Commit Graph

137 Commits

Author SHA1 Message Date
Nils Knappmeier 3fb331ef40 style: reformat all files using prettier 2019-12-03 22:39:17 +01:00
Nils Knappmeier dce6f54fdf Merge branch '4.x'
# Conflicts:
#	components/bower.json
#	components/handlebars.js.nuspec
#	components/package.json
#	package-lock.json
#	package.json
#	spec/amd-runtime.html
#	spec/amd.html
2019-11-18 08:26:56 +01:00
Nils Knappmeier f7f05d7558 fix: add "no-prototype-builtins" eslint-rule and fix all occurences 2019-11-18 07:33:45 +01:00
Nils Knappmeier 1988878087 fix: add more properties required to be enumerable
- __defineGetter__, __defineSetter__, __lookupGetter__, __proto__
2019-11-18 07:33:45 +01:00
kpdecker 7fcf9d24f8 Use objects for hash value tracking
The use of arrays was incorrect for the data type and causing problems when hash keys conflicted with array behaviors.

Fixes #1194

(cherry picked from commit 768ddbd661)
2019-10-27 17:27:37 +01:00
Nils Knappmeier 50e844b563 Merge branch '4.x'
# Conflicts:
#	components/bower.json
#	components/handlebars.js.nuspec
#	components/package.json
#	package.json
2019-10-22 00:02:19 +02:00
sohibe feb60f85c9 show source location for the strict lookup exceptions 2019-10-09 06:50:04 +02:00
Nils Knappmeier 566536b03d Merge branch '4.x'
# Conflicts:
#	components/bower.json
#	components/handlebars.js.nuspec
#	components/package.json
#	package-lock.json
#	package.json
2019-10-08 22:22:01 +02:00
Nils Knappmeier ff4d827c09 fix: harden "propertyIsEnumerable"-check
- "container" is an internal object that is most likely
  not accessible through templateing (unlike the proto of "Object", which might be.)
  In order to prevent overriding this method, we
  use "propertyIsEnumerable" from the constructor.
2019-09-28 10:36:49 +02:00
Nils Knappmeier 213c0bbe3c Use Object.prototype.propertyIsEnumerable to check for constructors
- context.propertyIsEnumerable can be replaced
  via __definedGetter__
- This is a fix specific to counter a known RCE exploit.
  Other fixes will follow.

closes #1563
2019-09-26 23:55:24 +02:00
Nils Knappmeier 25bae31578 Merge branch '4.x'
# Conflicts:
#	components/bower.json
#	components/handlebars.js.nuspec
#	components/package.json
#	lib/handlebars/runtime.js
#	package.json
2019-09-24 08:56:55 +02:00
Nils Knappmeier 2078c727c6 Disallow calling "helperMissing" and "blockHelperMissing" directly
closes #1558
2019-09-24 07:31:19 +02:00
Nils Knappmeier f349aa43c0 Merge branch '4.x'
# Conflicts:
#	components/bower.json
#	components/handlebars.js.nuspec
#	components/package.json
#	package.json
2019-02-07 11:06:49 +01:00
Nils Knappmeier 42841c41a4 fix: disallow access to the constructor in templates to prevent RCE
This commit fixes a Remote Code Execution (RCE) reported by
npm-security. Access to non-enumerable "constructor"-properties
is now prohibited by the compiled template-code, because this
the first step on the way to creating and execution arbitrary
JavaScript code.
The vulnerability affects systems where an attacker is allowed to
inject templates into the Handlebars setup.
Further details of the attack may be disclosed by npm-security.

Closes #1267
Closes #1495
2019-02-07 10:19:53 +01:00
Nils Knappmeier f21f900cf5 Merge branch '4.x'
# Conflicts:
#	.eslintrc.js
#	lib/precompiler.js
#	package.json
#	release-notes.md
2017-11-09 10:42:54 +01:00
Nils Knappmeier 7729aa956b Update grunt-eslint to 20.1.0 2017-10-21 15:42:27 +02:00
Nils Knappmeier 714a4c4482 Merge branch '4.x' into wycats-master
# Conflicts:
#	spec/regressions.js
2017-03-25 15:04:37 +01:00
Nils Knappmeier c8f4b570c1 Fix context-stack when calling block-helpers on null values
Fixes #1319

Original behaviour:
- When a block-helper was called on a null-context, an empty object was used
  as context instead. (#1093)
- The runtime verifies that whether the current context equals the
  last context and adds the current context to the stack, if it is not.
  This is done, so that inside a block-helper, the ".." path can be used
  to go back to the parent element.
- If the helper is called on a "null" element, the context was added, even
  though it shouldn't be, because the "null != {}"

Fix:
- The commit replaces "null" by the identifiable "container.nullContext"
  instead of "{}". "nullContext" is a sealed empty object.
- An additional check in the runtime verifies that the context is
  only added to the stack, if it is not the nullContext.

Backwards compatibility within 4.0.x-versions:
- This commit changes the compiler and compiled templates would not work
  with runtime-versions 4.0.0 - 4.0.6, because of the "nullContext"
  property. That's way, the compiled code reads
  "(container.nullContext || {})" so that the behavior will degrade
  gracefully with older runtime versions: Everything else will work
  fine, but GH-1319 will still be broken, if you use a newer compiler
  with a pre 4.0.7 runtime.
2017-03-25 15:00:58 +01:00
Charles O'Farrell 8ff49cef52 Ensure that existing blockParams and depths are respected on dupe programs
Fixes #1186
2016-11-11 12:01:16 -06:00
kpdecker 768ddbd661 Use objects for hash value tracking
The use of arrays was incorrect for the data type and causing problems when hash keys conflicted with array behaviors.

Fixes #1194
2016-03-11 22:16:18 -06:00
Charles O'Farrell c7be766902 Ensure that existing blockParams and depths are respected on dupe programs
Fixes #1186
2016-03-08 07:23:45 +11:00
machty 3f77b82ed0 Remove stringParams and trackIds mode
Closes #1145
2015-12-10 14:22:45 -05:00
kpdecker 9f59de9657 Fix lint errors under latest eslint 2015-10-31 13:32:43 -05:00
kpdecker fffb5a985f Fix iteration over undefined values
Allow for iteration on undefined values, but special case undefined and null to prevent rendering errors when not running in strict mode.

Fixes #1093
2015-09-23 21:17:57 -05:00
kpdecker 05b82a203e Fix failure when using decorators in partials 2015-09-02 20:43:54 -05:00
kpdecker 0aef72cb8e Update to latest eslint 2015-09-01 17:56:32 -05:00
kpdecker 452afbf2ff Implement block decorators
These allow for a given block to be wrapped in helper methods or metadata and allow for more control over the current container and method before the code is run.
2015-08-22 10:59:34 -07:00
kpdecker 9a2d1d6009 Pass container rather than exec as context
There is no real need for us to do `.call(container` other than for backwards compatibility with legacy versions. Using the 4.x release as a chance to optimize this behavior.
2015-08-18 23:54:04 -07:00
kpdecker 08093d72f0 Remove unused parameters 2015-08-18 23:14:09 -07:00
kpdecker 5d4b8da344 Pass undefined fields to helpers in strict mode
This allows for `{{helper foo}}` to still operate under strict mode when `foo` is not defined on the context. This allows helpers to perform whatever existence checks they please so patterns like `{{#if foo}}{{foo}}{{/if}}` can be used to protect against missing values.

Fixes #1063
2015-08-03 15:59:53 -05:00
kpdecker 410141c31e Fix escaping of non-javascript identifiers
The ‘ character would cause invalid javascript to be generated as it was not properly escaped. Switching to JSON.stringify safely handles all potential unescaped cases.
2015-08-01 15:48:28 -05:00
kpdecker fc13400b6f Remove jshint completely 2015-04-27 10:19:49 -05:00
kpdecker 4bed826d0e Update for let and optional parameters 2015-04-20 02:38:28 -05:00
kpdecker e3d3eda2e1 Add full support for es6
Converts the tool chain to use babel, eslint, and webpack vs. the previous proprietary solutions.

Additionally begins enforcing additional linting concerns as well as updates the code to reflect these rules.

Fixes #855
Fixes #993
2015-04-16 16:43:01 -05:00
kpdecker cb51b82b8e Add support for dynamic partial names
Uses the subexpression syntax to allow for dynamic partial lookups. Ex:

```
{{> (helper) }}
```

Fixes #933
2015-01-18 13:23:45 -06:00
Matthew Flaschen c9d723e0fb Add missing reserved words so compiler knows to use array syntax:
* await
* null
* true
* false

IE 8 was failing to compile Handlebars-generated source code
because it had helpers.null.

I came up with this list by diffing
https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Lexical_grammar#Keywords
against the ones Handlebars already had.

I added two corresponding tests for nameLookup.
2015-01-17 19:04:38 -05:00
kpdecker 6650957f79 Implement strict and assumeObject modes
Causes templates to throw when lookup fields are not defined within the context. Strict mode will throw when any field is omitted. assumeObjects mode maintains the existing behavior of outputting an empty response when fields are not defined but allows for performance/size optimizations by not doing safety checks for intermediate objects in the lookup chain.

Strict mode effectively disables the helperMissing and inverse handling for blockHelperMissing as templates will throw rather than call those features for missing data fields.

Fixes #651
Fixes #805
2014-12-27 14:59:36 -06:00
kpdecker b474630c7d Strip unnecessary whitespace in template output 2014-12-27 12:58:28 -06:00
kpdecker daa8f3dd05 Fix duplicate return statement on simple templates 2014-12-27 10:05:05 -06:00
kpdecker 396795c983 Implement block parameters
Fixes #907
2014-12-26 00:31:57 -06:00
kpdecker 6d2239d8ac Update fix for #926 for 3.0 codeline 2014-12-17 00:40:28 -06:00
kpdecker 59e80c5103 Track depths on deduped children
Fixes a very specific error case where deduped children won’t receive the depths object due to it being omitted by the caller when optimizing.

Fixes #926
2014-12-16 17:59:32 -06:00
kpdecker 203df9d5b7 Remove unused vars and add jshint checking 2014-12-16 12:57:46 -06:00
kpdecker 0d396ccd30 Remove Compiler.depths parameter
This is no longer necessary with the depths array tracking and adds compiler overhead.
2014-12-16 12:57:46 -06:00
kpdecker f84f76f006 Add basic docs for JavaScriptCompiler override API 2014-11-29 18:20:11 -06:00
kpdecker 96c1300f15 Drop unused JavaScriptCompiler.namespace param 2014-11-29 18:11:58 -06:00
kpdecker f990cf0064 Treat partial exec in a manner closer to helpers
This helps unify the code handling and will also be needed to support string/id tracking on partials.
2014-11-27 09:11:03 -06:00
kpdecker 1124908d2a Update subexpression and hash AST constructs 2014-11-27 08:37:48 -06:00
kpdecker 5c921cafeb Replace DataNode and IdNode with PathNode
This is a breaking change for string mode users as there is no longer a distinct type for data parameters. Instead data consumers should look for the @ prefix value.
2014-11-26 20:36:36 -06:00
kpdecker 61dd721ca2 Update AST location info to match SpiderMonkey
Part of #889
2014-11-26 09:01:03 -06:00