mirror of
https://github.com/smarty-php/smarty.git
synced 2026-08-06 21:44:17 +02:00
Compare commits
7 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 5de6092a56 | |||
| 32c8339492 | |||
| 2042979701 | |||
| d0270fb8ea | |||
| 39db8ce64f | |||
| 11cc46c942 | |||
| d974bde2c4 |
@@ -6,12 +6,6 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
|
||||
|
||||
## [Unreleased]
|
||||
|
||||
## [5.2.0] - 2024-05-28
|
||||
- Fixed a code injection vulnerability in extends-tag. This addresses CVE-2024-35226.
|
||||
- Added `$smarty->setCacheModifiedCheck()` setter for cache_modified_check
|
||||
- Added a PSR-4 loading script to allow Smarty to be used without Composer [#1017](https://github.com/smarty-php/smarty/pull/1017)
|
||||
|
||||
|
||||
## [5.1.0] - 2024-04-22
|
||||
- Prevent deprecation notices during compilation in PHP8.3 [#996](https://github.com/smarty-php/smarty/issues/996)
|
||||
- Fix that getTemplateVars would return an array of objects instead of the assigned variables values [#994](https://github.com/smarty-php/smarty/issues/994)
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
- Added a PSR-4 loading script to allow Smarty to be used without Composer [#1017](https://github.com/smarty-php/smarty/pull/1017)
|
||||
@@ -32,7 +32,7 @@ class ExtendsTag extends Inheritance {
|
||||
*
|
||||
* @var array
|
||||
*/
|
||||
protected $optional_attributes = [];
|
||||
protected $optional_attributes = ['extends_resource'];
|
||||
|
||||
/**
|
||||
* Attribute definition: Overwrites base class.
|
||||
@@ -64,7 +64,29 @@ class ExtendsTag extends Inheritance {
|
||||
}
|
||||
// add code to initialize inheritance
|
||||
$this->registerInit($compiler, true);
|
||||
$this->compileEndChild($compiler, $_attr['file']);
|
||||
$file = trim($_attr['file'], '\'"');
|
||||
if (strlen($file) > 8 && substr($file, 0, 8) === 'extends:') {
|
||||
// generate code for each template
|
||||
$files = array_reverse(explode('|', substr($file, 8)));
|
||||
$i = 0;
|
||||
foreach ($files as $file) {
|
||||
if ($file[0] === '"') {
|
||||
$file = trim($file, '".');
|
||||
} else {
|
||||
$file = "'{$file}'";
|
||||
}
|
||||
$i++;
|
||||
if ($i === count($files) && isset($_attr['extends_resource'])) {
|
||||
$this->compileEndChild($compiler);
|
||||
}
|
||||
$this->compileInclude($compiler, $file);
|
||||
}
|
||||
if (!isset($_attr['extends_resource'])) {
|
||||
$this->compileEndChild($compiler);
|
||||
}
|
||||
} else {
|
||||
$this->compileEndChild($compiler, $_attr['file']);
|
||||
}
|
||||
return '';
|
||||
}
|
||||
|
||||
@@ -84,4 +106,42 @@ class ExtendsTag extends Inheritance {
|
||||
(isset($template) ? ", {$template}, \$_smarty_current_dir" : '') . ");\n?>"
|
||||
);
|
||||
}
|
||||
|
||||
/**
|
||||
* Add code for including subtemplate to end of template
|
||||
*
|
||||
* @param \Smarty\Compiler\Template $compiler
|
||||
* @param string $template subtemplate name
|
||||
*
|
||||
* @throws \Smarty\CompilerException
|
||||
* @throws \Smarty\Exception
|
||||
*/
|
||||
private function compileInclude(\Smarty\Compiler\Template $compiler, $template) {
|
||||
$compiler->getParser()->template_postfix[] = new \Smarty\ParseTree\Tag(
|
||||
$compiler->getParser(),
|
||||
$compiler->compileTag(
|
||||
'include',
|
||||
[
|
||||
$template,
|
||||
['scope' => 'parent'],
|
||||
]
|
||||
)
|
||||
);
|
||||
}
|
||||
|
||||
/**
|
||||
* Create source code for {extends} from source components array
|
||||
*
|
||||
* @param \Smarty\Template $template
|
||||
*
|
||||
* @return string
|
||||
*/
|
||||
public static function extendsSourceArrayCode(\Smarty\Template $template) {
|
||||
$resources = [];
|
||||
foreach ($template->getSource()->components as $source) {
|
||||
$resources[] = $source->resource;
|
||||
}
|
||||
return $template->getLeftDelimiter() . 'extends file=\'extends:' . join('|', $resources) .
|
||||
'\' extends_resource=true' . $template->getRightDelimiter();
|
||||
}
|
||||
}
|
||||
|
||||
+11
-27
@@ -403,37 +403,21 @@ class Template extends BaseCompiler {
|
||||
}
|
||||
// get template source
|
||||
if (!empty($this->template->getSource()->components)) {
|
||||
|
||||
$_compiled_code = '<?php $_smarty_tpl->getInheritance()->init($_smarty_tpl, true); ?>';
|
||||
|
||||
$i = 0;
|
||||
$reversed_components = array_reverse($this->template->getSource()->components);
|
||||
foreach ($reversed_components as $source) {
|
||||
$i++;
|
||||
if ($i === count($reversed_components)) {
|
||||
$_compiled_code .= '<?php $_smarty_tpl->getInheritance()->endChild($_smarty_tpl); ?>';
|
||||
}
|
||||
$_compiled_code .= $this->compileTag(
|
||||
'include',
|
||||
[
|
||||
var_export($source->resource, true),
|
||||
['scope' => 'parent'],
|
||||
]
|
||||
);
|
||||
}
|
||||
$_compiled_code = $this->smarty->runPostFilters($_compiled_code, $this->template);
|
||||
// we have array of inheritance templates by extends: resource
|
||||
// generate corresponding source code sequence
|
||||
$_content =
|
||||
ExtendsTag::extendsSourceArrayCode($this->template);
|
||||
} else {
|
||||
// get template source
|
||||
$_content = $this->template->getSource()->getContent();
|
||||
$_compiled_code = $this->smarty->runPostFilters(
|
||||
$this->doCompile(
|
||||
$this->smarty->runPreFilters($_content, $this->template),
|
||||
true
|
||||
),
|
||||
$this->template
|
||||
);
|
||||
}
|
||||
|
||||
$_compiled_code = $this->smarty->runPostFilters(
|
||||
$this->doCompile(
|
||||
$this->smarty->runPreFilters($_content, $this->template),
|
||||
true
|
||||
),
|
||||
$this->template
|
||||
);
|
||||
} catch (\Exception $e) {
|
||||
if ($this->smarty->debugging) {
|
||||
$this->smarty->getDebug()->end_compile($this->template);
|
||||
|
||||
+1
-10
@@ -54,7 +54,7 @@ class Smarty extends \Smarty\TemplateBase {
|
||||
/**
|
||||
* smarty version
|
||||
*/
|
||||
const SMARTY_VERSION = '5.2.0';
|
||||
const SMARTY_VERSION = '5.1.0';
|
||||
|
||||
/**
|
||||
* define caching modes
|
||||
@@ -2211,14 +2211,5 @@ class Smarty extends \Smarty\TemplateBase {
|
||||
return $template;
|
||||
}
|
||||
|
||||
/**
|
||||
* Sets if Smarty should check If-Modified-Since headers to determine cache validity.
|
||||
* @param bool $cache_modified_check
|
||||
* @return void
|
||||
*/
|
||||
public function setCacheModifiedCheck($cache_modified_check): void {
|
||||
$this->cache_modified_check = (bool) $cache_modified_check;
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
|
||||
@@ -1193,38 +1193,8 @@ class CompileBlockExtendsTest extends PHPUnit_Smarty
|
||||
);
|
||||
}
|
||||
|
||||
public function testBlockWithAssign() {
|
||||
$this->assertEquals('Captured content is: Content with lots of html here', $this->smarty->fetch('038_child.tpl'));
|
||||
}
|
||||
|
||||
/**
|
||||
* Test escaping of file parameter
|
||||
*/
|
||||
public function testEscaping()
|
||||
{
|
||||
$this->expectException(\Smarty\Exception::class);
|
||||
$this->expectExceptionMessageMatches('/Unable to load.*/');
|
||||
$this->assertEquals('hello world', $this->smarty->fetch('escaping.tpl'));
|
||||
}
|
||||
|
||||
/**
|
||||
* Test escaping of file parameter 2
|
||||
*/
|
||||
public function testEscaping2()
|
||||
{
|
||||
$this->expectException(\Smarty\Exception::class);
|
||||
$this->expectExceptionMessageMatches('/Unable to load.*/');
|
||||
$this->assertEquals('hello world', $this->smarty->fetch('escaping2.tpl'));
|
||||
}
|
||||
|
||||
/**
|
||||
* Test escaping of file parameter 3
|
||||
*/
|
||||
public function testEscaping3()
|
||||
{
|
||||
$this->expectException(\Smarty\Exception::class);
|
||||
$this->expectExceptionMessageMatches('/Unable to load.*/');
|
||||
$this->assertEquals('hello world', $this->smarty->fetch('escaping3.tpl'));
|
||||
}
|
||||
public function testBlockWithAssign() {
|
||||
$this->assertEquals('Captured content is: Content with lots of html here', $this->smarty->fetch('038_child.tpl'));
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
@@ -1 +0,0 @@
|
||||
{extends "extends:helloworld.tpl', var_dump(shell_exec('ls')), 1, 2, 3);}}?>"}
|
||||
@@ -1 +0,0 @@
|
||||
{extends 'extends:"helloworld.tpl\', var_dump(shell_exec(\'ls\')), 1, 2, 3);}}?>'}
|
||||
@@ -1 +0,0 @@
|
||||
{extends file='extends:"helloworld.tpl'|cat:"', var_dump(shell_exec('ls')), 1, 2, 3);}}?>"}
|
||||
@@ -82,18 +82,6 @@ class CompileIncludeTest extends PHPUnit_Smarty
|
||||
$this->assertEquals('I1I2I3', $content, $text);
|
||||
}
|
||||
|
||||
/**
|
||||
* test template name escaping
|
||||
*/
|
||||
public function testIncludeFilenameEscaping()
|
||||
{
|
||||
$this->expectException(\Smarty\Exception::class);
|
||||
$this->expectExceptionMessageMatches('/Unable to load.*/');
|
||||
$tpl = $this->smarty->createTemplate('test_include_security.tpl');
|
||||
$content = $this->smarty->fetch($tpl);
|
||||
$this->assertEquals("hello world", $content);
|
||||
}
|
||||
|
||||
/**
|
||||
* test standard output
|
||||
*
|
||||
|
||||
@@ -1 +0,0 @@
|
||||
{include file="helloworld.tpl', var_dump(shell_exec('ls')), 1, 2, 3);}}?>"}
|
||||
@@ -32,11 +32,4 @@ class ExtendsIssue419Test extends PHPUnit_Smarty
|
||||
$this->assertEquals('child', $this->smarty->fetch('extends:001_parent.tpl|001_child.tpl'));
|
||||
}
|
||||
|
||||
public function testextendsSecurity()
|
||||
{
|
||||
$this->expectException(\Smarty\Exception::class);
|
||||
$this->expectExceptionMessageMatches('/Unable to load.*/');
|
||||
$this->assertEquals('child', $this->smarty->fetch('string:{include "001_parent.tpl\', var_dump(shell_exec(\'ls\')), 1, 2, 3);}}?>"}'));
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user