Commit Graph

1615 Commits

Author SHA1 Message Date
Nils Knappmeier 7372d4e9df fix: disallow access to the constructor in templates to prevent RCE
This commit fixes a Remote Code Execution (RCE) reported by
npm-security. Access to non-enumerable "constructor"-properties
is now prohibited by the compiled template-code, because this
the first step on the way to creating and execution arbitrary
JavaScript code.
The vulnerability affects systems where an attacker is allowed to
inject templates into the Handlebars setup.
Further details of the attack may be disclosed by npm-security.

Closes #1267
Closes #1495
2019-02-07 11:19:54 +01:00
Nils Knappmeier 8d22e6f501 v4.0.12 v4.0.12 2018-09-04 20:44:38 +02:00
Nils Knappmeier 3c970cc9c1 Update release notes 2018-09-04 20:44:07 +02:00
Nils Knappmeier abba3c7526 Update release notes 2018-09-04 20:37:53 +02:00
Nils Knappmeier 4bf1c4ff66 Update release notes 2018-09-04 20:36:06 +02:00
Nils Knappmeier 41b6a11d11 Merge branch '4.x' of github.com:wycats/handlebars.js into 4.x 2018-09-04 20:08:57 +02:00
Nils Knappmeier 2d28f920b0 bump grunt-plugin-dependencies to 1.x versions 2018-09-04 18:53:01 +02:00
Nils Knappmeier 29b174468d style: omit linting error caused by removing "if" 2018-09-04 18:53:01 +02:00
Nils Knappmeier d130ed2bc1 chore: bump various dependencies
- grunt -> 1
- grunt-contrib-watch -> 1
- mocha -> 5
  - in common.js: define "global" , see mochajs/mocha#1159
  - in builtins.js: revert "console.log" to old value just
    after using the mock (in log-helper tests), because
    mocha calls "console.log" on failure, before
    "afterEach"
2018-09-04 18:53:01 +02:00
Nils Knappmeier 2145c14994 bump grunt-plugin-dependencies to 1.x versions 2018-09-04 00:18:46 +02:00
Nils Knappmeier 8359722e5d style: omit linting error caused by removing "if" 2018-09-04 00:16:01 +02:00
Nils Knappmeier a1d864d4a7 chore: bump various dependencies
- grunt -> 1
- grunt-contrib-watch -> 1
- mocha -> 5
  - in common.js: define "global" , see mochajs/mocha#1159
  - in builtins.js: revert "console.log" to old value just
    after using the mock (in log-helper tests), because
    mocha calls "console.log" on failure, before
    "afterEach"
2018-09-04 00:15:02 +02:00
Qiang Li 0ddff8b388 unnecessary check
(cherry picked from commit e1fa310)
2018-05-31 23:16:26 +02:00
Nils Knappmeier 288e986161 Docs: Document branches in the CONTRIBUTING guide 2018-05-31 23:15:24 +02:00
Nils Knappmeier 30df8a1ac7 Testcase for accessing @root from a partial-block
related to #1445
2018-05-31 23:12:08 +02:00
Nils Knappmeier cda544bca9 Add package.json to components shim
This is an attempt to provide a valid package.json-file to the shim
repository for bower, in order to support `bower-away`

see components/handlebars.js#24
2017-11-28 22:13:17 +01:00
aaharu 69c6ca528d Use files field 2017-11-26 02:08:20 +09:00
Nils Knappmeier a4e39bdfd0 Fix release-notes (links to contributors` pages) 2017-11-09 10:46:39 +01:00
Nils Knappmeier b86b9189fa Fix release-notes (links to github-repo) 2017-11-09 10:44:20 +01:00
tim d3d39423a3 upgrade uglify-js 2017-10-21 23:04:23 +02:00
Nils Knappmeier 73d5637564 Update dependencies "async" to 2.5.0 and "source-map" to 0.6.1 2017-10-21 16:09:33 +02:00
Nils Knappmeier 7729aa956b Update grunt-eslint to 20.1.0 2017-10-21 15:42:27 +02:00
Nils Knappmeier 8947dd077c Update jsfiddle to 4.0.11 2017-10-17 23:15:53 +02:00
Nils Knappmeier 1e954ddf3c v4.0.11 v4.0.11 2017-10-17 22:52:25 +02:00
Nils Knappmeier 1ac131e652 Update release notes 2017-10-17 22:51:42 +02:00
Nils Knappmeier 59548b4bdc Extend compiler-api example by replacing child-compiler
closes #1376

(cherry picked from commit ce3cd8a)
2017-10-17 22:30:31 +02:00
Marcos Marado 21386b6474 Update (C) year in the LICENSE file
Welcome to 2017!

(cherry picked from commit 33773c2)
2017-10-17 22:21:41 +02:00
Nils Knappmeier 79309659e1 Gracefully handle missing uglify-js dependency
closes #1391

uglify-js is an optional dependency and should be treated as such.
This commit gracefully handles MODULE_NOT_FOUND errors while loading
uglify.

- Check for existing uglify-js (and load uglify-js) only if minification
  was activated
- Use "require.resolve" to check if uglify exists. Otherwise, a missing
  dependency of uglify-js would cause the same behavior as missing
  uglify-js. (Only a warning, no error)
- The code to load and run uglify is put into a single for readability
  purposes
- Tests use a mockup Module._resolveFilename to simulate the missing module.
  This function is used by both "require" and "require.resolve", so both
  are mocked equally.

(cherry picked from commit d5caa56)
2017-10-17 22:18:56 +02:00
Nils Knappmeier 5b76f041b3 Fix build on Windows
Closes #1233

- Handle path-separators properly. Use "path.sep" instead of "/".
  Or use "require.resolve()" if possible
- Use "execFile" instead of "exec" to run the Handlebars executable.
  This prevents problems due to (missing) shell escaping.
- Use explicit call to "node" in order to run the executable on Windows.
- Add "appveyor"-CI in order to run regular tests on Windows.
2017-08-23 22:29:30 +02:00
Nils Knappmeier 1ed163f4ae Update jsfiddle-link to 4.0.10 2017-05-21 14:15:39 +02:00
Nils Knappmeier 670ec6fafb v4.0.10 v4.0.10 2017-05-21 14:11:27 +02:00
Nils Knappmeier 2e935df8bf Update release notes 2017-05-21 14:10:50 +02:00
Nils Knappmeier 0e953d1db5 Replace "Object.assign" (not support in IE) by "util/extend" 2017-05-21 14:02:35 +02:00
Nils Knappmeier 5ec78a8c70 v4.0.9 v4.0.9 2017-05-21 13:39:05 +02:00
Nils Knappmeier 5333f316c3 Update release notes 2017-05-21 13:38:28 +02:00
Nils Knappmeier 8a836e2272 Handlebars.compile() does not modify "options" anymore
Fixes #1327

- This commit creates a shallow copy of the "options" passed to
  Handlebars.compile() in order to prevent modifications
- Note that "new Handlebars.Compiler().compile(..., options)" still
  modify the options object. This might change in the future, if
  anybody needs a fix for that.
2017-05-21 13:20:48 +02:00
Luiz Américo cc554a5813 Fix build in windows
(cherry picked from commit 275ab37)
2017-05-15 00:11:59 +02:00
Nils Knappmeier ed879a6068 Ensure LF line-edings in handlebars-template fixtures (*.hbs)
Fixes #1331
2017-05-14 23:57:07 +02:00
Nils Knappmeier 2e21e2bc9a Run integration test with node handlebars -a ... on Windows
Fixes #1233

NodeJS files cannot be executed directly on Windows.
2017-05-14 23:37:24 +02:00
Nils Knappmeier bdfdbea09c Ensure LF line-edings in lexer-files (*.l)
Related to #1233
2017-05-14 22:49:19 +02:00
Nils Knappmeier b50ef03823 Force LF line-endings for spec/artifacts
Fixes #1331
2017-05-14 14:43:14 +02:00
Nils Knappmeier 6e6269fcd7 Use istanbul/lib/cli.js instead of node_modules/.bin/istanbul
Fixes #1331

Due to the way, "bin"-files are distributed into the node_modules/.bin
directory on Windows, the task "test:cov" did not work on Windows.
This commit uses the node-script directly.
2017-05-14 14:43:14 +02:00
Nils Knappmeier 7378f854c3 Publish valid semver task independently of the branch 2017-05-13 00:57:46 +02:00
Nils Knappmeier fed5818876 v4.0.8 v4.0.8 2017-05-02 22:55:44 +02:00
Nils Knappmeier 0e81f0a082 Update release notes 2017-05-02 22:55:08 +02:00
Nils Knappmeier a00c598266 Allow partial-blocks to be executed without "options"
Closes #1341

If the @partial-block is called as parameter of a helper (like in
{{#if @partial-block}}...{{/if}}, the partialBlockWrapper is executed
without "options"-parameter. It should still work in without an error
in such a case.
2017-05-02 22:48:15 +02:00
Nils Knappmeier 606fa55b0a v4.0.7 v4.0.7 2017-04-29 22:52:09 +02:00
Nils Knappmeier 8e09f0ee4e Update release-notes for 4.0.7 2017-04-29 22:47:39 +02:00
Nils Knappmeier c8f4b570c1 Fix context-stack when calling block-helpers on null values
Fixes #1319

Original behaviour:
- When a block-helper was called on a null-context, an empty object was used
  as context instead. (#1093)
- The runtime verifies that whether the current context equals the
  last context and adds the current context to the stack, if it is not.
  This is done, so that inside a block-helper, the ".." path can be used
  to go back to the parent element.
- If the helper is called on a "null" element, the context was added, even
  though it shouldn't be, because the "null != {}"

Fix:
- The commit replaces "null" by the identifiable "container.nullContext"
  instead of "{}". "nullContext" is a sealed empty object.
- An additional check in the runtime verifies that the context is
  only added to the stack, if it is not the nullContext.

Backwards compatibility within 4.0.x-versions:
- This commit changes the compiler and compiled templates would not work
  with runtime-versions 4.0.0 - 4.0.6, because of the "nullContext"
  property. That's way, the compiled code reads
  "(container.nullContext || {})" so that the behavior will degrade
  gracefully with older runtime versions: Everything else will work
  fine, but GH-1319 will still be broken, if you use a newer compiler
  with a pre 4.0.7 runtime.
2017-03-25 15:00:58 +01:00
Tobias Bieniek b617375219 Parser: Change suffix to use ES6 default module export
- This export will be transpiled by Babel for the cjs distribution,
  but will enable others to  use a pure ES6 module distribution
- Instanbul: Ignore "parser.js" for coverage reporting. This file was ignored before
  via annotation, but this has no effect anymore due to the above change
- Remove istanbul annotation from `parser-prefix` (@nknapp)

Squashed by @nknapp

(cherry picked from commit 508347e)
2017-02-24 08:35:48 +01:00