Commit Graph

709 Commits

Author SHA1 Message Date
Nils Knappmeier 50e844b563 Merge branch '4.x'
# Conflicts:
#	components/bower.json
#	components/handlebars.js.nuspec
#	components/package.json
#	package.json
2019-10-22 00:02:19 +02:00
Nils Knappmeier a15d01d383 Merge branch '4.4.x' into 4.x 2019-10-22 00:00:18 +02:00
Nils Knappmeier 8e1cce7918 v4.4.5 2019-10-20 23:08:10 +02:00
Nils Knappmeier 2ab261eab7 v4.4.4 2019-10-20 21:33:00 +02:00
sohibe feb60f85c9 show source location for the strict lookup exceptions 2019-10-09 06:50:04 +02:00
Nils Knappmeier 566536b03d Merge branch '4.x'
# Conflicts:
#	components/bower.json
#	components/handlebars.js.nuspec
#	components/package.json
#	package-lock.json
#	package.json
2019-10-08 22:22:01 +02:00
Nils Knappmeier 2e53fba68f v4.4.3 2019-10-08 22:05:35 +02:00
Nils Knappmeier b793350fec v4.4.2 2019-10-02 22:44:36 +02:00
Nils Knappmeier b8e769fcb6 v4.4.1 2019-10-02 21:52:34 +02:00
Nils Knappmeier 059b330579 v4.4.0 2019-09-29 15:29:13 +02:00
antelle cf7545ef5a Added support for iterable objects in {{#each}} helper (#1557)
* Added support for iterable object in {{#each}} helper
Currently {{#each}} helper supports either arrays, or objects,
however nowadays you can define custom iterable objects by overriding
a special method called Symbol.iterator, which results in empty result
being rendered.
* improved a test for iterables in {{#each}} returning empty result
* #each helper: using ES5 instead of generator functions in tests
* #each helper: using ES5 in the helper itself
2019-09-29 14:57:47 +02:00
Nils Knappmeier c958cc8955 v4.3.4 2019-09-28 13:25:05 +02:00
Nils Knappmeier ff4d827c09 fix: harden "propertyIsEnumerable"-check
- "container" is an internal object that is most likely
  not accessible through templateing (unlike the proto of "Object", which might be.)
  In order to prevent overriding this method, we
  use "propertyIsEnumerable" from the constructor.
2019-09-28 10:36:49 +02:00
Nils Knappmeier e4738491b3 v4.3.3 2019-09-27 07:46:55 +02:00
Nils Knappmeier 2357140c68 v4.3.2 2019-09-26 23:58:48 +02:00
Nils Knappmeier 213c0bbe3c Use Object.prototype.propertyIsEnumerable to check for constructors
- context.propertyIsEnumerable can be replaced
  via __definedGetter__
- This is a fix specific to counter a known RCE exploit.
  Other fixes will follow.

closes #1563
2019-09-26 23:55:24 +02:00
Nils Knappmeier 050cca0866 v4.3.1 2019-09-25 00:32:32 +02:00
Nils Knappmeier 1266838829 do not break on precompiled templates from Handlebars >=4.0.0 <4.3.0
- The version-range above have compiler version 7 and
  precompiled templates expecte the (block)
  HelperMissing-functions in "helpers" and not in "container.hooks".
- Handlebars now accepts precompiled templates of version 7.
- If a precompiled template with version 7 is loaded,
  the (block)HelperMissing-functions are kept in "helpers"
2019-09-24 23:45:09 +02:00
Nils Knappmeier 25bae31578 Merge branch '4.x'
# Conflicts:
#	components/bower.json
#	components/handlebars.js.nuspec
#	components/package.json
#	lib/handlebars/runtime.js
#	package.json
2019-09-24 08:56:55 +02:00
Nils Knappmeier a89081d440 v4.3.0 2019-09-24 08:04:35 +02:00
Nils Knappmeier 06b7224ed9 adjust compiler revision 2019-09-24 07:31:19 +02:00
Nils Knappmeier 2078c727c6 Disallow calling "helperMissing" and "blockHelperMissing" directly
closes #1558
2019-09-24 07:31:19 +02:00
Nils Knappmeier fff3e40402 v4.2.1 2019-09-20 19:40:48 +02:00
Caleb Mazalevskis 00b4f2ff98 Fix some small typos. 2019-09-20 19:01:03 +02:00
Nils Knappmeier 35d3fdb1dd Merge branch '4.x'
# Conflicts:
#	components/bower.json
#	components/handlebars.js.nuspec
#	components/package.json
#	package-lock.json
#	package.json
2019-09-03 22:24:48 +02:00
Nils Knappmeier 164c7ceea4 v4.2.0 2019-09-03 21:58:07 +02:00
Andrew Leedham 133b96a2ff Add "Handlebars.VM.resolvePartial" to type definitions
- Handlebars.VM is actually not part of the API,
  but Handlebars.VM.resolvePartial is mentioned
  in the documentation and is thus now treated
  as part of the API.

Closes #1534
2019-09-03 21:33:35 +02:00
Nils Knappmeier f98c6a5425 v4.1.2-0 2019-08-25 18:06:35 +02:00
Nils Knappmeier 2f681d256f Merge branch '4.x'
# Conflicts:
#	components/bower.json
#	components/handlebars.js.nuspec
#	components/package.json
#	package.json
2019-04-13 16:48:27 +02:00
Nils Knappmeier 10b5fcf92e v4.1.2 2019-04-13 16:19:22 +02:00
Nils Knappmeier cd38583216 fix: prevent RCE through the "lookup"-helper
- The "lookup" helper could also be used to run a remote code execution
  by manipulating the template. The same check as for regular
  path queries now also is done in the "lookup"-helper
2019-04-11 23:08:57 +02:00
Timothy Lindvall 3fb6687013 Port over linting and test for typings
- Move typings from lib/ to types/.
- Add dtslint for validating types.
- Use grunt-bg-shell to call out to dtslint during build step.
2019-03-19 16:07:05 -07:00
Nils Knappmeier f691db546e v4.1.1 2019-03-16 22:28:38 +01:00
Qiang Li 445ae12fa4 deprecate substr method and use existing strip function in grammar 2019-03-13 14:24:19 -07:00
Nils Knappmeier 048f2ce7d2 refactor: replace "async" with "neo-async"
The main reason is that neo-async takes a lot less space due to the missing lodash-dependency.
The other is speed.

closes #1431
2019-02-18 19:26:38 +01:00
Nils Knappmeier f349aa43c0 Merge branch '4.x'
# Conflicts:
#	components/bower.json
#	components/handlebars.js.nuspec
#	components/package.json
#	package.json
2019-02-07 11:06:49 +01:00
Nils Knappmeier 7caca944b1 v4.1.0 2019-02-07 10:46:32 +01:00
Nils Knappmeier edc6220d51 fix: disallow access to the constructor in templates to prevent RCE
This commit fixes a Remote Code Execution (RCE) reported by
npm-security. Access to non-enumerable "constructor"-properties
is now prohibited by the compiled template-code, because this
the first step on the way to creating and execution arbitrary
JavaScript code.
The vulnerability affects systems where an attacker is allowed to
inject templates into the Handlebars setup.
Further details of the attack may be disclosed by npm-security.

Closes #1267
Closes #1495
2019-02-07 08:49:41 +01:00
Nils Knappmeier 920bf1c5ad Merge branch '4.x' 2019-01-02 01:09:10 +01:00
Timothy Lindvall 27ac1ee396 Feat: Import TypeScript typings
- Import typings from DefinitelyTyped into repo.
- Update typings header to cite contributors from history and git blame.
- Update package.json to add typings field.
2018-12-21 23:27:58 +01:00
Nils Knappmeier 379172e236 Merge branch '4.x' 2018-09-04 20:57:30 +02:00
Nils Knappmeier 8d22e6f501 v4.0.12 2018-09-04 20:44:38 +02:00
Nils Knappmeier 8359722e5d style: omit linting error caused by removing "if" 2018-09-04 00:16:01 +02:00
Qiang Li 0ddff8b388 unnecessary check
(cherry picked from commit e1fa310)
2018-05-31 23:16:26 +02:00
Qiang Li e1fa310101 unnecessary check 2018-03-31 08:22:20 +02:00
Nils Knappmeier f21f900cf5 Merge branch '4.x'
# Conflicts:
#	.eslintrc.js
#	lib/precompiler.js
#	package.json
#	release-notes.md
2017-11-09 10:42:54 +01:00
tim d3d39423a3 upgrade uglify-js 2017-10-21 23:04:23 +02:00
Nils Knappmeier 7729aa956b Update grunt-eslint to 20.1.0 2017-10-21 15:42:27 +02:00
Nils Knappmeier 1e954ddf3c v4.0.11 2017-10-17 22:52:25 +02:00
Nils Knappmeier 79309659e1 Gracefully handle missing uglify-js dependency
closes #1391

uglify-js is an optional dependency and should be treated as such.
This commit gracefully handles MODULE_NOT_FOUND errors while loading
uglify.

- Check for existing uglify-js (and load uglify-js) only if minification
  was activated
- Use "require.resolve" to check if uglify exists. Otherwise, a missing
  dependency of uglify-js would cause the same behavior as missing
  uglify-js. (Only a warning, no error)
- The code to load and run uglify is put into a single for readability
  purposes
- Tests use a mockup Module._resolveFilename to simulate the missing module.
  This function is used by both "require" and "require.resolve", so both
  are mocked equally.

(cherry picked from commit d5caa56)
2017-10-17 22:18:56 +02:00