mirror of
https://github.com/harttle/liquidjs.git
synced 2026-09-17 05:10:40 -07:00
* fix(date): cap strftime widths and account padding in memoryLimit - Clamp numeric strftime pad widths to MAX_STRFTIME_PAD (1024) - Export estimateStrftimePaddingMemory for the date filter to charge memoryLimit - Replace unbounded pad() concatenation loop with ch.repeat + single concat - Add regression tests for clamping and memoryLimit on huge %width directives Co-authored-by: Cursor <[email protected]> * fix(date): harden strftime memory accounting and document security model Move strftime memory charging into the same formatting path used for padding, enforce pre-allocation checks, and add regression tests for non-string date format PoCs. Add dedicated docs clarifying that memoryLimit is cooperative DoS mitigation and not strict heap isolation. Co-authored-by: Cursor <[email protected]> * docs(zh-cn): add security model docs for DoS limits Add a Chinese security-model tutorial and link it from the Chinese DoS guide to clarify that memoryLimit is cooperative accounting, list uncounted custom conversion cases, and recommend avoiding fully user-defined templates in online services. Co-authored-by: Cursor <[email protected]> * docs: consolidate DoS docs into security-model pages Merge DoS guidance into security-model docs in both English and Chinese, and remove the placeholder dos.md pages to avoid duplicate/redirect-only docs. Co-authored-by: Cursor <[email protected]> * docs: merge DoS details into security-model docs Move the detailed parseLimit/renderLimit/memoryLimit explanations and examples into the English and Chinese security-model pages so content from the removed dos pages is preserved. Co-authored-by: Cursor <[email protected]> * docs: reorganize security-model structure for clarity Restructure English and Chinese security-model docs into a consistent flow: security boundary, limits overview, per-limit details, and online service guidance. Co-authored-by: Cursor <[email protected]> * refactor(strftime): simplify %N width parsing logic Use regex-backed width assumptions to simplify %N width normalization and padding memory accounting while keeping behavior equivalent. Co-authored-by: Cursor <[email protected]> * refactor(strftime): rely on memoryLimit for width control Remove MAX_STRFTIME_PAD hard capping and rely on memoryLimit enforcement before padding allocation. Update strftime/date tests and security-model docs to match the new boundary and renderLimit caveats. Co-authored-by: Cursor <[email protected]> * fix(strftime): use add() once for padding, minimize churn - pad(): replace per-char loop with a single add(str, ch.repeat(n)) call. The earlier `probe[0] === ch` heuristic was wrong when ch happened to equal a leading char of 'probe' (e.g. ch === 'p'). - strftime.ts: revert unrelated typing/structural refactors so the diff contains only the memoryLimit threading and the %N memory charge. - docs: rewire the deleted dos.html sidebar entry to security-model.html (with localized labels) so the deleted page does not 404 from the sidebar. Co-authored-by: Cursor <[email protected]> --------- Co-authored-by: Cursor <[email protected]>
67 lines
1.9 KiB
YAML
67 lines
1.9 KiB
YAML
menu:
|
|
tutorials: Tutorials
|
|
tags: Tags
|
|
filters: Filters
|
|
playground: Playground
|
|
api: API
|
|
search: Search
|
|
|
|
index:
|
|
get_started: Get Started
|
|
contributors:
|
|
title: Contributors
|
|
description: 'LiquidJS follows the <a href="https://github.com/all-contributors/all-contributors">all-contributors</a> specification, see <a href="tutorials/contribution-guidelines.html">guidelines here</a>! Thanks goes to these wonderful people:'
|
|
sponsors:
|
|
title: Sponsors
|
|
description: 'If you personally love LiquidJS or it's benefiting your business, please <a href="https://github.com/sponsors/harttle">sponsor us</a>!'
|
|
|
|
playground:
|
|
title: Playground
|
|
loading: Loading...
|
|
|
|
page:
|
|
contents: Contents
|
|
back_to_top: Back to Top
|
|
improve: Improve this doc
|
|
report: Report problems
|
|
prev: Prev
|
|
next: Next
|
|
last_updated: "Last updated: %s"
|
|
|
|
sidebar:
|
|
tutorials:
|
|
getting_started: Getting Started
|
|
intro: Intro to Liquid
|
|
setup: Setup
|
|
options: Options
|
|
render_file: Render Files
|
|
partials: Includes and Layouts
|
|
express: Use in Express.js
|
|
|
|
advanced: Advanced
|
|
caching: Caching
|
|
escaping: Escaping
|
|
registration: Register Filters/Tags
|
|
access_scope_in_filters: Access Scope in Filters
|
|
parse_parameters: Parse Parameters
|
|
render_tag_content: Render Tag Content
|
|
drops: Liquid Drops
|
|
sync_and_async: Sync and Async
|
|
whitespace: Whitespace Control
|
|
plugins: Plugins
|
|
operators: Operators
|
|
truth: Truthy and Falsy
|
|
security_model: Security Model
|
|
static_analysis: Static Analysis
|
|
|
|
miscellaneous: Miscellaneous
|
|
migration9: 'Migrate to LiquidJS 9'
|
|
contribution_guidelines: 'Contribution Guidelines'
|
|
changelog: 'Changelog'
|
|
differences: Differences with Shopify/liquid
|
|
filters:
|
|
overview: Overview
|
|
tags:
|
|
overview: Overview
|
|
footer:
|
|
license: 'Documentation licensed under <a href="https://creativecommons.org/licenses/by/4.0/" target="_blank">CC BY 4.0</a>.' |