mirror of
https://github.com/harttle/liquidjs.git
synced 2026-09-16 12:50:38 -07:00
- `relativeReference` is enabled by default, set to `false` to disable
- Referenced files are still constrained within root/partias/layouts
- fix: relative filenames are not constrained (which allows arbitrary filesystem read)
Example Usage:
{% render "../foo/bar.html" %}
Note:
../foo/bar.html' should also be within `partials` (or `root` if `partials` not set)
17 lines
591 B
TypeScript
17 lines
591 B
TypeScript
import { expect, use } from 'chai'
|
|
import * as fs from '../../../src/fs/node'
|
|
import * as chaiAsPromised from 'chai-as-promised'
|
|
import { Loader } from '../../../src/fs/loader'
|
|
|
|
use(chaiAsPromised)
|
|
|
|
describe('fs/loader', function () {
|
|
describe('.candidates()', function () {
|
|
it('should break once found', async function () {
|
|
const loader = new Loader({ relativeReference: true, fs, extname: '' } as any)
|
|
const candidates = [...loader.candidates('./foo/bar', ['/root', '/root/foo'], '/root/current')]
|
|
expect(candidates.join()).to.equal('/root/foo/bar')
|
|
})
|
|
})
|
|
})
|