Compare commits

...

15 Commits

Author SHA1 Message Date
Uwe Tews ad3e64b890 Merge branch 'v2.6.26' 2014-10-31 00:57:26 +01:00
Uwe Tews 8bcad8125a delete unneeded 2014-10-31 00:56:50 +01:00
Uwe Tews de8354e152 Merge branch 'v2.6.25' 2014-10-31 00:52:59 +01:00
Uwe Tews 9e6dddeee4 delete unneeded 2014-10-31 00:52:20 +01:00
monte.ohrt fc60543d80 remove trunk dir 2010-11-11 23:01:55 +00:00
monte.ohrt d88df01d7d tag 2_6_26 2010-11-11 22:50:16 +00:00
monte.ohrt 443e36f1a8 revert super global access changes, and instead use ALLOW_SUPER_GLOBALS for security measures 2009-06-17 14:39:24 +00:00
monte.ohrt c1bf89849b fix syntax error in example 2009-06-15 14:56:50 +00:00
monte.ohrt 4014a41c02 update super global access to gracefully handle unset super global vars 2009-06-15 14:04:53 +00:00
matakagi 3bdad9eaeb sync with en. 2009-06-14 07:23:39 +00:00
matakagi 42696fcc21 sync with en. 2009-06-14 05:59:54 +00:00
monte.ohrt 8189261d68 update example to be css friendly 2009-06-12 14:49:25 +00:00
monte.ohrt 49e154a6f9 make it clear {section} is for sequentially indexed arrays 2009-05-28 14:13:11 +00:00
monte.ohrt 2172df777a fix E_NOTICE Errors 2009-05-23 20:59:25 +00:00
monte.ohrt 25be1792e6 fix E_NOTICE with sessions disabled 2009-05-17 14:48:19 +00:00
4 changed files with 58 additions and 29 deletions
+11
View File
@@ -1,3 +1,14 @@
- revert super global access changes, and instead rely on
USE_SUPER_GLOBALS for security
Version 2.6.25 (May 19th, 2009)
-------------------------------
- fix E_NOTICE when sessions are disabled (mohrt)
Version 2.6.24 (May 16th, 2009)
-------------------------------
- fix problem introduced with super global changes (mohrt)
Version 2.6.23 (May 13th, 2009)
-------------------------------
- strip backticks from {math} equations (mohrt)
+1 -1
View File
@@ -22,7 +22,7 @@
* smarty-discussion-subscribe@googlegroups.com
*
* @link http://www.smarty.net/
* @version 2.6.24-dev
* @version 2.6.25-dev
* @copyright Copyright: 2001-2005 New Digital Group, Inc.
* @author Andrei Zmievski <andrei@php.net>
* @access public
+3 -20
View File
@@ -27,7 +27,7 @@
* @author Monte Ohrt <monte at ohrt dot com>
* @author Andrei Zmievski <andrei@php.net>
* @package Smarty
* @version 2.6.24-dev
* @version 2.6.25-dev
*/
/* $Id$ */
@@ -107,7 +107,7 @@ class Smarty
/**
* When set, smarty does uses this value as error_reporting-level.
*
* @var boolean
* @var integer
*/
var $error_reporting = null;
@@ -465,7 +465,7 @@ class Smarty
*
* @var string
*/
var $_version = '2.6.24-dev';
var $_version = '2.6.25-dev';
/**
* current template inclusion depth
@@ -562,14 +562,6 @@ class Smarty
*/
var $_cache_including = false;
/**
* array of super globals internally
*
* @var array
*/
var $_supers = array();
/**#@-*/
/**
* The class constructor.
@@ -578,15 +570,6 @@ class Smarty
{
$this->assign('SCRIPT_NAME', isset($_SERVER['SCRIPT_NAME']) ? $_SERVER['SCRIPT_NAME']
: @$GLOBALS['HTTP_SERVER_VARS']['SCRIPT_NAME']);
$this->_supers['get'] = $this->request_use_auto_globals ? $_GET : $GLOBALS['HTTP_GET_VARS'];
$this->_supers['post'] = $this->request_use_auto_globals ? $_POST : $GLOBALS['HTTP_POST_VARS'];
$this->_supers['server'] = $this->request_use_auto_globals ? $_SERVER : $GLOBALS['HTTP_SERVER_VARS'];
$this->_supers['session'] = $this->request_use_auto_globals ? $_SESSION : $GLOBALS['HTTP_SESSION_VARS'];
$this->_supers['request'] = $this->request_use_auto_globals ? $_REQUEST : $GLOBALS['HTTP_REQUEST_VARS'];
$this->_supers['cookies'] = $this->request_use_auto_globals ? $_COOKIE : $GLOBALS['HTTP_COOKIE_VARS'];
$this->_supers['env'] = $this->request_use_auto_globals ? $_ENV : $GLOBALS['HTTP_ENV_VARS'];
}
/**
+43 -8
View File
@@ -21,7 +21,7 @@
* @link http://smarty.php.net/
* @author Monte Ohrt <monte at ohrt dot com>
* @author Andrei Zmievski <andrei@php.net>
* @version 2.6.24-dev
* @version 2.6.25-dev
* @copyright 2001-2005 New Digital Group, Inc.
* @package Smarty
*/
@@ -2047,27 +2047,57 @@ class Smarty_Compiler extends Smarty {
break;
case 'get':
$compiled_ref = "\$this->_supers['get']";
if ($this->security && !$this->security_settings['ALLOW_SUPER_GLOBALS']) {
$this->_syntax_error("(secure mode) super global access not permitted",
E_USER_WARNING, __FILE__, __LINE__);
return;
}
$compiled_ref = "\$_GET";
break;
case 'post':
$compiled_ref = "\$this->_supers['post']";
if ($this->security && !$this->security_settings['ALLOW_SUPER_GLOBALS']) {
$this->_syntax_error("(secure mode) super global access not permitted",
E_USER_WARNING, __FILE__, __LINE__);
return;
}
$compiled_ref = "\$_POST";
break;
case 'cookies':
$compiled_ref = "\$this->_supers['cookies']";
if ($this->security && !$this->security_settings['ALLOW_SUPER_GLOBALS']) {
$this->_syntax_error("(secure mode) super global access not permitted",
E_USER_WARNING, __FILE__, __LINE__);
return;
}
$compiled_ref = "\$_COOKIE";
break;
case 'env':
$compiled_ref = "\$this->_supers['env']";
if ($this->security && !$this->security_settings['ALLOW_SUPER_GLOBALS']) {
$this->_syntax_error("(secure mode) super global access not permitted",
E_USER_WARNING, __FILE__, __LINE__);
return;
}
$compiled_ref = "\$_ENV";
break;
case 'server':
$compiled_ref = "\$this->_supers['server']";
if ($this->security && !$this->security_settings['ALLOW_SUPER_GLOBALS']) {
$this->_syntax_error("(secure mode) super global access not permitted",
E_USER_WARNING, __FILE__, __LINE__);
return;
}
$compiled_ref = "\$_SERVER";
break;
case 'session':
$compiled_ref = "\$this->_supers['session']";
if ($this->security && !$this->security_settings['ALLOW_SUPER_GLOBALS']) {
$this->_syntax_error("(secure mode) super global access not permitted",
E_USER_WARNING, __FILE__, __LINE__);
return;
}
$compiled_ref = "\$_SESSION";
break;
/*
@@ -2075,8 +2105,13 @@ class Smarty_Compiler extends Smarty {
* compiler.
*/
case 'request':
if ($this->security && !$this->security_settings['ALLOW_SUPER_GLOBALS']) {
$this->_syntax_error("(secure mode) super global access not permitted",
E_USER_WARNING, __FILE__, __LINE__);
return;
}
if ($this->request_use_auto_globals) {
$compiled_ref = "\$this->_supers['request']";
$compiled_ref = "\$_REQUEST";
break;
} else {
$this->_init_smarty_vars = true;