Compare commits

...
Author SHA1 Message Date
Simon Wisselink 4698dd9fb0 Changelog 2021-03-21 21:24:32 +01:00
David GoodwinandGitHub 039043e5a2 Update modifier.escape.php (#649)
trigger a notice if an incorrect modifier was used (E.g.|escape:quotes vs |escape:quote).
2021-03-21 21:21:55 +01:00
Simon WisselinkandGitHub 290aee6db3 Update CHANGELOG.md
Add CVE's
2021-02-21 22:23:45 +01:00
Simon WisselinkandGitHub e2485fa45e Create SECURITY.md 2021-02-21 22:03:44 +01:00
Simon Wisselink e27da524f7 Merge branch 'release/3.1.39' 2021-02-17 22:57:51 +01:00
Simon Wisselink a21f59663c version bump 2021-02-17 22:57:50 +01:00
Simon Wisselink 3148d406a0 changelog 2021-02-17 22:57:33 +01:00
Simon Wisselink 4f634c0097 Merge branch 'bugfix/tplfunction_sandbox_escape' 2021-02-17 22:52:34 +01:00
Simon Wisselink c9272058d9 Merge branch 'bugfix/template_object_sandbox_escape' 2021-02-17 22:51:38 +01:00
Simon Wisselink e66e293a8a Do not push release automatically in make release script, to enable a chance to catch any errors. 2021-02-17 22:50:52 +01:00
Simon Wisselink 74cab5a56b updated changelog header to security 2021-02-17 22:30:35 +01:00
Simon Wisselink 8fc66e27a7 Cannot use in Smarty3 yet, revert to @expectedException 2021-02-01 10:33:00 +01:00
Simon Wisselink 2543174460 Cannot use in Smarty3 yet, revert to @expectedException 2021-02-01 10:31:20 +01:00
Simon Wisselink 288a54f6b0 Add unit test 2021-01-24 23:52:45 +01:00
Simon Wisselink 165f1bd4d2 Fixed Code injection vulnerability by using illegal function names 2021-01-24 23:44:07 +01:00
Simon Wisselink 6463519a6c Prevent access to .template_object when in security mode to prevent PHP code injection vulnerability 2021-01-24 23:13:26 +01:00
Simon Wisselink fedc127057 Mark tests that use sleep calls as slow, so we can ignore them when running unit tests in development 2021-01-16 23:01:15 +01:00
Ikko AshimineandGitHub 3af2df20a4 Fix typo in StreamVariableTest.php (#616)
existant -> existent
2021-01-08 17:28:33 +01:00
Simon Wisselink 63b3c0aed0 Merge branch 'release/3.1.38' 2021-01-08 15:05:42 +01:00
Simon Wisselink 2af2a07906 version bump 2021-01-08 15:05:40 +01:00
Simon Wisselink cb4254355e Removed unused error_reporting.ini file, updated version number in Smarty::SMARTY_VERSION, fixed inline phpdoc that caused an IDE error 2021-01-08 15:05:10 +01:00
Simon Wisselink f65e7ddd22 fixed changelog 2021-01-07 00:34:08 +01:00
Simon WisselinkandGitHub 92e05d4f8d Brought lexer source functionally up-to-date with compiled version (#625)
Fixes #621
2021-01-07 00:26:28 +01:00
Simon Wisselink e2b28167f8 Clarify correct LGPL version.
Fixes #612
2021-01-05 22:23:13 +01:00
Libor MandGitHub 820782cd80 const fix for usage with comparison operators (#618)
Fixes #609 #613
2021-01-05 22:07:44 +01:00
c295786e43 Fixes for php8.0.0beta3 (#608)
* Set $errcontext argument optional to support PHP 8

- Argument is optional and deprecated in PHP 7.2

* Getting ready for PHP8, handling changed error levels/handlers mostly

* php5 compat syntax

* Updated UndefinedTemplateVarTest for PHP8 (and disabled a check for PHP<5.6) and re-enabled php:nightly in travis config

* Attempt to fix travis runs for (almost) all php versions supported

* Fix unit tests for php8, force composer to think we are still php7 to pick a supported phpunit and being less specific about an error msg because PHP8 is in active development and the exact wording is changing.

* Fixed a unit test that accidentally passed on phpunit < 7 because of sloppy string comparison.

* changelog

* run travis in xenial where possible for latest php versions. Fix unit tests from freakingo over inconsistent error messages in php8-beta.

* Incorporated AnrDaemons suggestions, making composer figure out the required phpunit version instead of specifying it explicitly and removing a unneeded error supression (@).

Co-authored-by: Jorge Sá Pereira <me@jorgesapereira.com>
2020-09-12 21:37:31 +02:00
♚ PH⑦ de Soria™♛andGitHub 859a09e1bb Bumped phpdoc @version tag to 3.1.36 (#598)
Although this could be removed, since the header comment is still there, it's good to keep the @version tag updated in order to avoid confusion for those who read it :)
2020-09-11 13:34:15 +02:00
Simon Wisselink a5934a755d Fixed a unit test that accidentally passed on phpunit < 7 because of sloppy string comparison. 2020-09-11 13:22:45 +02:00
38 changed files with 174 additions and 73 deletions
-1
View File
@@ -12,7 +12,6 @@
/.gitattributes export-ignore /.gitattributes export-ignore
/.gitignore export-ignore /.gitignore export-ignore
/.travis.yml export-ignore /.travis.yml export-ignore
/error_reporting.ini export-ignore
/make-release.sh export-ignore /make-release.sh export-ignore
/phpunit.sh export-ignore /phpunit.sh export-ignore
/phpunit.xml export-ignore /phpunit.xml export-ignore
+11 -10
View File
@@ -1,25 +1,29 @@
language: php language: php
os: linux
dist: xenial
sudo: false install:
- travis_retry composer install
dist: trusty jobs:
matrix:
include: include:
- php: 5.3 # Composer requires PHP 5.3.2+ to run, so we cannot test below 5.3 - php: 5.3 # Composer and PHPUnit require PHP 5.3.2+ to run, so we cannot test below 5.3
dist: precise # PHP 5.3 is supported only on Precise. dist: precise # PHP 5.3 is supported only on Precise.
- php: 5.4 - php: 5.4
dist: trusty # PHP 5.4 is supported only on Trusty.
- php: 5.5 - php: 5.5
dist: trusty # PHP 5.5 is supported only on Trusty.
- php: 5.6 - php: 5.6
- php: 7.0 - php: 7.0
- php: 7.1 - php: 7.1
- php: 7.2 - php: 7.2
- php: 7.3 - php: 7.3
- php: 7.4 - php: 7.4
# - php: nightly # PHP nightly build testing disabled because PHPUnit doesn't support PHP8 yet. - php: nightly
install: travis_retry composer config platform.php 7.4.0 && composer install
fast_finish: true fast_finish: true
allow_failures: allow_failures:
- php: nightly - php: nightly # PHP 8 is still in beta
services: services:
- memcached - memcached
@@ -31,8 +35,5 @@ before_script:
before_install: before_install:
- phpenv config-rm xdebug.ini || return 0 - phpenv config-rm xdebug.ini || return 0
install:
- travis_retry composer install
script: script:
- ./phpunit.sh - ./phpunit.sh
+22 -2
View File
@@ -7,10 +7,30 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
## [Unreleased] ## [Unreleased]
### Changed ### Changed
- Travis unit tests now run for all php versions >= 5.3 - modifier escape now triggers a E_USER_NOTICE when an unsupported escape type is used https://github.com/smarty-php/smarty/pull/649
## [3.1.39] - 2021-02-17
### Security
- Prevent access to `$smarty.template_object` in sandbox mode. This addresses CVE-2021-26119.
- Fixed code injection vulnerability by using illegal function names in `{function name='blah'}{/function}`. This addresses CVE-2021-26120.
## [3.1.38] - 2021-01-08
### Fixed ### Fixed
- PHP5.3 compatability fixes - Smarty::SMARTY_VERSION wasn't updated https://github.com/smarty-php/smarty/issues/628
## [3.1.37] - 2021-01-07
### Changed
- Changed error handlers and handling of undefined constants for php8-compatibility (set $errcontext argument optional) https://github.com/smarty-php/smarty/issues/605
- Changed expected error levels in unit tests for php8-compatibility
- Travis unit tests now run for all php versions >= 5.3, including php8
- Travis runs on Xenial where possible
### Fixed
- PHP5.3 compatibility fixes
- Brought lexer source functionally up-to-date with compiled version
## [3.1.36] - 2020-04-14 ## [3.1.36] - 2020-04-14
+1 -1
View File
@@ -3,7 +3,7 @@ Smarty: the PHP compiling template engine
This library is free software; you can redistribute it and/or This library is free software; you can redistribute it and/or
modify it under the terms of the GNU Lesser General Public modify it under the terms of the GNU Lesser General Public
License as published by the Free Software Foundation; either License as published by the Free Software Foundation; either
version 2.1 of the License, or (at your option) any later version. version 3.0 of the License, or (at your option) any later version.
This library is distributed in the hope that it will be useful, This library is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of but WITHOUT ANY WARRANTY; without even the implied warranty of
+19
View File
@@ -0,0 +1,19 @@
# Security Policy
## Supported Versions
Smarty currently supports the latest minor version of Smarty 3 and Smarty 4. (Smarty 4 has not been released yet.)
| Version | Supported |
| ------- | ------------------ |
| 4.0.x | :white_check_mark: |
| 3.1.x | :white_check_mark: |
| < 3.1 | :x: |
## Reporting a Vulnerability
If you have discovered a security issue with Smarty, please contact us at mail [at] simonwisselink.nl. Do not
disclose your findings publicly and PLEASE PLEASE do not file an Issue.
We will try to confirm the vulnerability and develop a fix if appropriate. When we release the fix, we will publish
a security release. Please let us know if you want to be credited.
+1 -1
View File
@@ -40,7 +40,7 @@
} }
}, },
"require-dev": { "require-dev": {
"phpunit/phpunit": "6.4.1 || ^5.7 || ^4.8", "phpunit/phpunit": "^7.5 || ^6.5 || ^5.7 || ^4.8",
"smarty/smarty-lexer": "^3.1" "smarty/smarty-lexer": "^3.1"
} }
} }
-1
View File
@@ -1 +0,0 @@
error_reporting = E_ALL & ~E_DEPRECATED & ~E_STRICT
View File
+8 -2
View File
@@ -249,7 +249,13 @@ template ::= template PHP(B). {
// template text // template text
template ::= template TEXT(B). { template ::= template TEXT(B). {
$this->current_buffer->append_subtree($this, $this->compiler->processText(B)); $text = $this->yystack[ $this->yyidx + 0 ]->minor;
if ((string)$text == '') {
$this->current_buffer->append_subtree($this, null);
}
$this->current_buffer->append_subtree($this, new Smarty_Internal_ParseTree_Text($text, $this->strip));
} }
// strip on // strip on
template ::= template STRIPON. { template ::= template STRIPON. {
@@ -308,7 +314,7 @@ smartytag(A)::= SIMPLETAG(B). {
$tag = trim(substr(B, $this->compiler->getLdelLength(), -$this->compiler->getRdelLength())); $tag = trim(substr(B, $this->compiler->getLdelLength(), -$this->compiler->getRdelLength()));
if ($tag == 'strip') { if ($tag == 'strip') {
$this->strip = true; $this->strip = true;
A = null;; A = null;
} else { } else {
if (defined($tag)) { if (defined($tag)) {
if ($this->security) { if ($this->security) {
+2 -3
View File
@@ -6,7 +6,7 @@
* This library is free software; you can redistribute it and/or * This library is free software; you can redistribute it and/or
* modify it under the terms of the GNU Lesser General Public * modify it under the terms of the GNU Lesser General Public
* License as published by the Free Software Foundation; either * License as published by the Free Software Foundation; either
* version 2.1 of the License, or (at your option) any later version. * version 3.0 of the License, or (at your option) any later version.
* *
* This library is distributed in the hope that it will be useful, * This library is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of * but WITHOUT ANY WARRANTY; without even the implied warranty of
@@ -27,7 +27,6 @@
* @author Uwe Tews <uwe dot tews at gmail dot com> * @author Uwe Tews <uwe dot tews at gmail dot com>
* @author Rodney Rehm * @author Rodney Rehm
* @package Smarty * @package Smarty
* @version 3.1.34-dev
*/ */
/** /**
* set SMARTY_DIR to absolute path to Smarty library files. * set SMARTY_DIR to absolute path to Smarty library files.
@@ -112,7 +111,7 @@ class Smarty extends Smarty_Internal_TemplateBase
/** /**
* smarty version * smarty version
*/ */
const SMARTY_VERSION = '3.1.36'; const SMARTY_VERSION = '3.1.39';
/** /**
* define variable scopes * define variable scopes
*/ */
+1 -1
View File
@@ -6,7 +6,7 @@
* This library is free software; you can redistribute it and/or * This library is free software; you can redistribute it and/or
* modify it under the terms of the GNU Lesser General Public * modify it under the terms of the GNU Lesser General Public
* License as published by the Free Software Foundation; either * License as published by the Free Software Foundation; either
* version 2.1 of the License, or (at your option) any later version. * version 3.0 of the License, or (at your option) any later version.
* This library is distributed in the hope that it will be useful, * This library is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of * but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+1
View File
@@ -250,6 +250,7 @@ function smarty_modifier_escape($string, $esc_type = 'html', $char_set = null, $
} }
return $return; return $return;
default: default:
trigger_error("escape: unsupported type: $esc_type - returning unmodified string", E_USER_NOTICE);
return $string; return $string;
} }
} }
@@ -58,6 +58,11 @@ class Smarty_Internal_Compile_Function extends Smarty_Internal_CompileBase
} }
unset($_attr[ 'nocache' ]); unset($_attr[ 'nocache' ]);
$_name = trim($_attr[ 'name' ], '\'"'); $_name = trim($_attr[ 'name' ], '\'"');
if (!preg_match('/^[a-zA-Z0-9_\x80-\xff]+$/', $_name)) {
$compiler->trigger_template_error("Function name contains invalid characters: {$_name}", null, true);
}
$compiler->parent_compiler->tpl_function[ $_name ] = array(); $compiler->parent_compiler->tpl_function[ $_name ] = array();
$save = array( $save = array(
$_attr, $compiler->parser->current_buffer, $compiler->template->compiled->has_nocache_code, $_attr, $compiler->parser->current_buffer, $compiler->template->compiled->has_nocache_code,
@@ -81,6 +81,10 @@ class Smarty_Internal_Compile_Private_Special_Variable extends Smarty_Internal_C
case 'template': case 'template':
return 'basename($_smarty_tpl->source->filepath)'; return 'basename($_smarty_tpl->source->filepath)';
case 'template_object': case 'template_object':
if (isset($compiler->smarty->security_policy)) {
$compiler->trigger_template_error("(secure mode) template_object not permitted");
break;
}
return '$_smarty_tpl'; return '$_smarty_tpl';
case 'current_dir': case 'current_dir':
return 'dirname($_smarty_tpl->source->filepath)'; return 'dirname($_smarty_tpl->source->filepath)';
@@ -94,9 +98,9 @@ class Smarty_Internal_Compile_Private_Special_Variable extends Smarty_Internal_C
break; break;
} }
if (strpos($_index[ 1 ], '$') === false && strpos($_index[ 1 ], '\'') === false) { if (strpos($_index[ 1 ], '$') === false && strpos($_index[ 1 ], '\'') === false) {
return "@constant('{$_index[1]}')"; return "(defined('{$_index[1]}') ? constant('{$_index[1]}') : null)";
} else { } else {
return "@constant({$_index[1]})"; return "(defined({$_index[1]}) ? constant({$_index[1]}) : null)";
} }
// no break // no break
case 'config': case 'config':
@@ -65,7 +65,7 @@ class Smarty_Internal_ErrorHandler
* *
* @return bool * @return bool
*/ */
public static function mutingErrorHandler($errno, $errstr, $errfile, $errline, $errcontext) public static function mutingErrorHandler($errno, $errstr, $errfile, $errline, $errcontext = array())
{ {
$_is_muted_directory = false; $_is_muted_directory = false;
// add the SMARTY_DIR to the list of muted directories // add the SMARTY_DIR to the list of muted directories
+1 -1
View File
@@ -14,6 +14,6 @@ git pull
git merge --no-ff "release/$1" git merge --no-ff "release/$1"
git branch -d "release/$1" git branch -d "release/$1"
git tag -a "v$1" -m "Release $1" git tag -a "v$1" -m "Release $1"
git push --follow-tags
printf 'Done creating release %s\n' "$1" printf 'Done creating release %s\n' "$1"
printf 'Run `git push --follow-tags origin` to publish it.\n'
-1
View File
@@ -16,7 +16,6 @@ if (!class_exists('\PHPUnit_Framework_TestCase') && class_exists('\PHPUnit\Frame
class_alias('\PHPUnit\Framework\Error\Error', '\PHPUnit_Framework_Error_Error'); class_alias('\PHPUnit\Framework\Error\Error', '\PHPUnit_Framework_Error_Error');
class_alias('\PHPUnit\Framework\Error\Warning', '\PHPUnit_Framework_Error_Warning'); class_alias('\PHPUnit\Framework\Error\Warning', '\PHPUnit_Framework_Error_Warning');
class_alias('\PHPUnit\Framework\Error\Warning', '\PHPUnit_Framework_Error_Deprecated'); class_alias('\PHPUnit\Framework\Error\Warning', '\PHPUnit_Framework_Error_Deprecated');
class_alias('\PHPUnit\Util\Configuration', '\PHPUnit_Util_Configuration');
} }
require_once 'PHPUnit_Smarty.php'; require_once 'PHPUnit_Smarty.php';
@@ -24,34 +24,37 @@ class UndefinedTemplateVarTest extends PHPUnit_Smarty
$this->cleanDirs(); $this->cleanDirs();
} }
/** /**
* Test E_NOTICE suppression template fetched by Smarty object * Test Error suppression template fetched by Smarty object
*/ */
public function testE_NoticeDisabled() public function testErrorDisabled()
{ {
$e1 = error_reporting(); $e1 = error_reporting();
$this->smarty->setErrorReporting(E_ALL & ~E_NOTICE); $this->smarty->setErrorReporting(E_ALL & ~E_WARNING & ~E_NOTICE);
$this->assertEquals('undefined = ', $this->smarty->fetch('001_main.tpl')); $this->assertEquals('undefined = ', $this->smarty->fetch('001_main.tpl'));
$e2 = error_reporting(); $e2 = error_reporting();
$this->assertEquals($e1, $e2); $this->assertEquals($e1, $e2);
} }
/** /**
* Test E_NOTICE suppression template fetched by template object * Test Error suppression template fetched by template object
*/ */
public function testE_NoticeDisabledTplObject_1() public function testErrorDisabledTplObject_1()
{ {
$e1 = error_reporting(); $e1 = error_reporting();
$this->smarty->setErrorReporting(E_ALL & ~E_NOTICE); $this->smarty->setErrorReporting(E_ALL & ~E_WARNING & ~E_NOTICE);
$tpl = $this->smarty->createTemplate('001_main.tpl'); $tpl = $this->smarty->createTemplate('001_main.tpl');
$this->assertEquals('undefined = ', $tpl->fetch()); $this->assertEquals('undefined = ', $tpl->fetch());
$e2 = error_reporting(); $e2 = error_reporting();
$this->assertEquals($e1, $e2); $this->assertEquals($e1, $e2);
} }
public function testE_NoticeDisabledTplObject_2() /**
* Test Error suppression template object fetched by Smarty object
*/
public function testErrorDisabledTplObject_2()
{ {
$e1 = error_reporting(); $e1 = error_reporting();
$this->smarty->setErrorReporting(E_ALL & ~E_NOTICE); $this->smarty->setErrorReporting(E_ALL & ~E_WARNING & ~E_NOTICE);
$tpl = $this->smarty->createTemplate('001_main.tpl'); $tpl = $this->smarty->createTemplate('001_main.tpl');
$this->assertEquals('undefined = ', $this->smarty->fetch($tpl)); $this->assertEquals('undefined = ', $this->smarty->fetch($tpl));
$e2 = error_reporting(); $e2 = error_reporting();
@@ -59,16 +62,31 @@ class UndefinedTemplateVarTest extends PHPUnit_Smarty
} }
/** /**
* Throw E_NOTICE message * Throw Error message
*
* @expectedException PHPUnit_Framework_Error_Notice
* @expectedExceptionMessage Undefined index: foo
*/ */
public function testE_Notice() public function testError()
{ {
$exceptionThrown = false;
try {
$e1 = error_reporting(); $e1 = error_reporting();
$this->assertEquals('undefined = ', $this->smarty->fetch('001_main.tpl')); $this->assertEquals('undefined = ', $this->smarty->fetch('001_main.tpl'));
$e2 = error_reporting(); $e2 = error_reporting();
$this->assertEquals($e1, $e2); $this->assertEquals($e1, $e2);
} catch (Exception $e) {
$exceptionThrown = true;
$this->assertStringStartsWith('Undefined ', $e->getMessage());
$this->assertTrue(in_array(
get_class($e),
array(
'PHPUnit_Framework_Error_Warning',
'PHPUnit_Framework_Error_Notice',
'PHPUnit\Framework\Error\Warning',
'PHPUnit\Framework\Error\Notice',
)
));
}
$this->assertTrue($exceptionThrown);
} }
} }
@@ -27,7 +27,7 @@ class MuteExpectedErrorsTest extends PHPUnit_Smarty
{ {
$this->cleanDirs(); $this->cleanDirs();
} }
public function error_handler($errno, $errstr, $errfile, $errline, $errcontext) public function error_handler($errno, $errstr, $errfile, $errline, $errcontext = array())
{ {
$this->_errors[] = $errfile . ' line ' . $errline; $this->_errors[] = $errfile . ' line ' . $errline;
} }
@@ -339,6 +339,10 @@ class CacheResourceTestCommon extends PHPUnit_Smarty
$this->assertNull($tpl->cached->handler->getCachedContent($tpl3)); $this->assertNull($tpl->cached->handler->getCachedContent($tpl3));
$this->assertEquals('hello world', $tpl->cached->handler->getCachedContent($tpl4)); $this->assertEquals('hello world', $tpl->cached->handler->getCachedContent($tpl4));
} }
/**
* @group slow
*/
public function testClearCacheExpired() public function testClearCacheExpired()
{ {
$this->smarty->caching = true; $this->smarty->caching = true;
@@ -399,7 +403,7 @@ class CacheResourceTestCommon extends PHPUnit_Smarty
* @runInSeparateProcess * @runInSeparateProcess
* @preserveGlobalState disabled * @preserveGlobalState disabled
* @dataProvider data * @dataProvider data
* * @group slow
*/ */
public function testCache($lockTime, $lockTimeout, $compile_id, $cache_id, $isCached, $tmin, $tmax, $forceCompile, $forceCache, $update, $testNumber, $compileTestNumber, $renderTestNumber, $testName) public function testCache($lockTime, $lockTimeout, $compile_id, $cache_id, $isCached, $tmin, $tmax, $forceCompile, $forceCache, $update, $testNumber, $compileTestNumber, $renderTestNumber, $testName)
{ {
@@ -403,7 +403,11 @@ class ConfigVarTest extends PHPUnit_Smarty
$this->assertEquals("", $this->smarty->fetch('foo.tpl')); $this->assertEquals("", $this->smarty->fetch('foo.tpl'));
} }
catch (Exception $e) { catch (Exception $e) {
$this->assertEquals('Undefined variable: foo', $e->getMessage()); if (PHP_VERSION_ID >= 80000) {
$this->assertStringStartsWith('Undefined variable', $e->getMessage());
} else {
$this->assertStringStartsWith('Undefined variable', $e->getMessage());
}
} }
} }
} }
@@ -125,7 +125,7 @@ class ExtendsResourceTest extends PHPUnit_Smarty
* test grandchild/child/parent dependency test2 * test grandchild/child/parent dependency test2
* @runInSeparateProcess * @runInSeparateProcess
* @preserveGlobalState disabled * @preserveGlobalState disabled
* * @group slow
*/ */
public function testCompileBlockGrandChildMustCompile_021_2() public function testCompileBlockGrandChildMustCompile_021_2()
{ {
@@ -193,7 +193,7 @@ class ExtendsResourceTest extends PHPUnit_Smarty
* test grandchild/child/parent dependency test4 * test grandchild/child/parent dependency test4
* @runInSeparateProcess * @runInSeparateProcess
* @preserveGlobalState disabled * @preserveGlobalState disabled
* * @group slow
*/ */
public function testCompileBlockGrandChildMustCompile_021_4() public function testCompileBlockGrandChildMustCompile_021_4()
{ {
@@ -382,6 +382,15 @@ class SecurityTest extends PHPUnit_Smarty
$this->smarty->security_policy->trusted_uri = array(); $this->smarty->security_policy->trusted_uri = array();
$this->assertContains('<title>Preface | Smarty</title>', $this->smarty->fetch('string:{fetch file="https://www.smarty.net/docs/en/preface.tpl"}')); $this->assertContains('<title>Preface | Smarty</title>', $this->smarty->fetch('string:{fetch file="https://www.smarty.net/docs/en/preface.tpl"}'));
} }
/**
* In security mode, accessing $smarty.template_object should be illegal.
* @expectedException SmartyCompilerException
*/
public function testSmartyTemplateObject() {
$this->smarty->display('string:{$smarty.template_object}');
}
} }
class mysecuritystaticclass class mysecuritystaticclass
@@ -33,7 +33,7 @@ class ClearAllAssignBCTest extends PHPUnit_Smarty
public function testSmarty2ClearAllAssignInSmarty() public function testSmarty2ClearAllAssignInSmarty()
{ {
error_reporting((error_reporting() & ~(E_NOTICE | E_USER_NOTICE))); error_reporting((error_reporting() & ~(E_NOTICE | E_WARNING | E_USER_NOTICE)));
$this->smartyBC->clear_all_assign(); $this->smartyBC->clear_all_assign();
$this->assertEquals('barblar', $this->smartyBC->fetch($this->_tplBC)); $this->assertEquals('barblar', $this->smartyBC->fetch($this->_tplBC));
} }
@@ -46,7 +46,7 @@ class ClearAllAssignTest extends PHPUnit_Smarty
*/ */
public function testClearAllAssignInTemplate() public function testClearAllAssignInTemplate()
{ {
error_reporting((error_reporting() & ~(E_NOTICE | E_USER_NOTICE))); error_reporting((error_reporting() & ~(E_NOTICE | E_USER_NOTICE | E_WARNING)));
$this->_tpl->clearAllAssign(); $this->_tpl->clearAllAssign();
$this->assertEquals('foobar', $this->smarty->fetch($this->_tpl)); $this->assertEquals('foobar', $this->smarty->fetch($this->_tpl));
} }
@@ -56,7 +56,7 @@ class ClearAllAssignTest extends PHPUnit_Smarty
*/ */
public function testClearAllAssignInData() public function testClearAllAssignInData()
{ {
error_reporting((error_reporting() & ~(E_NOTICE | E_USER_NOTICE))); error_reporting((error_reporting() & ~(E_NOTICE | E_USER_NOTICE | E_WARNING)));
$this->_data->clearAllAssign(); $this->_data->clearAllAssign();
$this->assertEquals('fooblar', $this->smarty->fetch($this->_tpl)); $this->assertEquals('fooblar', $this->smarty->fetch($this->_tpl));
} }
@@ -66,7 +66,7 @@ class ClearAllAssignTest extends PHPUnit_Smarty
*/ */
public function testClearAllAssignInSmarty() public function testClearAllAssignInSmarty()
{ {
error_reporting((error_reporting() & ~(E_NOTICE | E_USER_NOTICE))); error_reporting((error_reporting() & ~(E_NOTICE | E_USER_NOTICE | E_WARNING)));
$this->smarty->clearAllAssign(); $this->smarty->clearAllAssign();
$this->assertEquals('barblar', $this->smarty->fetch($this->_tpl)); $this->assertEquals('barblar', $this->smarty->fetch($this->_tpl));
} }
@@ -33,14 +33,14 @@ class ClearAssignBCTest extends PHPUnit_Smarty
} }
public function testSmarty2ClearAssign() public function testSmarty2ClearAssign()
{ {
$this->smartyBC->setErrorReporting(error_reporting() & ~(E_NOTICE | E_USER_NOTICE)); $this->smartyBC->setErrorReporting(error_reporting() & ~(E_NOTICE | E_USER_NOTICE | E_WARNING));
$this->smartyBC->clear_assign('blar'); $this->smartyBC->clear_assign('blar');
$this->assertEquals('foobar', $this->smartyBC->fetch('eval:{$foo}{$bar}{$blar}')); $this->assertEquals('foobar', $this->smartyBC->fetch('eval:{$foo}{$bar}{$blar}'));
} }
public function testSmarty2ArrayClearAssign() public function testSmarty2ArrayClearAssign()
{ {
$this->smartyBC->setErrorReporting(error_reporting() & ~(E_NOTICE | E_USER_NOTICE)); $this->smartyBC->setErrorReporting(error_reporting() & ~(E_NOTICE | E_USER_NOTICE | E_WARNING));
$this->smartyBC->clear_assign(array('blar', 'foo')); $this->smartyBC->clear_assign(array('blar', 'foo'));
$this->assertEquals('bar', $this->smartyBC->fetch('eval:{$foo}{$bar}{$blar}')); $this->assertEquals('bar', $this->smartyBC->fetch('eval:{$foo}{$bar}{$blar}'));
} }
@@ -36,7 +36,7 @@ class ClearAssignTest extends PHPUnit_Smarty
*/ */
public function testClearAssign() public function testClearAssign()
{ {
$this->smarty->setErrorReporting(error_reporting() & ~(E_NOTICE | E_USER_NOTICE)); $this->smarty->setErrorReporting(error_reporting() & ~(E_NOTICE | E_USER_NOTICE | E_WARNING));
$this->smarty->clearAssign('blar'); $this->smarty->clearAssign('blar');
$this->assertEquals('foobar', $this->smarty->fetch('eval:{$foo}{$bar}{$blar}')); $this->assertEquals('foobar', $this->smarty->fetch('eval:{$foo}{$bar}{$blar}'));
} }
@@ -46,7 +46,7 @@ class ClearAssignTest extends PHPUnit_Smarty
*/ */
public function testArrayClearAssign() public function testArrayClearAssign()
{ {
$this->smarty->setErrorReporting(error_reporting() & ~(E_NOTICE | E_USER_NOTICE)); $this->smarty->setErrorReporting(error_reporting() & ~(E_NOTICE | E_USER_NOTICE | E_WARNING));
$this->smarty->clearAssign(array('blar', 'foo')); $this->smarty->clearAssign(array('blar', 'foo'));
$this->assertEquals('bar', $this->smarty->fetch('eval:{$foo}{$bar}{$blar}')); $this->assertEquals('bar', $this->smarty->fetch('eval:{$foo}{$bar}{$blar}'));
} }
@@ -610,7 +610,7 @@ class CompileBlockExtendsTest extends PHPUnit_Smarty
* *
* @runInSeparateProcess * @runInSeparateProcess
* @preserveGlobalState disabled * @preserveGlobalState disabled
* * @group slow
*/ */
public function testCompileBlockGrandChildMustCompile_021_2() public function testCompileBlockGrandChildMustCompile_021_2()
{ {
@@ -645,7 +645,7 @@ class CompileBlockExtendsTest extends PHPUnit_Smarty
* *
* @runInSeparateProcess * @runInSeparateProcess
* @preserveGlobalState disabled * @preserveGlobalState disabled
* * @group slow
*/ */
public function testCompileBlockGrandChildMustCompile_021_3() public function testCompileBlockGrandChildMustCompile_021_3()
{ {
@@ -670,7 +670,7 @@ class CompileBlockExtendsTest extends PHPUnit_Smarty
* *
* @runInSeparateProcess * @runInSeparateProcess
* @preserveGlobalState disabled * @preserveGlobalState disabled
* * @group slow
*/ */
public function testCompileBlockGrandChildMustCompile_021_32() public function testCompileBlockGrandChildMustCompile_021_32()
{ {
@@ -692,6 +692,7 @@ class CompileBlockExtendsTest extends PHPUnit_Smarty
* *
* @runInSeparateProcess * @runInSeparateProcess
* @preserveGlobalState disabled * @preserveGlobalState disabled
* @group slow
*/ */
public function testCompileBlockGrandChildMustCompile_021_4() public function testCompileBlockGrandChildMustCompile_021_4()
{ {
@@ -716,6 +717,7 @@ class CompileBlockExtendsTest extends PHPUnit_Smarty
* *
* @runInSeparateProcess * @runInSeparateProcess
* @preserveGlobalState disabled * @preserveGlobalState disabled
* @group slow
*/ */
public function testCompileBlockGrandChildMustCompile_021_42() public function testCompileBlockGrandChildMustCompile_021_42()
{ {
@@ -44,7 +44,7 @@ class CompileForeachTest extends PHPUnit_Smarty
$this->smarty->assign('foo', $foo); $this->smarty->assign('foo', $foo);
} else { } else {
// unassigned $from parameter // unassigned $from parameter
$this->smarty->setErrorReporting(error_reporting() & ~(E_NOTICE | E_USER_NOTICE)); $this->smarty->setErrorReporting(error_reporting() & ~(E_NOTICE | E_USER_NOTICE | E_WARNING));
} }
$this->assertEquals($result, $this->smarty->fetch($file), "testForeach - {$code} - {$testName}"); $this->assertEquals($result, $this->smarty->fetch($file), "testForeach - {$code} - {$testName}");
@@ -210,6 +210,7 @@ class CompileInsertTest extends PHPUnit_Smarty
* test insert plugin caching 2 * test insert plugin caching 2
* @runInSeparateProcess * @runInSeparateProcess
* @preserveGlobalState disabled * @preserveGlobalState disabled
* @group slow
*/ */
public function testInsertPluginCaching3_2() public function testInsertPluginCaching3_2()
{ {
@@ -275,7 +275,7 @@ class PluginFunctionHtmlCheckboxesTest extends PHPUnit_Smarty
protected $_errors = array(); protected $_errors = array();
public function error_handler($errno, $errstr, $errfile, $errline, $errcontext) public function error_handler($errno, $errstr, $errfile, $errline, $errcontext = array())
{ {
$this->_errors[] = $errstr; $this->_errors[] = $errstr;
} }
@@ -369,7 +369,7 @@ class PluginFunctionHtmlOptionsTest extends PHPUnit_Smarty
protected $_errors = array(); protected $_errors = array();
public function error_handler($errno, $errstr, $errfile, $errline, $errcontext) public function error_handler($errno, $errstr, $errfile, $errline, $errcontext = array())
{ {
$this->_errors[] = $errstr; $this->_errors[] = $errstr;
} }
@@ -275,7 +275,7 @@ class PluginFunctionHtmlRadiosTest extends PHPUnit_Smarty
protected $_errors = array(); protected $_errors = array();
public function error_handler($errno, $errstr, $errfile, $errline, $errcontext) public function error_handler($errno, $errstr, $errfile, $errline, $errcontext = array())
{ {
$this->_errors[] = $errstr; $this->_errors[] = $errstr;
} }
@@ -297,7 +297,7 @@ class CompileFunctionTest extends PHPUnit_Smarty
*/ */
public function testExternalDefinedFunctionRecursion($text) public function testExternalDefinedFunctionRecursion($text)
{ {
$this->assertEquals('12345', $this->smarty->fetch('test_template_function_recursion2.tpl'), $text); $this->assertEquals('012345', $this->smarty->fetch('test_template_function_recursion2.tpl'), $text);
} }
/** /**
@@ -432,4 +432,13 @@ class CompileFunctionTest extends PHPUnit_Smarty
array("{function name=simple}A\n{\$foo}\nC{/function}{call name='simple'}", "A\nbar\nC", 'T15', $i++), array("{function name=simple}A\n{\$foo}\nC{/function}{call name='simple'}", "A\nbar\nC", 'T15', $i++),
); );
} }
/**
* Test handling of function names that are a security risk
* @expectedException SmartyCompilerException
*/
public function testIllegalFunctionName() {
$this->smarty->fetch('string:{function name=\'rce(){};echo "hi";function \'}{/function}');
}
} }
@@ -78,11 +78,13 @@ class ConstantsTest extends PHPUnit_Smarty
} }
public function testConstantsUndefined() public function testConstantsUndefined()
{ {
$this->smarty->setErrorReporting(E_ALL & ~E_WARNING & ~E_NOTICE);
$tpl = $this->smarty->createTemplate('string:{$smarty.const.MYCONSTANT2}'); $tpl = $this->smarty->createTemplate('string:{$smarty.const.MYCONSTANT2}');
$this->assertEquals("", $this->smarty->fetch($tpl)); $this->assertEquals("", $this->smarty->fetch($tpl));
} }
public function testConstantsUndefined2() public function testConstantsUndefined2()
{ {
$this->smarty->setErrorReporting(E_ALL & ~E_WARNING & ~E_NOTICE);
$tpl = $this->smarty->createTemplate('eval:{$foo = MYCONSTANT2}{$foo}'); $tpl = $this->smarty->createTemplate('eval:{$foo = MYCONSTANT2}{$foo}');
$this->assertEquals("MYCONSTANT2", $this->smarty->fetch($tpl)); $this->assertEquals("MYCONSTANT2", $this->smarty->fetch($tpl));
} }
@@ -35,7 +35,7 @@ class SmartyNowTest extends PHPUnit_Smarty
} }
/** /**
* test {$smarty.now nocache} * test {$smarty.now nocache}
* * @group slow
*/ */
public function testSmartyNowNocache() { public function testSmartyNowNocache() {
$this->smarty->setCaching(true); $this->smarty->setCaching(true);
@@ -59,7 +59,7 @@ class StreamVariableTest extends PHPUnit_Smarty
} }
*/ */
/** /**
* test no existant stream variable * test no existent stream variable
*/ */
// public function testStreamVariable2() // public function testStreamVariable2()
// { // {