Timmy Braun and GitHub
1cdf10b57d
fix: rounding negative away from zero when half ( #873 )
2026-04-08 00:52:35 +08:00
Timmy Braun and GitHub
4f9a49988a
fix: null date should return empty ( #868 ) ( #872 )
2026-04-08 00:10:33 +08:00
Yang Jun and GitHub
f41c1fc02f
fix: enforce root containment for renderFile/parseFile lookups ( #870 )
...
Made-with: Cursor
2026-04-07 23:18:53 +08:00
Yang Jun and GitHub
e743da0020
fix: sort and sort_natural filters bypass ownPropertyOnly ( #869 )
...
Use _getFromScope for property access in sort/sort_natural filters to respect the ownPropertyOnly security option, preventing prototype chain traversal that could leak sensitive inherited properties.
Also extract shared sortBy helper, add orderedCompare with nil handling consistent with caseInsensitiveCompare and Ruby Liquid.
Made-with: Cursor
2026-04-07 21:01:20 +08:00
Yang Jun and GitHub
529dd67eeb
fix: use realpath for fs.contains ( #867 )
...
* fix: use realpath for fs.contains
* chore: reset file mode changes
Made-with: Cursor
* fix: Windows compat for contains/containsSync and toLiquidAsync arg order
Made-with: Cursor
2026-04-06 14:40:35 +08:00
Harttle
abc058be0f
fix: precise memoryLimit for string replace
2026-03-26 19:36:31 +08:00
Joe Cottam and GitHub
0ad2b11ab1
fix: handle undefined replacement argument in replace filter ( #864 )
2026-03-26 01:18:40 +08:00
Harttle
35d5230263
fix: treat args for replace_first as literal
2026-03-22 22:16:45 +08:00
Harttle
94440a0653
chore: more strict mem limit for string filters
2026-03-22 22:10:39 +08:00
Yang Jun and Harttle
95ddefc056
fix: mem limiter for invalid ranges
2026-03-22 10:24:03 +08:00
3cd024d652
fix: path traversal vulnerability, #851 ( #855 )
...
* Fix Path Traversal fallback
* Update loader.ts
Fixed nested
* Update loader.ts
padding fix
* refactor: reuse root enforcing
* docs: update test case and docs
---------
Co-authored-by: MorielHarush <[email protected] >
2026-03-08 02:36:09 +08:00
Yang Jun and GitHub
71aa1b1998
feat: export error types, resolving #837 ( #840 )
2025-11-22 00:27:44 +08:00
Loo Rong Jie and GitHub
955b7971c0
Support having new line and other whitespace after include filename ( #834 )
2025-11-11 13:58:12 +08:00
Omri Rosner and GitHub
86fc135d9e
feat(filters): Add base64_encode and base64_decode filters for Shopify compatibility ( #828 )
...
* feat(filters): add base64 encode and decode
* fix: use Object.defineProperty for cross-platform btoa/atob mocking
* docs(filters): update docs
* docs(filters): update version
2025-10-27 22:40:31 +08:00
Ihor Panasiuk and GitHub
4f7d2fd84a
feat: Export specific tokens as types ( #824 )
...
* Export specific tokens as types
* Update index.ts
2025-10-23 21:37:20 +08:00
Yang Jun and GitHub
e55128850e
feat: allow context access in liquidMethodMissing, #808 ( #820 )
2025-10-06 18:34:08 +08:00
Yang Jun and GitHub
e8e502c585
fix: math filters coerce invalid string to 0, #813 ( #819 )
2025-10-06 18:31:43 +08:00
Yang Jun and GitHub
025c40f0f2
fix: block.super with strictVariables, #806 ( #807 )
2025-05-15 01:47:57 +08:00
Bruno Carvalho and GitHub
0deb93eeae
feat: add find_index, has, and reject filters ( #799 )
...
* feat: add find_index, has, and reject filters
* Minor tweaks
* Change semantics of jekyllStyle, add more tests
* Some docs improvements
2025-02-23 22:57:17 +08:00
Harttle and Yang Jun
38a0f510b0
fix: empty tagToken.args since 10.20.0, fixes #796
2025-02-09 22:49:40 +08:00
Harttle and Jun Yang
a490a70da1
fix: consistent range syntax parsing, #791
2025-01-19 17:58:00 +08:00
Harttle and Jun Yang
a5070af3e4
fix: context for group_by_exp/where_exp/find_exp, #790
2025-01-19 17:53:25 +08:00
Jun Yang and GitHub
25ef104446
fix: enumerate plain objects in where/where_exp, #785 ( #788 )
2025-01-04 23:41:25 +08:00
Harttle and Jun Yang
59cf3c08db
fix: preserveTimezones support for RFC2822 date, #784
2025-01-04 22:46:07 +08:00
Harttle and Jun Yang
5f1a4cfdc9
fix: break/continue stops whole template, #783
2025-01-04 22:15:39 +08:00
James and GitHub
3492ff63f4
feat: static variable analysis ( #770 )
...
* feat: static variable analysis
* Accept any iterable from `children`, `arguments`, etc.
* Test analysis of standard tags
* Use `TagToken.tokenizer` instead of creating a new one
* Test analysis of netsted tags
* Group variables by their root value
* Test analysis of nested globals and locals
* Analyze included and rendered templates WIP
* Use existing tokenizer when constructing `Hash`
* Improve test coverage
* Analyze variables from `layout` and `block` tags
* Test analysis of Jekyll style includes
* Handle variables that start with a nested variable
* Async analysis
* Test non-standard tag end to end
* Implement convenience analysis methods on the `Liquid` class
* More analysis convenience methods
* Accept string or template array
* Draft static analysis docs
* Deduplicate variables names
* Fix isolated scope global variable map
* Coerce variables to strings instead of extending String
* Private map instead of extending Map
* Fix e2e test
* Tentatively implement analysis of aliased variables
* Fix nested variable segments array
* Update docs sidebar
2024-12-28 21:35:28 +08:00
Harttle and Jun Yang
35a84421a6
feat: size, first, last support arraylike objects, #781
2024-12-28 16:10:06 +08:00
Harttle and Jun Yang
e3ef574674
fix: inconsistent continue behaviour, fixes #779
2024-12-22 16:32:08 +08:00
Harttle
2af297f81a
fix: memoryLimit doesn't work in for tag, #776
2024-12-22 15:46:56 +08:00
Harttle and Jun Yang
9107eb1b93
feat: support Jekyll style where, #768
2024-11-17 21:33:38 +08:00
Santi Albo and GitHub
11f013bf24
feat: allow drops in property access ( #769 )
2024-11-17 20:24:45 +08:00
Yang Jun
d705888c8d
feat: expose FilterToken to filter this, #762
2024-10-16 22:07:25 +08:00
Yang Jun and Jun Yang
6aeed2586a
feat: support custom key-value separator, #752
2024-09-22 21:55:44 +08:00
Yang Jun
e5fbdfe434
fix: use cwd to resolve npm partials for Node.JS
2024-08-30 01:08:39 +08:00
Yang Jun
86f6bf0d31
fix: expose originalError from LiquidError, #742
2024-08-29 11:37:56 +08:00
Yang Jun
ce84cd6f43
fix: ESM bundle for Node.js, #739
2024-08-28 00:31:59 +08:00
Yang Jun
68387c31ea
fix: "filter is not a function" for uniq
2024-08-23 21:27:53 +08:00
Yang Jun
2d59cff0a6
fix: memory limit issue for join filter, fix #737
2024-08-23 21:27:53 +08:00
Yang Jun
4548c11406
fix: support for NodeJS 15, fixes #732
2024-08-16 23:40:48 +08:00
Jun Yang and GitHub
c6a6ef1a1f
chore: check node@14 on pipeline, #728 ( #731 )
2024-08-16 00:55:14 +08:00
Koen and GitHub
f03247d420
Import performance object from perf_hooks ( #729 )
2024-08-15 22:37:46 +08:00
Yang Jun
21a822348f
fix: parser throws on non-string input, #726
2024-07-25 20:06:12 +08:00
Jun Yang and GitHub
e4aeb023fd
feat: locale support for date filter, #567 ( #723 )
2024-07-22 00:39:44 +08:00
Yang Jun
e443068cb9
feat: DoS prevention, #250
2024-07-09 22:51:11 +08:00
Yang Jun
fad00aa14e
test: edge cases for map fs
2024-07-09 22:51:11 +08:00
Harttle
df27ac6947
feat: support in-memory template mapping, inspired by @jg-rp #714
2024-07-08 02:25:25 +08:00
Harttle
22b5a12333
fix: report error for malformed else/elsif/endif/endfor, #713
2024-07-05 01:23:33 +08:00
Jun Yang and GitHub
3b5627b040
feat: support catching all errors, #220 ( #710 )
2024-06-17 22:48:57 +08:00
a0ea372764
docs: fix some spelling ( #708 )
...
* spelling: according
Signed-off-by: Josh Soref <[email protected] >
* spelling: asynchronously
Signed-off-by: Josh Soref <[email protected] >
* spelling: background
Signed-off-by: Josh Soref <[email protected] >
* spelling: camel
Signed-off-by: Josh Soref <[email protected] >
* spelling: cannot
Signed-off-by: Josh Soref <[email protected] >
* spelling: case-sensitive
Signed-off-by: Josh Soref <[email protected] >
* spelling: comparison
Signed-off-by: Josh Soref <[email protected] >
* spelling: demos
Signed-off-by: Josh Soref <[email protected] >
* spelling: forloop
Signed-off-by: Josh Soref <[email protected] >
* spelling: formatters
Signed-off-by: Josh Soref <[email protected] >
* spelling: github
Signed-off-by: Josh Soref <[email protected] >
* spelling: guidelines
Signed-off-by: Josh Soref <[email protected] >
* spelling: hashes
Signed-off-by: Josh Soref <[email protected] >
* spelling: https
Signed-off-by: Josh Soref <[email protected] >
* spelling: javascript
Signed-off-by: Josh Soref <[email protected] >
* spelling: keep
Signed-off-by: Josh Soref <[email protected] >
* spelling: natural
Signed-off-by: Josh Soref <[email protected] >
* spelling: neither
Signed-off-by: Josh Soref <[email protected] >
* spelling: no longer
Signed-off-by: Josh Soref <[email protected] >
* spelling: nonexistent
Signed-off-by: Josh Soref <[email protected] >
* spelling: output
Signed-off-by: Josh Soref <[email protected] >
* spelling: polymorphism
Signed-off-by: Josh Soref <[email protected] >
* spelling: precache
Signed-off-by: Josh Soref <[email protected] >
* spelling: programmatically
Signed-off-by: Josh Soref <[email protected] >
* spelling: punctuation
Signed-off-by: Josh Soref <[email protected] >
* spelling: registration
Signed-off-by: Josh Soref <[email protected] >
* spelling: rendered
Signed-off-by: Josh Soref <[email protected] >
* spelling: synchronously
Signed-off-by: Josh Soref <[email protected] >
* spelling: thrown
Signed-off-by: Josh Soref <[email protected] >
* spelling: trimmed
Signed-off-by: Josh Soref <[email protected] >
* spelling: unbalanced
Signed-off-by: Josh Soref <[email protected] >
* chore: use example.com
* chore: fix reference for sidebar.registration
---------
Signed-off-by: Josh Soref <[email protected] >
Co-authored-by: Harttle <[email protected] >
2024-06-17 17:19:46 +08:00
Adam Tanner and GitHub
a7da93ff0f
fix: use drop valueOf when evaluated as condition ( #705 )
2024-06-05 08:28:21 +08:00