Commit Graph

1943 Commits

Author SHA1 Message Date
Hannah Wolfe 6f17a8e75c Merge branch '4.x' 2020-04-02 20:34:06 +01:00
Hannah Wolfe 1fd2edee2a v4.7.5 v4.7.5 2020-04-02 20:09:49 +01:00
Hannah Wolfe 3c9c2f5cf2 Update release notes 2020-04-02 20:09:16 +01:00
Hannah Wolfe 16487a088e chore: downgrade yargs to v14
- allows us to support Node v6 and v8 for now
2020-04-02 19:28:36 +01:00
Hannah Wolfe 309d2b49a1 chore: set Node.js compatibility to v6+
- drop support for versions less than Node v6 via engines
- update integration tests to also test newer versions
2020-04-02 19:28:35 +01:00
Nils Knappmeier 645ac73844 test: fix integration tests
- They should fail, if any test fails
- Use "set -e" instead of "|| exit 1", because it suffices to be specified
  at the top of each file
2020-04-02 19:25:37 +01:00
Nils Knappmeier b454b02147 docs: update release-docs in CONTRIBUTING.md
- remove ember testing
- add docs for updating the website.
- add list of required accesses to publish
2020-04-02 14:10:47 +02:00
Hannah Wolfe f8eade7b41 Merge branch '4.x' 2020-04-01 18:54:36 +01:00
Hannah Wolfe d36adf9343 Revert "Update release-notes.md"
This reverts commit 2fd4a3da7a.
2020-04-01 18:49:13 +01:00
Hannah Wolfe 7adc19ab40 v4.7.4 v4.7.4 2020-04-01 18:20:30 +01:00
Hannah Wolfe 9dd8d10e12 Update release notes 2020-04-01 18:19:34 +01:00
Hannah Wolfe 4671c4b383 Use tmp directory for files written during tests
- Add spec/tmp directory with .gitkeep file to indicate the folder is intentional
- Add the folder contents to .gitignore
- Use this folder to output the sourcemap file during bin tests. This file is a sideeffect of the main test
2020-04-01 18:04:14 +01:00
DeeDeeG e46baa1fe2 tasks/test-bin.js: Delete duplicate test
Per comment by @ErisDS on the GitHub PR:
https://github.com/wycats/handlebars.js/pull/1666#issuecomment-606805248
2020-04-01 17:25:35 +01:00
Hannah Wolfe c491b4ea25 Revert "Update release-notes.md"
This reverts commit 738391a064.
Think this needs to be left to the release tool :|
2020-04-01 17:21:20 +01:00
Hannah Wolfe 738391a064 Update release-notes.md 2020-03-31 17:05:33 +01:00
Hannah Wolfe 2fd4a3da7a Update release-notes.md 2020-03-31 17:04:46 +01:00
Aori Nevo 80c4516fda chore: add unit tests for cli options (#1666)
- adds full unit tests for all cli options
- demonstrates that nothing changes between minimist and yargs except a minor order change in the --help text
- proves b9c4b253e works the same as before

Co-authored-by: fabb <fabb@users.noreply.github.com>
2020-03-31 16:54:11 +01:00
Avi Vahl d79212a662 fix: migrate from optimist to yargs (#1666)
closes #1658

- adapted code from master to latest yargs (`.option` calls).

```
4.x:
found 188 vulnerabilities (169 low, 4 moderate, 14 high, 1 critical) in 5815 scanned packages

4.x with this PR:
found 32 vulnerabilities (17 low, 1 moderate, 13 high, 1 critical) in 5829 scanned packages
```
2020-03-31 16:54:11 +01:00
Avi Vahl b440c38886 chore: ignore external @types in tests
- some indirect dependencies install @types packages which are not compatible with the older typescript.
- adjusted test's tsconfig to not pick these up automatically, as the actual .d.ts does not depend on these external types.
2020-03-31 16:53:54 +01:00
Eli Skeggs 2dba7eee3f docs: fix comparison link 2020-03-05 15:10:10 +01:00
Ilja leyberman 3800b7dd4c Update README.markdown
added a new Project (openVALIDATION) to the section  Handlebars in the Wild
2020-02-25 22:15:55 +01:00
Nils Knappmeier 2ea32e8db9 Merge branch '4.x'
# Conflicts:
#	components/bower.json
#	components/handlebars.js.nuspec
#	components/package.json
#	package.json
2020-02-05 06:13:36 +01:00
Nils Knappmeier c9789691af v4.7.3 v4.7.3 2020-02-05 06:10:33 +01:00
Nils Knappmeier 9278f217e0 Update release notes 2020-02-05 06:10:09 +01:00
roydukkey d78cc73d3c Fixes spelling and punctuation
(cherry picked from commit fd3ca85d13)
2020-02-05 06:06:42 +01:00
ismailjones 4de51fe26b Add Type Definition for Handlebars.VERSION, Fixes #1647 2020-02-04 23:32:10 +01:00
papasmile a32d05f2fc Include Type Definition for runtime.js in Package 2020-02-04 21:58:49 +01:00
Nils Knappmeier ad63f5189f chore: add missing "await" in aws-s3 publishing code
closes #1644
2020-01-21 21:52:23 +01:00
roydukkey fd3ca85d13 Fixes spelling and punctuation 2020-01-13 22:00:27 +01:00
Nils Knappmeier edfe6b899c Merge branch '4.x'
# Conflicts:
#	components/bower.json
#	components/handlebars.js.nuspec
#	components/package.json
#	package.json
2020-01-13 21:58:50 +01:00
Nils Knappmeier 586e672c8b v4.7.2 v4.7.2 2020-01-13 21:53:14 +01:00
Nils Knappmeier f0c6c4cc1f Update release notes 2020-01-13 21:52:50 +01:00
Nils Knappmeier a4fd391ba1 chore: execute saucelabs-task only if access-key exists
- up to now, the existance of the SAUCE_USERNAME was checked
  but this variable is even present in pull-requests from other
  repos. This means that builds fail, because the access key
  is not there.
  This change looks for SAUCE_ACCESS_KEY instead, which is
  a secure variable, only present in build originating from
  the handlebars.js repo.
2020-01-13 21:47:51 +01:00
Nils Knappmeier 9d5aa363cf fix: don't wrap helpers that are not functions
- helpers should always be a function, but in #1639 one seems to
  be undefined. This was not a problem before 4.6 because helpers
  weren't wrapped then.
  Now, we must take care only to wrap helpers (when adding
  the "lookupProperty" function to the options), if they
  are really functions.
2020-01-13 21:39:01 +01:00
Nils Knappmeier 14ba3d0c43 v4.7.1 v4.7.1 2020-01-12 13:21:08 +01:00
Nils Knappmeier 4cddfe7017 Update release notes 2020-01-12 13:20:37 +01:00
Nils Knappmeier f152dfc892 fix: fix log output in case of illegal property access
- fix link url to handlebarsjs.com
2020-01-12 13:09:19 +01:00
Nils Knappmeier 3c1e252169 fix: log error for illegal property access only once per property 2020-01-12 13:06:56 +01:00
Nils Knappmeier 0d5c807017 v4.7.0 v4.7.0 2020-01-10 17:24:06 +01:00
Nils Knappmeier 1f0834b1a2 Update release notes 2020-01-10 17:23:31 +01:00
Nils Knappmeier 575d8772e2 fix: use "logger" instead of console.error
... to be graceful with older browser without "console"
2020-01-10 17:06:57 +01:00
Nils Knappmeier 7af1c12db6 feat: default options for controlling proto access
This commmit adds the runtime options
- `allowProtoPropertiesByDefault` (boolean, default: false) and
- `allowProtoMethodsByDefault` (boolean, default: false)`
which can be used to allow access to prototype properties and
functions in general.

Specific properties and methods can still be disabled from access
via `allowedProtoProperties` and `allowedProtoMethods` by
setting the corresponding values to false.

The methods `constructor`, `__defineGetter__`, `__defineSetter__`, `__lookupGetter__`
and the property `__proto__` will be disabled, even if the allow...ByDefault-options
are set to true. In order to allow access to those properties and methods, they have
to be explicitly set to true in the 'allowedProto...'-options.

A warning is logged when the a proto-access it attempted and denied
by default (i.e. if no option is set by the user to make the access
decision explicit)
2020-01-10 16:55:45 +01:00
Nils Knappmeier 0c8230c253 Merge branch '4.x'
# Conflicts:
#	components/bower.json
#	components/handlebars.js.nuspec
#	components/package.json
#	package.json
2020-01-09 00:17:28 +01:00
Nils Knappmeier 91a1b5d2f4 v4.6.0 v4.6.0 2020-01-08 23:45:15 +01:00
Nils Knappmeier 770d746e60 Update release notes 2020-01-08 23:44:46 +01:00
Nils Knappmeier d7f0dcf2bb refactor: fix typo in private test method 2020-01-08 23:17:23 +01:00
Nils Knappmeier 187d611e8c test: add path to nodeJs when running test:bin
- this allows the test to be run in a debugger
  without the complete PATH
2020-01-08 23:17:23 +01:00
Nils Knappmeier d337f40d0e test: show diff when test:bin fails 2020-01-08 23:17:23 +01:00
Nils Knappmeier d03b6ecfc4 feat: access control to prototype properties via whitelist
Disallow access to prototype properties and methods by default.
Access to properties is always checked via
`Object.prototype.hasOwnProperty.call(parent, propertyName)`.

New runtime options:
- **allowedProtoMethods**: a string-to-boolean map of property-names that are allowed if they are methods of the parent object.
- **allowedProtoProperties**: a string-to-boolean map of property-names that are allowed if they are properties but not methods of the parent object.

```js
const template = handlebars.compile('{{aString.trim}}')
const result = template({ aString: '  abc  ' })
// result is empty, because trim is defined at String prototype
```

```js
const template = handlebars.compile('{{aString.trim}}')
const result = template({ aString: '  abc  ' }, {
  allowedProtoMethods: {
    trim: true
  }
})
// result = 'abc'
```

Implementation details: The method now "container.lookupProperty"
handles the prototype-checks and the white-lists. It is used in
- JavaScriptCompiler#nameLookup
- The "lookup"-helper (passed to all helpers as "options.lookupProperty")
- The "lookup" function at the container, which is used for recursive lookups in "compat" mode

Compatibility:
- **Old precompiled templates work with new runtimes**: The "options.lookupPropery"-function is passed to the helper by a wrapper, not by the compiled templated.
- **New templates work with old runtimes**: The template contains a function that is used as fallback if the "lookupProperty"-function cannot be found at the container. However, the runtime-options "allowedProtoProperties" and "allowedProtoMethods" only work with the newest runtime.

BREAKING CHANGE:
- access to prototype properties is forbidden completely by default
2020-01-08 23:17:23 +01:00
Nils Knappmeier d23ccf636a Merge branch '4.x'
# Conflicts:
#	Gruntfile.js
#	package-lock.json
#	package.json
2019-12-14 18:46:25 +01:00