change: Render an opaque internal error by default for non-Liquid::Error (#835)

These errors may contain sensitive information, so is safer to
render a more vague message by default.

This is done by replacing non-Liquid::Error exceptions with a
Liquid::InternalError exception with the non-Liquid::Error accessible on
through the cause method. This also allows the template name and line
number to be attached to the template errors.

The exception_handler render option has been changed to exception_renderer
since now it should raise an exception to re-raise on a liquid rendering
error or return a string to be rendered where the error occurred.
This commit is contained in:
Dylan Thacker-Smith
2016-12-07 17:34:29 -05:00
committed by GitHub
parent a9b84b7806
commit f27bd619b9
6 changed files with 45 additions and 55 deletions
+1 -8
View File
@@ -17,14 +17,6 @@ module Liquid
str
end
def self.render(e)
if e.is_a?(Liquid::Error)
e.to_s
else
"Liquid error: #{e}"
end
end
private
def message_prefix
@@ -60,4 +52,5 @@ module Liquid
UndefinedDropMethod = Class.new(Error)
UndefinedFilter = Class.new(Error)
MethodOverrideError = Class.new(Error)
InternalError = Class.new(Error)
end