Commit Graph

370 Commits

Author SHA1 Message Date
Nils Knappmeier e97685e989 style: reformat all files using prettier 2019-12-03 22:37:15 +01:00
Nils Knappmeier f7f05d7558 fix: add "no-prototype-builtins" eslint-rule and fix all occurences 2019-11-18 07:33:45 +01:00
Nils Knappmeier 1988878087 fix: add more properties required to be enumerable
- __defineGetter__, __defineSetter__, __lookupGetter__, __proto__
2019-11-18 07:33:45 +01:00
Robert Jackson 62ed3c25c7 Add Handlebars.parseWithoutProcessing (#1584)
When authoring tooling that parses Handlebars files and emits Handlebars
files, you often want to preserve the **exact** formatting of the input.
The changes in this commit add a new method to the `Handlebars`
namespace: `parseWithoutProcessing`. Unlike, `Handlebars.parse` (which
will mutate the parsed AST to apply whitespace control) this method will
parse the template and return it directly (**without** processing
😉).

For example, parsing the following template:

```hbs
 {{#foo}}
   {{~bar~}} {{baz~}}
 {{/foo}}
```

Using `Handlebars.parse`, the AST returned would have truncated the
following whitespace:

* The whitespace prior to the `{{#foo}}`
* The newline following `{{#foo}}`
* The leading whitespace before `{{~bar~}}`
* The whitespace between `{{~bar~}}` and `{{baz~}}`
* The newline after `{{baz~}}`
* The whitespace prior to the `{{/foo}}`

When `Handlebars.parse` is used from  `Handlebars.precompile` or
`Handlebars.compile`, this whitespace stripping is **very** important
(these behaviors are intentional, and generally lead to better rendered
output).

When the same template is parsed with
`Handlebars.parseWithoutProcessing` none of those modifications to the
AST are made. This enables "codemod tooling" (e.g. `prettier` and
`ember-template-recast`) to preserve the **exact** initial formatting.
Prior to these changes, those tools would have to _manually_ reconstruct
the whitespace that is lost prior to emitting source.
2019-10-28 00:28:28 +01:00
kpdecker 7fcf9d24f8 Use objects for hash value tracking
The use of arrays was incorrect for the data type and causing problems when hash keys conflicted with array behaviors.

Fixes #1194

(cherry picked from commit 768ddbd661)
2019-10-27 17:27:37 +01:00
sohibe feb60f85c9 show source location for the strict lookup exceptions 2019-10-09 06:50:04 +02:00
Nils Knappmeier ff4d827c09 fix: harden "propertyIsEnumerable"-check
- "container" is an internal object that is most likely
  not accessible through templateing (unlike the proto of "Object", which might be.)
  In order to prevent overriding this method, we
  use "propertyIsEnumerable" from the constructor.
2019-09-28 10:36:49 +02:00
Nils Knappmeier 213c0bbe3c Use Object.prototype.propertyIsEnumerable to check for constructors
- context.propertyIsEnumerable can be replaced
  via __definedGetter__
- This is a fix specific to counter a known RCE exploit.
  Other fixes will follow.

closes #1563
2019-09-26 23:55:24 +02:00
Nils Knappmeier 2078c727c6 Disallow calling "helperMissing" and "blockHelperMissing" directly
closes #1558
2019-09-24 07:31:19 +02:00
Caleb Mazalevskis 00b4f2ff98 Fix some small typos. 2019-09-20 19:01:03 +02:00
Qiang Li 445ae12fa4 deprecate substr method and use existing strip function in grammar 2019-03-13 14:24:19 -07:00
Nils Knappmeier 42841c41a4 fix: disallow access to the constructor in templates to prevent RCE
This commit fixes a Remote Code Execution (RCE) reported by
npm-security. Access to non-enumerable "constructor"-properties
is now prohibited by the compiled template-code, because this
the first step on the way to creating and execution arbitrary
JavaScript code.
The vulnerability affects systems where an attacker is allowed to
inject templates into the Handlebars setup.
Further details of the attack may be disclosed by npm-security.

Closes #1267
Closes #1495
2019-02-07 10:19:53 +01:00
Nils Knappmeier 8359722e5d style: omit linting error caused by removing "if" 2018-09-04 00:16:01 +02:00
Qiang Li 0ddff8b388 unnecessary check
(cherry picked from commit e1fa310)
2018-05-31 23:16:26 +02:00
Nils Knappmeier 7729aa956b Update grunt-eslint to 20.1.0 2017-10-21 15:42:27 +02:00
Nils Knappmeier 0e953d1db5 Replace "Object.assign" (not support in IE) by "util/extend" 2017-05-21 14:02:35 +02:00
Nils Knappmeier 8a836e2272 Handlebars.compile() does not modify "options" anymore
Fixes #1327

- This commit creates a shallow copy of the "options" passed to
  Handlebars.compile() in order to prevent modifications
- Note that "new Handlebars.Compiler().compile(..., options)" still
  modify the options object. This might change in the future, if
  anybody needs a fix for that.
2017-05-21 13:20:48 +02:00
Nils Knappmeier c8f4b570c1 Fix context-stack when calling block-helpers on null values
Fixes #1319

Original behaviour:
- When a block-helper was called on a null-context, an empty object was used
  as context instead. (#1093)
- The runtime verifies that whether the current context equals the
  last context and adds the current context to the stack, if it is not.
  This is done, so that inside a block-helper, the ".." path can be used
  to go back to the parent element.
- If the helper is called on a "null" element, the context was added, even
  though it shouldn't be, because the "null != {}"

Fix:
- The commit replaces "null" by the identifiable "container.nullContext"
  instead of "{}". "nullContext" is a sealed empty object.
- An additional check in the runtime verifies that the context is
  only added to the stack, if it is not the nullContext.

Backwards compatibility within 4.0.x-versions:
- This commit changes the compiler and compiled templates would not work
  with runtime-versions 4.0.0 - 4.0.6, because of the "nullContext"
  property. That's way, the compiled code reads
  "(container.nullContext || {})" so that the behavior will degrade
  gracefully with older runtime versions: Everything else will work
  fine, but GH-1319 will still be broken, if you use a newer compiler
  with a pre 4.0.7 runtime.
2017-03-25 15:00:58 +01:00
Charles O'Farrell 8ff49cef52 Ensure that existing blockParams and depths are respected on dupe programs
Fixes #1186
2016-11-11 12:01:16 -06:00
kpdecker 9f59de9657 Fix lint errors under latest eslint 2015-10-31 13:32:43 -05:00
kpdecker fffb5a985f Fix iteration over undefined values
Allow for iteration on undefined values, but special case undefined and null to prevent rendering errors when not running in strict mode.

Fixes #1093
2015-09-23 21:17:57 -05:00
kpdecker 05b82a203e Fix failure when using decorators in partials 2015-09-02 20:43:54 -05:00
kpdecker 0aef72cb8e Update to latest eslint 2015-09-01 17:56:32 -05:00
kpdecker b63d74a7b3 Add explicitPartialContext compiler flag
Fixes #1032
2015-09-01 01:05:00 -05:00
kpdecker 452afbf2ff Implement block decorators
These allow for a given block to be wrapped in helper methods or metadata and allow for more control over the current container and method before the code is run.
2015-08-22 10:59:34 -07:00
kpdecker 408192ba9f Add decorator parsing 2015-08-22 10:59:34 -07:00
kpdecker 0b5e82e1c3 Add whitespace control to partial block statements 2015-08-22 10:59:08 -07:00
kpdecker 233caf3f7c Create validateClose helper method
Avoid duplicating the logic needed to check for close block mismatches.
2015-08-22 10:59:08 -07:00
kpdecker 91ffd32cad Implement partial blocks
This allows for failover for missing partials as well as limited templating ability through the `{{> @partial-block }}` partial special case.

Partial fix for #1018
2015-08-22 10:59:08 -07:00
kpdecker 2571dd8e8e Improve sanity checks in compiler and visitor 2015-08-22 10:58:44 -07:00
kpdecker 95d84badca Drop AST constructors in favor of JSON
These were little more than object literal statements that were less clear due to their use of index-based arguments.

Fixes #1077
2015-08-18 23:57:27 -07:00
kpdecker 9a2d1d6009 Pass container rather than exec as context
There is no real need for us to do `.call(container` other than for backwards compatibility with legacy versions. Using the 4.x release as a chance to optimize this behavior.
2015-08-18 23:54:04 -07:00
kpdecker 08093d72f0 Remove unused parameters 2015-08-18 23:14:09 -07:00
kpdecker ea3a5a1eb6 Add ignoreStandalone compiler option
Fixes #1072
2015-08-13 01:51:17 -05:00
kpdecker 93b07605cd Bulletproof AST.helpers.helperExpression
Avoid undefined values and potential false positives from other type values such as partials.

Fixes #1055
2015-08-03 20:31:57 -05:00
kpdecker 85750f8d0a Use += in printer 2015-08-03 18:51:46 -05:00
kpdecker 324d615726 Enforce 100% code coverage 2015-08-03 17:49:47 -05:00
kpdecker 5d4b8da344 Pass undefined fields to helpers in strict mode
This allows for `{{helper foo}}` to still operate under strict mode when `foo` is not defined on the context. This allows helpers to perform whatever existence checks they please so patterns like `{{#if foo}}{{foo}}{{/if}}` can be used to protect against missing values.

Fixes #1063
2015-08-03 15:59:53 -05:00
kpdecker 9f265b9761 Handle this references properly in track id mode 2015-08-03 12:13:24 -05:00
kpdecker efddc3c09c Increase code coverage 2015-08-01 22:01:16 -05:00
kpdecker 410141c31e Fix escaping of non-javascript identifiers
The ‘ character would cause invalid javascript to be generated as it was not properly escaped. Switching to JSON.stringify safely handles all potential unescaped cases.
2015-08-01 15:48:28 -05:00
Eric Nielsen 868ef4b309 #1056 Fixed grammar for nested raw blocks 2015-07-15 14:45:43 -03:00
kpdecker 93faffa549 Fix location information for programs
There appears to be a bug in our use of jison causing the parent location information to be reported to programs. I wasn’t able to work through what might be causing this so instead using the location information of the statements collection to generate the proper location information.

This is a bit of a hack but we are very far behind on the Jison release train and upgrading will likely be a less than pleasant task that doesn’t provide us much benefit.

Fixes #1024
2015-06-26 16:58:34 -05:00
kpdecker fc13400b6f Remove jshint completely 2015-04-27 10:19:49 -05:00
kpdecker 4bed826d0e Update for let and optional parameters 2015-04-20 02:38:28 -05:00
kpdecker e3d3eda2e1 Add full support for es6
Converts the tool chain to use babel, eslint, and webpack vs. the previous proprietary solutions.

Additionally begins enforcing additional linting concerns as well as updates the code to reflect these rules.

Fixes #855
Fixes #993
2015-04-16 16:43:01 -05:00
kpdecker 54e743a09a Allow this references in literal statements
Fixes #967
2015-04-14 01:12:39 -05:00
kpdecker 37a664bf64 Ignore branches tested without coverage monitoring 2015-04-07 23:38:05 -05:00
kpdecker c699d0b82f Remove vestigial code 2015-04-07 23:37:46 -05:00
kpdecker 2d149e7797 Add undefined and null literal support
This adds the UndefinedLiteral and NullLiteral to AST.

Fixes #990
2015-04-07 23:37:38 -05:00