Commit Graph

649 Commits

Author SHA1 Message Date
Nils Knappmeier 42841c41a4 fix: disallow access to the constructor in templates to prevent RCE
This commit fixes a Remote Code Execution (RCE) reported by
npm-security. Access to non-enumerable "constructor"-properties
is now prohibited by the compiled template-code, because this
the first step on the way to creating and execution arbitrary
JavaScript code.
The vulnerability affects systems where an attacker is allowed to
inject templates into the Handlebars setup.
Further details of the attack may be disclosed by npm-security.

Closes #1267
Closes #1495
2019-02-07 10:19:53 +01:00
Timothy Lindvall 27ac1ee396 Feat: Import TypeScript typings
- Import typings from DefinitelyTyped into repo.
- Update typings header to cite contributors from history and git blame.
- Update package.json to add typings field.
2018-12-21 23:27:58 +01:00
Nils Knappmeier 8d22e6f501 v4.0.12 2018-09-04 20:44:38 +02:00
Nils Knappmeier 8359722e5d style: omit linting error caused by removing "if" 2018-09-04 00:16:01 +02:00
Qiang Li 0ddff8b388 unnecessary check
(cherry picked from commit e1fa310)
2018-05-31 23:16:26 +02:00
tim d3d39423a3 upgrade uglify-js 2017-10-21 23:04:23 +02:00
Nils Knappmeier 7729aa956b Update grunt-eslint to 20.1.0 2017-10-21 15:42:27 +02:00
Nils Knappmeier 1e954ddf3c v4.0.11 2017-10-17 22:52:25 +02:00
Nils Knappmeier 79309659e1 Gracefully handle missing uglify-js dependency
closes #1391

uglify-js is an optional dependency and should be treated as such.
This commit gracefully handles MODULE_NOT_FOUND errors while loading
uglify.

- Check for existing uglify-js (and load uglify-js) only if minification
  was activated
- Use "require.resolve" to check if uglify exists. Otherwise, a missing
  dependency of uglify-js would cause the same behavior as missing
  uglify-js. (Only a warning, no error)
- The code to load and run uglify is put into a single for readability
  purposes
- Tests use a mockup Module._resolveFilename to simulate the missing module.
  This function is used by both "require" and "require.resolve", so both
  are mocked equally.

(cherry picked from commit d5caa56)
2017-10-17 22:18:56 +02:00
Nils Knappmeier 670ec6fafb v4.0.10 2017-05-21 14:11:27 +02:00
Nils Knappmeier 0e953d1db5 Replace "Object.assign" (not support in IE) by "util/extend" 2017-05-21 14:02:35 +02:00
Nils Knappmeier 5ec78a8c70 v4.0.9 2017-05-21 13:39:05 +02:00
Nils Knappmeier 8a836e2272 Handlebars.compile() does not modify "options" anymore
Fixes #1327

- This commit creates a shallow copy of the "options" passed to
  Handlebars.compile() in order to prevent modifications
- Note that "new Handlebars.Compiler().compile(..., options)" still
  modify the options object. This might change in the future, if
  anybody needs a fix for that.
2017-05-21 13:20:48 +02:00
Nils Knappmeier fed5818876 v4.0.8 2017-05-02 22:55:44 +02:00
Nils Knappmeier a00c598266 Allow partial-blocks to be executed without "options"
Closes #1341

If the @partial-block is called as parameter of a helper (like in
{{#if @partial-block}}...{{/if}}, the partialBlockWrapper is executed
without "options"-parameter. It should still work in without an error
in such a case.
2017-05-02 22:48:15 +02:00
Nils Knappmeier 606fa55b0a v4.0.7 2017-04-29 22:52:09 +02:00
Nils Knappmeier c8f4b570c1 Fix context-stack when calling block-helpers on null values
Fixes #1319

Original behaviour:
- When a block-helper was called on a null-context, an empty object was used
  as context instead. (#1093)
- The runtime verifies that whether the current context equals the
  last context and adds the current context to the stack, if it is not.
  This is done, so that inside a block-helper, the ".." path can be used
  to go back to the parent element.
- If the helper is called on a "null" element, the context was added, even
  though it shouldn't be, because the "null != {}"

Fix:
- The commit replaces "null" by the identifiable "container.nullContext"
  instead of "{}". "nullContext" is a sealed empty object.
- An additional check in the runtime verifies that the context is
  only added to the stack, if it is not the nullContext.

Backwards compatibility within 4.0.x-versions:
- This commit changes the compiler and compiled templates would not work
  with runtime-versions 4.0.0 - 4.0.6, because of the "nullContext"
  property. That's way, the compiled code reads
  "(container.nullContext || {})" so that the behavior will degrade
  gracefully with older runtime versions: Everything else will work
  fine, but GH-1319 will still be broken, if you use a newer compiler
  with a pre 4.0.7 runtime.
2017-03-25 15:00:58 +01:00
Nils Knappmeier 5a164d0ca5 Fix for #1252: Using @partial-block twice in a template not possible
Fixes #1252
- This fix treats partial-blocks more like closures and uses the closure-context of
  the "invokePartial"-function to store the @partial-block for the partial.
- Adds a tes for the fix
2017-02-14 22:18:30 +01:00
Joonas Lahtinen 01b0f656bb Avoid duplicate "sourceMappingURL=" lines.
Avoid duplicate // sourceMappingURL=... lines when minifying AND
generating a map. UglifyJS2 will write the line when minifying.

(cherry picked from commit 660a117)
2017-02-14 22:01:13 +01:00
Nils Knappmeier a023cb4dd9 Make "column"-property of Errors enumerable
Fixes #1284

Appearently, there is a use-case of stringifying the error in order to
evaluated its properties on another system. There was a regression
from 4.0.5  to 4.0.6 that the column-property of compilation errors
was not  enumerable anymore in 4.0.6 (due to  commit 20c965c) and
thus was not included in the output of "JSON.stringify".
2016-12-30 16:33:32 +01:00
Lon Ingram ad3037cf54 v4.0.6 (again)
Missed some versions in the repo that needed bumping.
2016-11-12 12:32:45 -06:00
Lon Ingram ef9e0dc2ab Walk up data frames for nested @partial-block
The root cause of #1218 is that `invokePartial` creates a stack of data frames
for nested partial blocks, but `resolvePartial` always uses the value at top of
the stack without "popping" it. The result is an infinite recursive loop, as
references to `@partial-block` in the partial at the top of the stack resolve to
itself.

So, walk up the stack of data frames when evaluating. This is accomplished by
1) setting the `partial-block` property to `noop` after use and
2) using `_parent['partial-block']` if `partial-block` is `noop`

Fix #1218
2016-11-11 12:01:16 -06:00
Charles O'Farrell 8ff49cef52 Ensure that existing blockParams and depths are respected on dupe programs
Fixes #1186
2016-11-11 12:01:16 -06:00
kpdecker 8c19874497 Drop extra Error params
This was causing a difficult to diagnose failure under IE and doesn’t give us enough value to justify the change.
2016-11-11 12:01:16 -06:00
kpdecker 32d6363841 Exclude coverage check in exception conditional 2016-11-11 12:01:16 -06:00
kpdecker 20c965cd65 Fix throw when creating exception object in Safari
https://github.com/jquery/esprima/issues/1290
2016-11-11 12:01:16 -06:00
kpdecker c393c81561 Relax depth check for context push
Fixes #1135
2016-11-11 12:01:16 -06:00
kpdecker 205c61cfb1 v4.0.5 2015-11-19 23:06:54 -06:00
kpdecker 685cf92bcb Return current handlebars instance from noConflict
Fixes wycats/handlebars-site#131
2015-11-19 22:58:26 -06:00
kpdecker 9f59de9657 Fix lint errors under latest eslint 2015-10-31 13:32:43 -05:00
kpdecker b7c95e9feb v4.0.4 2015-10-29 01:54:17 -05:00
Mark Christian 33b53ef989 Use template string for error message and double-quotes for quoting partial name 2015-10-19 09:44:53 -07:00
Mark Christian f08d48764d Include partial name in 'undefined partial' exception message 2015-10-19 09:22:54 -07:00
kpdecker 9365b82900 v4.0.3 2015-09-23 22:41:14 -05:00
kpdecker 94c840b6ed Create data frame for @partial-block
Fixes #1099
2015-09-23 22:08:59 -05:00
kpdecker 861d6f7b8d Fix tests under IE 2015-09-23 21:59:58 -05:00
kpdecker fffb5a985f Fix iteration over undefined values
Allow for iteration on undefined values, but special case undefined and null to prevent rendering errors when not running in strict mode.

Fixes #1093
2015-09-23 21:17:57 -05:00
kpdecker a5a3ab01d3 v4.0.2 2015-09-04 09:13:16 -05:00
kpdecker 7b1fdf814c Fix use of decorators within partials
If a decorator is used within a partial but not in the calling template, the hash is not passed in. For now error on the side of always including as just assigning values has minimal overhead.

Fixes #1089
2015-09-04 09:09:17 -05:00
kpdecker c7b28a65da v4.0.1 2015-09-02 21:21:36 -05:00
kpdecker 05b82a203e Fix failure when using decorators in partials 2015-09-02 20:43:54 -05:00
kpdecker 0aef72cb8e Update to latest eslint 2015-09-01 17:56:32 -05:00
kpdecker bff5fab8f9 v4.0.0 2015-09-01 08:19:14 -05:00
kpdecker 83b8e846a3 Escape = in HTML content
There was a potential XSS exploit when using unquoted attributes that this should help reduce.

Fixes #1083
2015-09-01 01:44:35 -05:00
kpdecker b0d217e13d Rev runtime compiler revision 2015-09-01 01:43:00 -05:00
kpdecker b63d74a7b3 Add explicitPartialContext compiler flag
Fixes #1032
2015-09-01 01:05:00 -05:00
kpdecker e7a64f018c Merge branch 'decorators' 2015-09-01 00:48:20 -05:00
Dennis Kuczynski 7c896a074d Fix #each when last object entry has empty key 2015-08-30 10:43:24 -04:00
kpdecker 6c45f49b24 Implement decorator helper method 2015-08-22 11:13:08 -07:00
kpdecker 495cd05a7e Implement inline partials
Allows for partials to be defined within the current template to allow for localized code reuse as well as for conditional behavior within nested partials.

Fixes #1018
2015-08-22 11:13:08 -07:00