Yang Jun and Cursor
bf3a06fe23
test(context): assert scope isolation without probing prototypes
...
Replace Object.getPrototypeOf checks for bottom() and getAll() with
'in' checks on typical Object.prototype names plus a merge assertion.
Co-authored-by: Cursor <[email protected] >
2026-05-13 01:06:51 +08:00
Yang Jun and Cursor
8a3634a3cb
revert(context): plain {} registers and getRegister ||
...
Registers are only mutated by tag implementations, not templates; keep null-prototype scopes/createScope for push frames.
Co-authored-by: Cursor <[email protected] >
2026-05-13 00:40:49 +08:00
Yang Jun and Cursor
a69c3ea2a6
fix(context): use null-prototype scope and register objects
...
Add createScope(); use for bottom scope, spawn default, getAll merge, ctx.push frames, filter loops, include/layout blocks registers, and cycle groups. registers uses Object.create(null) and getRegister uses ??.
For-loop continue register defaults to 0 (not {}): Array.slice coerces plain {} but not null-prototype objects.
Export createScope from the package entry.
Co-authored-by: Cursor <[email protected] >
2026-05-12 22:50:51 +08:00
dbbf628803
fix: propagate ownPropertyOnly into Context.spawn() for {% render %} ( #893 )
...
Child contexts from spawn() re-derived ownPropertyOnly from Liquid opts
only, dropping per-render RenderOptions overrides. That broke the contract
that parseAndRender(..., { ownPropertyOnly: true }) locks down a single
render, including partials loaded via {% render %}.
Add regression test matching prototype-chain leak PoC.
Co-authored-by: Cursor <[email protected] >
2026-05-03 22:35:31 +08:00
Yang Jun and GitHub
e2311dfd6e
fix: nested block for layout ( #883 )
2026-04-19 23:41:35 +08:00
Yang Jun and GitHub
e743da0020
fix: sort and sort_natural filters bypass ownPropertyOnly ( #869 )
...
Use _getFromScope for property access in sort/sort_natural filters to respect the ownPropertyOnly security option, preventing prototype chain traversal that could leak sensitive inherited properties.
Also extract shared sortBy helper, add orderedCompare with nil handling consistent with caseInsensitiveCompare and Ruby Liquid.
Made-with: Cursor
2026-04-07 21:01:20 +08:00
Yang Jun and GitHub
e55128850e
feat: allow context access in liquidMethodMissing, #808 ( #820 )
2025-10-06 18:34:08 +08:00
Harttle and Jun Yang
e3ef574674
fix: inconsistent continue behaviour, fixes #779
2024-12-22 16:32:08 +08:00
Santi Albo and GitHub
11f013bf24
feat: allow drops in property access ( #769 )
2024-11-17 20:24:45 +08:00
Yang Jun
68387c31ea
fix: "filter is not a function" for uniq
2024-08-23 21:27:53 +08:00
Yang Jun
4548c11406
fix: support for NodeJS 15, fixes #732
2024-08-16 23:40:48 +08:00
Koen and GitHub
f03247d420
Import performance object from perf_hooks ( #729 )
2024-08-15 22:37:46 +08:00
Jun Yang and GitHub
e4aeb023fd
feat: locale support for date filter, #567 ( #723 )
2024-07-22 00:39:44 +08:00
Yang Jun
e443068cb9
feat: DoS prevention, #250
2024-07-09 22:51:11 +08:00
Jun Yang
2b713b721d
feat: group_by/group_by_exp/find/find_exp from Jekyll, #443
2024-04-14 19:34:07 +08:00
Harttle
45adbd7008
fix: map filter allow nil results in strict mode, fixes #647
2023-08-24 00:20:57 +08:00
Francisco Soto and Jun Yang
dc6a301387
fix: for throws undefined var with a null value with strictVariables
2023-08-19 23:54:32 +08:00
Harttle and Jun Yang
c6cde9cd10
chore: migrate test cases from Chai to Jest
2023-03-20 00:41:06 +08:00
Slav Ivanov and Harttle
d489916231
fix: "ownPropertyOnly" not respected when passed via "renderOptions"
2023-02-14 22:39:38 +08:00
Jun Yang
92992689cd
refactor: Tag class support in registerTag()
2022-11-27 14:04:01 +08:00
Jun Yang
7eb621601c
refactor: change ownPropertyOnly default value to true
...
BREAKING CHANGE: `ownPropertyOnly` default value changed to `true`
2022-11-27 14:04:01 +08:00
Harttle and Harttle
bbf00f37bf
feat: promise in expression & nested property, #533 #276
2022-08-27 23:19:16 +08:00
Harttle
049685b9a0
feat: Access array item by negative index, closes #486
2022-03-06 00:52:22 +08:00
Harttle
2b0c5696bc
docs: introduce JS script to escape for Hexo, fixes #480
2022-02-24 01:04:50 +08:00
Harttle and Harttle
7e99efc513
feat: ownPropertyOnly option to protect prototype, #454
2022-01-29 01:22:34 +08:00
Harttle and Harttle
6801552fe6
feat: customize globals & strictVariables when calling render, see #432
2021-12-11 20:22:58 +08:00
Harttle and Harttle
6c114267a5
fix: size filter does not respect Objects, fixes #385
2021-12-07 23:05:46 +08:00
AleksandrHovhannisyan and Harttle
124f4c4485
fix: allow {%render%} to reassign argument, #404
2021-10-31 16:28:33 +08:00
Harttle and harttle
aea34418de
perf: make the most of streamed rendering
2021-10-01 18:36:57 +08:00
harttle
e37824fd8a
feat: support function calls, closes #222
2021-02-12 13:47:30 +08:00
sschuldenzucker and Jun Yang
d8f9091a12
add and use error classes for undefined variables
...
cleans up funky message-matching code in expression.ts for lenient.
2020-12-06 22:58:08 +08:00
harttle
d2d6a38235
perf: introduce AST to avoid reparse
2020-03-15 02:51:25 +08:00
harttle
3dfdf982c9
perf: remove transient strings to reduce memory
2020-03-14 19:04:18 +08:00
harttle
6ea6881f08
feat: with & for in render tag, closes #195
2020-03-04 07:08:54 +08:00
harttle
870e7ec6aa
feat: globals shared between tags, see #185
2020-02-08 04:59:23 +08:00
harttle
60ec74f55d
feat: nested property for the where filter, #178
2019-12-13 01:15:29 +08:00
harttle
f82da11f5a
fix: reading .first, .last of Array, closes #175
2019-11-16 01:14:09 +08:00
Jun Yang
d5e7b047bb
feat: Support for the "render" tag #163
2019-10-27 00:06:16 +08:00
harttle
0426d08fd0
style: fix linting
2019-08-26 10:15:43 -05:00
harttle
7fb01ad69a
feat: renderSync, parseAndRenderSync and renderFileSync, see #48
2019-08-26 10:15:43 -05:00
harttle
ae45c4622e
fix: break/continue omitting output before them, #123
...
BREAKING CHANGE: remove default export, now should be used like import
{Liquid} from 'liquidjs'
2019-08-26 10:15:43 -05:00
harttle
34d5af25a4
chore: trying to fix TS4053
2019-07-06 14:49:39 +08:00
harttle
88c89fe3b3
style: introduce @typescript-eslint/recommended
2019-07-06 14:33:34 +08:00
harttle
6c5dc336e7
chore: fix linting, working on #120
2019-04-17 10:45:02 +08:00
harttle
00bc1efe6a
feat: pass context to filters
2019-04-17 10:24:55 +08:00
harttle
82d7673554
perf: use polymophism instead duck test
2019-03-25 20:11:23 +08:00
harttle
64dd057552
refactor: Context#propertyAccessSeq => parseProp
2019-03-25 10:36:23 +08:00
harttle
45e3c2bb8e
refactor: switch Context <-> Scope concepts
2019-03-25 10:36:23 +08:00