Commit Graph

700 Commits

Author SHA1 Message Date
Nils Knappmeier 14ba3d0c43 v4.7.1 2020-01-12 13:21:08 +01:00
Nils Knappmeier f152dfc892 fix: fix log output in case of illegal property access
- fix link url to handlebarsjs.com
2020-01-12 13:09:19 +01:00
Nils Knappmeier 3c1e252169 fix: log error for illegal property access only once per property 2020-01-12 13:06:56 +01:00
Nils Knappmeier 0d5c807017 v4.7.0 2020-01-10 17:24:06 +01:00
Nils Knappmeier 575d8772e2 fix: use "logger" instead of console.error
... to be graceful with older browser without "console"
2020-01-10 17:06:57 +01:00
Nils Knappmeier 7af1c12db6 feat: default options for controlling proto access
This commmit adds the runtime options
- `allowProtoPropertiesByDefault` (boolean, default: false) and
- `allowProtoMethodsByDefault` (boolean, default: false)`
which can be used to allow access to prototype properties and
functions in general.

Specific properties and methods can still be disabled from access
via `allowedProtoProperties` and `allowedProtoMethods` by
setting the corresponding values to false.

The methods `constructor`, `__defineGetter__`, `__defineSetter__`, `__lookupGetter__`
and the property `__proto__` will be disabled, even if the allow...ByDefault-options
are set to true. In order to allow access to those properties and methods, they have
to be explicitly set to true in the 'allowedProto...'-options.

A warning is logged when the a proto-access it attempted and denied
by default (i.e. if no option is set by the user to make the access
decision explicit)
2020-01-10 16:55:45 +01:00
Nils Knappmeier 91a1b5d2f4 v4.6.0 2020-01-08 23:45:15 +01:00
Nils Knappmeier d03b6ecfc4 feat: access control to prototype properties via whitelist
Disallow access to prototype properties and methods by default.
Access to properties is always checked via
`Object.prototype.hasOwnProperty.call(parent, propertyName)`.

New runtime options:
- **allowedProtoMethods**: a string-to-boolean map of property-names that are allowed if they are methods of the parent object.
- **allowedProtoProperties**: a string-to-boolean map of property-names that are allowed if they are properties but not methods of the parent object.

```js
const template = handlebars.compile('{{aString.trim}}')
const result = template({ aString: '  abc  ' })
// result is empty, because trim is defined at String prototype
```

```js
const template = handlebars.compile('{{aString.trim}}')
const result = template({ aString: '  abc  ' }, {
  allowedProtoMethods: {
    trim: true
  }
})
// result = 'abc'
```

Implementation details: The method now "container.lookupProperty"
handles the prototype-checks and the white-lists. It is used in
- JavaScriptCompiler#nameLookup
- The "lookup"-helper (passed to all helpers as "options.lookupProperty")
- The "lookup" function at the container, which is used for recursive lookups in "compat" mode

Compatibility:
- **Old precompiled templates work with new runtimes**: The "options.lookupPropery"-function is passed to the helper by a wrapper, not by the compiled templated.
- **New templates work with old runtimes**: The template contains a function that is used as fallback if the "lookupProperty"-function cannot be found at the container. However, the runtime-options "allowedProtoProperties" and "allowedProtoMethods" only work with the newest runtime.

BREAKING CHANGE:
- access to prototype properties is forbidden completely by default
2020-01-08 23:17:23 +01:00
Nils Knappmeier e97685e989 style: reformat all files using prettier 2019-12-03 22:37:15 +01:00
ole-martin 23d58e79bb fix(runtime.js): partials compile not caching (#1600)
Reintroduce "merge" function, no called "mergeIfNeeded", that only creates a new partials
object if both "env.partials" and "options.partials" are set.

closes #1598
2019-11-18 21:21:03 +01:00
Nils Knappmeier c819c8b533 v4.5.3 2019-11-18 08:10:26 +01:00
Nils Knappmeier f7f05d7558 fix: add "no-prototype-builtins" eslint-rule and fix all occurences 2019-11-18 07:33:45 +01:00
Nils Knappmeier 1988878087 fix: add more properties required to be enumerable
- __defineGetter__, __defineSetter__, __lookupGetter__, __proto__
2019-11-18 07:33:45 +01:00
Nils Knappmeier 8de121d21c v4.5.2 2019-11-13 22:07:27 +01:00
Nils Knappmeier d54137810a fix: use String(field) in lookup when checking for "constructor"
closes #1603
2019-11-13 22:02:05 +01:00
Nils Knappmeier 7ef86173ab v4.5.1 2019-10-29 05:42:23 +01:00
Nils Knappmeier b24797da01 v4.5.0 2019-10-28 19:47:51 +01:00
Robert Jackson 62ed3c25c7 Add Handlebars.parseWithoutProcessing (#1584)
When authoring tooling that parses Handlebars files and emits Handlebars
files, you often want to preserve the **exact** formatting of the input.
The changes in this commit add a new method to the `Handlebars`
namespace: `parseWithoutProcessing`. Unlike, `Handlebars.parse` (which
will mutate the parsed AST to apply whitespace control) this method will
parse the template and return it directly (**without** processing
😉).

For example, parsing the following template:

```hbs
 {{#foo}}
   {{~bar~}} {{baz~}}
 {{/foo}}
```

Using `Handlebars.parse`, the AST returned would have truncated the
following whitespace:

* The whitespace prior to the `{{#foo}}`
* The newline following `{{#foo}}`
* The leading whitespace before `{{~bar~}}`
* The whitespace between `{{~bar~}}` and `{{baz~}}`
* The newline after `{{baz~}}`
* The whitespace prior to the `{{/foo}}`

When `Handlebars.parse` is used from  `Handlebars.precompile` or
`Handlebars.compile`, this whitespace stripping is **very** important
(these behaviors are intentional, and generally lead to better rendered
output).

When the same template is parsed with
`Handlebars.parseWithoutProcessing` none of those modifications to the
AST are made. This enables "codemod tooling" (e.g. `prettier` and
`ember-template-recast`) to preserve the **exact** initial formatting.
Prior to these changes, those tools would have to _manually_ reconstruct
the whitespace that is lost prior to emitting source.
2019-10-28 00:28:28 +01:00
kpdecker 7fcf9d24f8 Use objects for hash value tracking
The use of arrays was incorrect for the data type and causing problems when hash keys conflicted with array behaviors.

Fixes #1194

(cherry picked from commit 768ddbd661)
2019-10-27 17:27:37 +01:00
Hannah Wolfe c76ded8f0f fix: add guard to if & unless helpers (#1549)
fixes #1548

- add a guard to show readable syntax error for if / unless helper
- prevents against 3 different errors that can be generated by different systax errors
2019-10-27 15:41:35 +01:00
Nils Knappmeier a15d01d383 Merge branch '4.4.x' into 4.x 2019-10-22 00:00:18 +02:00
Nils Knappmeier 8e1cce7918 v4.4.5 2019-10-20 23:08:10 +02:00
Nils Knappmeier 2ab261eab7 v4.4.4 2019-10-20 21:33:00 +02:00
sohibe feb60f85c9 show source location for the strict lookup exceptions 2019-10-09 06:50:04 +02:00
Nils Knappmeier 2e53fba68f v4.4.3 2019-10-08 22:05:35 +02:00
Nils Knappmeier b793350fec v4.4.2 2019-10-02 22:44:36 +02:00
Nils Knappmeier b8e769fcb6 v4.4.1 2019-10-02 21:52:34 +02:00
Nils Knappmeier 059b330579 v4.4.0 2019-09-29 15:29:13 +02:00
antelle cf7545ef5a Added support for iterable objects in {{#each}} helper (#1557)
* Added support for iterable object in {{#each}} helper
Currently {{#each}} helper supports either arrays, or objects,
however nowadays you can define custom iterable objects by overriding
a special method called Symbol.iterator, which results in empty result
being rendered.
* improved a test for iterables in {{#each}} returning empty result
* #each helper: using ES5 instead of generator functions in tests
* #each helper: using ES5 in the helper itself
2019-09-29 14:57:47 +02:00
Nils Knappmeier c958cc8955 v4.3.4 2019-09-28 13:25:05 +02:00
Nils Knappmeier ff4d827c09 fix: harden "propertyIsEnumerable"-check
- "container" is an internal object that is most likely
  not accessible through templateing (unlike the proto of "Object", which might be.)
  In order to prevent overriding this method, we
  use "propertyIsEnumerable" from the constructor.
2019-09-28 10:36:49 +02:00
Nils Knappmeier e4738491b3 v4.3.3 2019-09-27 07:46:55 +02:00
Nils Knappmeier 2357140c68 v4.3.2 2019-09-26 23:58:48 +02:00
Nils Knappmeier 213c0bbe3c Use Object.prototype.propertyIsEnumerable to check for constructors
- context.propertyIsEnumerable can be replaced
  via __definedGetter__
- This is a fix specific to counter a known RCE exploit.
  Other fixes will follow.

closes #1563
2019-09-26 23:55:24 +02:00
Nils Knappmeier 050cca0866 v4.3.1 2019-09-25 00:32:32 +02:00
Nils Knappmeier 1266838829 do not break on precompiled templates from Handlebars >=4.0.0 <4.3.0
- The version-range above have compiler version 7 and
  precompiled templates expecte the (block)
  HelperMissing-functions in "helpers" and not in "container.hooks".
- Handlebars now accepts precompiled templates of version 7.
- If a precompiled template with version 7 is loaded,
  the (block)HelperMissing-functions are kept in "helpers"
2019-09-24 23:45:09 +02:00
Nils Knappmeier a89081d440 v4.3.0 2019-09-24 08:04:35 +02:00
Nils Knappmeier 06b7224ed9 adjust compiler revision 2019-09-24 07:31:19 +02:00
Nils Knappmeier 2078c727c6 Disallow calling "helperMissing" and "blockHelperMissing" directly
closes #1558
2019-09-24 07:31:19 +02:00
Nils Knappmeier fff3e40402 v4.2.1 2019-09-20 19:40:48 +02:00
Caleb Mazalevskis 00b4f2ff98 Fix some small typos. 2019-09-20 19:01:03 +02:00
Nils Knappmeier 164c7ceea4 v4.2.0 2019-09-03 21:58:07 +02:00
Andrew Leedham 133b96a2ff Add "Handlebars.VM.resolvePartial" to type definitions
- Handlebars.VM is actually not part of the API,
  but Handlebars.VM.resolvePartial is mentioned
  in the documentation and is thus now treated
  as part of the API.

Closes #1534
2019-09-03 21:33:35 +02:00
Nils Knappmeier f98c6a5425 v4.1.2-0 2019-08-25 18:06:35 +02:00
Nils Knappmeier 10b5fcf92e v4.1.2 2019-04-13 16:19:22 +02:00
Nils Knappmeier cd38583216 fix: prevent RCE through the "lookup"-helper
- The "lookup" helper could also be used to run a remote code execution
  by manipulating the template. The same check as for regular
  path queries now also is done in the "lookup"-helper
2019-04-11 23:08:57 +02:00
Timothy Lindvall 3fb6687013 Port over linting and test for typings
- Move typings from lib/ to types/.
- Add dtslint for validating types.
- Use grunt-bg-shell to call out to dtslint during build step.
2019-03-19 16:07:05 -07:00
Nils Knappmeier f691db546e v4.1.1 2019-03-16 22:28:38 +01:00
Qiang Li 445ae12fa4 deprecate substr method and use existing strip function in grammar 2019-03-13 14:24:19 -07:00
Nils Knappmeier 048f2ce7d2 refactor: replace "async" with "neo-async"
The main reason is that neo-async takes a lot less space due to the missing lodash-dependency.
The other is speed.

closes #1431
2019-02-18 19:26:38 +01:00