||||||
# :error raises an error when tainted output is used
|
# :error raises an error when tainted output is used
|
||||||
attr_writer :taint_mode
|
attr_writer :taint_mode
|
||||||
|
|||||||
@@ -113,27 +113,27 @@ class DropsTest < Minitest::Test
|
|||||||
end
|
end
|
||||||
|
|
||||||
def test_rendering_raises_on_tainted_attr
|
def test_rendering_raises_on_tainted_attr
|
||||||
Liquid::Template.taint_mode = :error
|
with_taint_mode(:error) do
|
||||||
tpl = Liquid::Template.parse('{{ product.user_input }}')
|
tpl = Liquid::Template.parse('{{ product.user_input }}')
|
||||||
assert_raises TaintedError do
|
assert_raises TaintedError do
|
||||||
tpl.render!('product' => ProductDrop.new)
|
tpl.render!('product' => ProductDrop.new)
|
||||||
|
end
|
||||||
end
|
end
|
||||||
Liquid::Template.taint_mode = :lax
|
|
||||||
end
|
end
|
||||||
|
|
||||||
def test_rendering_warns_on_tainted_attr
|
def test_rendering_warns_on_tainted_attr
|
||||||
Liquid::Template.taint_mode = :warn
|
with_taint_mode(:warn) do
|
||||||
tpl = Liquid::Template.parse('{{ product.user_input }}')
|
tpl = Liquid::Template.parse('{{ product.user_input }}')
|
||||||
tpl.render!('product' => ProductDrop.new)
|
tpl.render!('product' => ProductDrop.new)
|
||||||
assert_match /tainted/, tpl.warnings.first
|
assert_match /tainted/, tpl.warnings.first
|
||||||
Liquid::Template.taint_mode = :lax
|
end
|
||||||
end
|
end
|
||||||
|
|
||||||
def test_rendering_doesnt_raise_on_escaped_tainted_attr
|
def test_rendering_doesnt_raise_on_escaped_tainted_attr
|
||||||
Liquid::Template.taint_mode = :error
|
with_taint_mode(:error) do
|
||||||
tpl = Liquid::Template.parse('{{ product.user_input | escape }}')
|
tpl = Liquid::Template.parse('{{ product.user_input | escape }}')
|
||||||
tpl.render!('product' => ProductDrop.new)
|
tpl.render!('product' => ProductDrop.new)
|
||||||
Liquid::Template.taint_mode = :lax
|
end
|
||||||
end
|
end
|
||||||
|
|
||||||
def test_drop_does_only_respond_to_whitelisted_methods
|
def test_drop_does_only_respond_to_whitelisted_methods
|
||||||
|
|||||||
@@ -57,6 +57,14 @@ module Minitest
|
|||||||
Liquid::Strainer.class_variable_set(:@@filters, original_filters)
|
Liquid::Strainer.class_variable_set(:@@filters, original_filters)
|
||||||
end
|
end
|
||||||
|
|
||||||
|
def with_taint_mode(mode)
|
||||||
|
old_mode = Liquid::Template.taint_mode
|
||||||
|
Liquid::Template.taint_mode = mode
|
||||||
|
yield
|
||||||
|
ensure
|
||||||
|
Liquid::Template.taint_mode = old_mode
|
||||||
|
end
|
||||||
|
|
||||||
def with_error_mode(mode)
|
def with_error_mode(mode)
|
||||||
old_mode = Liquid::Template.error_mode
|
old_mode = Liquid::Template.error_mode
|
||||||
Liquid::Template.error_mode = mode
|
Liquid::Template.error_mode = mode
|
||||||
|
|||||||
Reference in New Issue
Block a user