Commit Graph

1775 Commits

Author SHA1 Message Date
Nils Knappmeier 14ba3d0c43 v4.7.1 v4.7.1 2020-01-12 13:21:08 +01:00
Nils Knappmeier 4cddfe7017 Update release notes 2020-01-12 13:20:37 +01:00
Nils Knappmeier f152dfc892 fix: fix log output in case of illegal property access
- fix link url to handlebarsjs.com
2020-01-12 13:09:19 +01:00
Nils Knappmeier 3c1e252169 fix: log error for illegal property access only once per property 2020-01-12 13:06:56 +01:00
Nils Knappmeier 0d5c807017 v4.7.0 v4.7.0 2020-01-10 17:24:06 +01:00
Nils Knappmeier 1f0834b1a2 Update release notes 2020-01-10 17:23:31 +01:00
Nils Knappmeier 575d8772e2 fix: use "logger" instead of console.error
... to be graceful with older browser without "console"
2020-01-10 17:06:57 +01:00
Nils Knappmeier 7af1c12db6 feat: default options for controlling proto access
This commmit adds the runtime options
- `allowProtoPropertiesByDefault` (boolean, default: false) and
- `allowProtoMethodsByDefault` (boolean, default: false)`
which can be used to allow access to prototype properties and
functions in general.

Specific properties and methods can still be disabled from access
via `allowedProtoProperties` and `allowedProtoMethods` by
setting the corresponding values to false.

The methods `constructor`, `__defineGetter__`, `__defineSetter__`, `__lookupGetter__`
and the property `__proto__` will be disabled, even if the allow...ByDefault-options
are set to true. In order to allow access to those properties and methods, they have
to be explicitly set to true in the 'allowedProto...'-options.

A warning is logged when the a proto-access it attempted and denied
by default (i.e. if no option is set by the user to make the access
decision explicit)
2020-01-10 16:55:45 +01:00
Nils Knappmeier 91a1b5d2f4 v4.6.0 v4.6.0 2020-01-08 23:45:15 +01:00
Nils Knappmeier 770d746e60 Update release notes 2020-01-08 23:44:46 +01:00
Nils Knappmeier d7f0dcf2bb refactor: fix typo in private test method 2020-01-08 23:17:23 +01:00
Nils Knappmeier 187d611e8c test: add path to nodeJs when running test:bin
- this allows the test to be run in a debugger
  without the complete PATH
2020-01-08 23:17:23 +01:00
Nils Knappmeier d337f40d0e test: show diff when test:bin fails 2020-01-08 23:17:23 +01:00
Nils Knappmeier d03b6ecfc4 feat: access control to prototype properties via whitelist
Disallow access to prototype properties and methods by default.
Access to properties is always checked via
`Object.prototype.hasOwnProperty.call(parent, propertyName)`.

New runtime options:
- **allowedProtoMethods**: a string-to-boolean map of property-names that are allowed if they are methods of the parent object.
- **allowedProtoProperties**: a string-to-boolean map of property-names that are allowed if they are properties but not methods of the parent object.

```js
const template = handlebars.compile('{{aString.trim}}')
const result = template({ aString: '  abc  ' })
// result is empty, because trim is defined at String prototype
```

```js
const template = handlebars.compile('{{aString.trim}}')
const result = template({ aString: '  abc  ' }, {
  allowedProtoMethods: {
    trim: true
  }
})
// result = 'abc'
```

Implementation details: The method now "container.lookupProperty"
handles the prototype-checks and the white-lists. It is used in
- JavaScriptCompiler#nameLookup
- The "lookup"-helper (passed to all helpers as "options.lookupProperty")
- The "lookup" function at the container, which is used for recursive lookups in "compat" mode

Compatibility:
- **Old precompiled templates work with new runtimes**: The "options.lookupPropery"-function is passed to the helper by a wrapper, not by the compiled templated.
- **New templates work with old runtimes**: The template contains a function that is used as fallback if the "lookupProperty"-function cannot be found at the container. However, the runtime-options "allowedProtoProperties" and "allowedProtoMethods" only work with the newest runtime.

BREAKING CHANGE:
- access to prototype properties is forbidden completely by default
2020-01-08 23:17:23 +01:00
Nils Knappmeier 164b7ff0de chore: ignore .nyc_output 2019-12-14 18:41:06 +01:00
Nils Knappmeier ac4655ee95 chore: disable "dot-notation" rule
- I don't think it makes much sense. In some cases,
  it is more readable to wrap property access in quotes,
  some times not, but there is no universal rule
  for that.
- a promises "catch"-function should not be wrapped, but it has to
  be, if "allow-keywords" is set to false
- an "if"-helper should be wrapped, but it is not allowed to be
  if "allow-keywords" is set to true (default).
2019-12-14 18:41:06 +01:00
Nils Knappmeier 14b621caf5 test/style: remove or hide unused code in git.js, add tests 2019-12-14 18:41:06 +01:00
Nils Knappmeier 1ec1737d24 test/style: refactor remaining grunt tasks to use promises instead of callbacks 2019-12-14 18:41:06 +01:00
Nils Knappmeier 1ebce2b53c test/style: use nyc instead of istanbul, npm audit fix 2019-12-14 18:41:06 +01:00
Nils Knappmeier 3a5b65e02b test/style: refactor parser task 2019-12-14 18:41:06 +01:00
Nils Knappmeier dde108e283 test/style: refactor test-task to make it more readable 2019-12-14 18:41:06 +01:00
Nils Knappmeier dc5495216d chore: change eslint-rules for tasks/
- use es2017 rules as NodeJS supports it today
- add "prefer-const"
2019-12-14 18:41:06 +01:00
Marcos Marado d1fb07b32b Update (C) year in the LICENSE file
Welcome to 2019!
2019-12-08 16:21:38 +01:00
Nils Knappmeier 04b19848cc chore: try to fix saucelabs credentials (#1627) 2019-12-08 16:17:15 +01:00
Nils Knappmeier c40d9f33ad chore: active linting and formatting on commit 2019-12-05 08:01:33 +01:00
Nils Knappmeier 8901c28e9a chore: fix task name in build 2019-12-03 22:59:04 +01:00
Nils Knappmeier e97685e989 style: reformat all files using prettier 2019-12-03 22:37:15 +01:00
Nils Knappmeier e913dc5f12 chore: restructure build commands
- move dtslint (checkTypes) away from Gruntfile.js
  (as it disturbs debugging `grunt`)
  and call it directly as npm-script in travis-ci
- re-group task definition in Gruntfile.js
- use a multi-job travis build to
  run linting, format, dtslint and tests
  in parallel
- run only "npm test" on appveyor
- rename Grunt-tasks for be more descriptive
- SAUCE_USERNAME is not a secret variable anymore
  it can be easily guessed anyway and the
  [secure] value messes up with a lot of the
  log output

- linting on commit disable during transition
2019-12-03 22:21:30 +01:00
Nils Knappmeier 1f61f21250 chore: configure prettier and eslint
- add prettier to do formatting
- add eslint-config-prettier to
  disable rules conflicting with prettier
- remove eslint from grunt workflow
- use lint-stage to lint and format
  on precommit
- use eslint and prettier in travis directly
- remove rules that are already part of
  the "recommended" ruleset

That rational is that eslint and prettier should be run in
Travis-CI, on commit and as IDE integration (highlighting
errors directlry). They don't need to be run along with
test-cases. Getting linting errors when running the tests
because of missing semicolons is just annoying, but doesn't
help the overall code-quality.
2019-12-02 22:40:05 +01:00
Nils Knappmeier 587e7a3e63 remove yarn.lock 2019-12-02 22:40:04 +01:00
ole-martin edcc84f292 Update readme.md with updated links (#1620)
* Update readme.md with updated links

Fix http->https where possible and update links doc links

* Update README.markdown

* Fix precompilation link
2019-12-02 22:03:52 +01:00
ole-martin 23d58e79bb fix(runtime.js): partials compile not caching (#1600)
Reintroduce "merge" function, no called "mergeIfNeeded", that only creates a new partials
object if both "env.partials" and "options.partials" are set.

closes #1598
2019-11-18 21:21:03 +01:00
Nils Knappmeier c819c8b533 v4.5.3 v4.5.3 2019-11-18 08:10:26 +01:00
Nils Knappmeier 827c9d0747 Update release notes 2019-11-18 08:09:48 +01:00
Nils Knappmeier f7f05d7558 fix: add "no-prototype-builtins" eslint-rule and fix all occurences 2019-11-18 07:33:45 +01:00
Nils Knappmeier 1988878087 fix: add more properties required to be enumerable
- __defineGetter__, __defineSetter__, __lookupGetter__, __proto__
2019-11-18 07:33:45 +01:00
Nils Knappmeier 886ba86c2f test/chore: add chai/expect and sinon to "runtime"-environment 2019-11-17 22:18:20 +01:00
Nils Knappmeier 0817dad7e7 test: add sinon as global variable to eslint in the specs 2019-11-15 17:22:29 +01:00
Nils Knappmeier 93516a0b07 test: add sinon.js for spies, deprecate current assertions
- the goal is to get overall cleaner test.
- chai and sinon are standard libraries for testing
  assertions and spies. We should not use custom ones.
2019-11-15 16:38:28 +01:00
Nils Knappmeier 93e284ed9b chore: add chai and dirty-chai for better test assertions 2019-11-15 16:38:28 +01:00
Nils Knappmeier c02b05fa81 fix: use !== 0 instead of != 0 2019-11-15 16:38:28 +01:00
Nils Knappmeier 8de121d21c v4.5.2 v4.5.2 2019-11-13 22:07:27 +01:00
Nils Knappmeier 6914090086 Update release notes 2019-11-13 22:06:51 +01:00
Nils Knappmeier d54137810a fix: use String(field) in lookup when checking for "constructor"
closes #1603
2019-11-13 22:02:05 +01:00
Nils Knappmeier c2ac79c970 test: add fluent API for testing Handlebars
use "expectTemplate(template)....toCompileTo(output)"
2019-11-13 22:02:05 +01:00
Nils Knappmeier 7ef86173ab v4.5.1 v4.5.1 2019-10-29 05:42:23 +01:00
Nils Knappmeier b75e3e1f40 Update release notes 2019-10-29 05:41:43 +01:00
Nils Knappmeier 5e9d17f8fa fix: move "eslint-plugin-compat" to devDependencies 2019-10-29 05:17:03 +01:00
Nils Knappmeier b24797da01 v4.5.0 v4.5.0 2019-10-28 19:47:51 +01:00
Nils Knappmeier a243067883 Update release notes 2019-10-28 19:47:08 +01:00