Commit Graph

486 Commits

Author SHA1 Message Date
Nils Knappmeier b0bb2a42b4 Merge branch '4.x'
# Conflicts:
#	components/bower.json
#	components/handlebars.js.nuspec
#	components/package.json
#	package-lock.json
#	package.json
2019-11-09 06:47:10 +01:00
Nils Knappmeier 088e61812a chore: add eslint-plugin-compat and eslint-plugin-es5
- tests are not compiled with babel and must thus be in
  es5
- we don't use polyfills, so we need to make sure no
  functions aren't used that are not supported by popular browsers. (like Object.assign in Safari and IE11)
- Boths are errors that usually only appear when running
  tests in SauceLabs, which happens only on _after_
  merging a PR.
2019-10-28 19:17:57 +01:00
Robert Jackson 62ed3c25c7 Add Handlebars.parseWithoutProcessing (#1584)
When authoring tooling that parses Handlebars files and emits Handlebars
files, you often want to preserve the **exact** formatting of the input.
The changes in this commit add a new method to the `Handlebars`
namespace: `parseWithoutProcessing`. Unlike, `Handlebars.parse` (which
will mutate the parsed AST to apply whitespace control) this method will
parse the template and return it directly (**without** processing
😉).

For example, parsing the following template:

```hbs
 {{#foo}}
   {{~bar~}} {{baz~}}
 {{/foo}}
```

Using `Handlebars.parse`, the AST returned would have truncated the
following whitespace:

* The whitespace prior to the `{{#foo}}`
* The newline following `{{#foo}}`
* The leading whitespace before `{{~bar~}}`
* The whitespace between `{{~bar~}}` and `{{baz~}}`
* The newline after `{{baz~}}`
* The whitespace prior to the `{{/foo}}`

When `Handlebars.parse` is used from  `Handlebars.precompile` or
`Handlebars.compile`, this whitespace stripping is **very** important
(these behaviors are intentional, and generally lead to better rendered
output).

When the same template is parsed with
`Handlebars.parseWithoutProcessing` none of those modifications to the
AST are made. This enables "codemod tooling" (e.g. `prettier` and
`ember-template-recast`) to preserve the **exact** initial formatting.
Prior to these changes, those tools would have to _manually_ reconstruct
the whitespace that is lost prior to emitting source.
2019-10-28 00:28:28 +01:00
Nils Knappmeier e46c239b3d Merge branch '4.x'
# Conflicts:
#	lib/handlebars/compiler/javascript-compiler.js
#	lib/handlebars/helpers/with.js
2019-10-27 17:31:48 +01:00
kpdecker 7fcf9d24f8 Use objects for hash value tracking
The use of arrays was incorrect for the data type and causing problems when hash keys conflicted with array behaviors.

Fixes #1194

(cherry picked from commit 768ddbd661)
2019-10-27 17:27:37 +01:00
Nils Knappmeier 081e1d0ad9 Merge branch '4.x'
# Conflicts:
#	lib/handlebars/compiler/javascript-compiler.js
2019-10-27 17:26:57 +01:00
kpdecker 2ef6fbd1fc Use objects for hash value tracking
The use of arrays was incorrect for the data type and causing problems when hash keys conflicted with array behaviors.

Fixes #1194

(cherry picked from commit 768ddbd661)
2019-10-27 17:25:40 +01:00
Hannah Wolfe c76ded8f0f fix: add guard to if & unless helpers (#1549)
fixes #1548

- add a guard to show readable syntax error for if / unless helper
- prevents against 3 different errors that can be generated by different systax errors
2019-10-27 15:41:35 +01:00
Nils Knappmeier 50e844b563 Merge branch '4.x'
# Conflicts:
#	components/bower.json
#	components/handlebars.js.nuspec
#	components/package.json
#	package.json
2019-10-22 00:02:19 +02:00
Nils Knappmeier fd2e5c983d fix: non-eager matching raw-block-contents
In 4.4.4 the block-contents was matched with an eager match, which means
that with multiple raw-blocks of the same kind, the block was spanned
over the first ending-tag until the last one.
This commit replaces this by a non-eager match.

closes #1579
2019-10-20 22:57:13 +02:00
Nils Knappmeier aaab6099f2 fix: prevent zero length tokens in raw-blocks (#1577)
This comment ensures that the lexer is not stuck on zero-length tokens, in raw-blocks like {{{{a}}}} {{{{/a}}}}
2019-10-20 21:23:02 +02:00
sohibe feb60f85c9 show source location for the strict lookup exceptions 2019-10-09 06:50:04 +02:00
Nils Knappmeier 566536b03d Merge branch '4.x'
# Conflicts:
#	components/bower.json
#	components/handlebars.js.nuspec
#	components/package.json
#	package-lock.json
#	package.json
2019-10-08 22:22:01 +02:00
antelle cf7545ef5a Added support for iterable objects in {{#each}} helper (#1557)
* Added support for iterable object in {{#each}} helper
Currently {{#each}} helper supports either arrays, or objects,
however nowadays you can define custom iterable objects by overriding
a special method called Symbol.iterator, which results in empty result
being rendered.
* improved a test for iterables in {{#each}} returning empty result
* #each helper: using ES5 instead of generator functions in tests
* #each helper: using ES5 in the helper itself
2019-09-29 14:57:47 +02:00
Nils Knappmeier 8742bde701 fix test case for browsers that do not support __defineGetter__ 2019-09-27 00:09:04 +02:00
Nils Knappmeier 213c0bbe3c Use Object.prototype.propertyIsEnumerable to check for constructors
- context.propertyIsEnumerable can be replaced
  via __definedGetter__
- This is a fix specific to counter a known RCE exploit.
  Other fixes will follow.

closes #1563
2019-09-26 23:55:24 +02:00
Nils Knappmeier e3639e2407 fix saucelabs tests (internet explorer) 2019-09-25 00:18:02 +02:00
Nils Knappmeier c2a17c7b30 fix saucelabs tests (internet explorer) 2019-09-25 00:00:51 +02:00
Nils Knappmeier 1266838829 do not break on precompiled templates from Handlebars >=4.0.0 <4.3.0
- The version-range above have compiler version 7 and
  precompiled templates expecte the (block)
  HelperMissing-functions in "helpers" and not in "container.hooks".
- Handlebars now accepts precompiled templates of version 7.
- If a precompiled template with version 7 is loaded,
  the (block)HelperMissing-functions are kept in "helpers"
2019-09-24 23:45:09 +02:00
Nils Knappmeier 25bae31578 Merge branch '4.x'
# Conflicts:
#	components/bower.json
#	components/handlebars.js.nuspec
#	components/package.json
#	lib/handlebars/runtime.js
#	package.json
2019-09-24 08:56:55 +02:00
Nils Knappmeier 06b7224ed9 adjust compiler revision 2019-09-24 07:31:19 +02:00
Nils Knappmeier 2078c727c6 Disallow calling "helperMissing" and "blockHelperMissing" directly
closes #1558
2019-09-24 07:31:19 +02:00
Nils Knappmeier 2f681d256f Merge branch '4.x'
# Conflicts:
#	components/bower.json
#	components/handlebars.js.nuspec
#	components/package.json
#	package.json
2019-04-13 16:48:27 +02:00
Nils Knappmeier cd38583216 fix: prevent RCE through the "lookup"-helper
- The "lookup" helper could also be used to run a remote code execution
  by manipulating the template. The same check as for regular
  path queries now also is done in the "lookup"-helper
2019-04-11 23:08:57 +02:00
Nils Knappmeier 7840ab66a5 test: make security testcase internet explorer compatible
Internet Explorer does not support the 'class Testclass {}' notation,
and tests are not compiled using babel.

closes #1497
2019-03-15 23:01:49 +01:00
Nils Knappmeier f349aa43c0 Merge branch '4.x'
# Conflicts:
#	components/bower.json
#	components/handlebars.js.nuspec
#	components/package.json
#	package.json
2019-02-07 11:06:49 +01:00
Nils Knappmeier 42841c41a4 fix: disallow access to the constructor in templates to prevent RCE
This commit fixes a Remote Code Execution (RCE) reported by
npm-security. Access to non-enumerable "constructor"-properties
is now prohibited by the compiled template-code, because this
the first step on the way to creating and execution arbitrary
JavaScript code.
The vulnerability affects systems where an attacker is allowed to
inject templates into the Handlebars setup.
Further details of the attack may be disclosed by npm-security.

Closes #1267
Closes #1495
2019-02-07 10:19:53 +01:00
Nils Knappmeier 379172e236 Merge branch '4.x' 2018-09-04 20:57:30 +02:00
Nils Knappmeier a1d864d4a7 chore: bump various dependencies
- grunt -> 1
- grunt-contrib-watch -> 1
- mocha -> 5
  - in common.js: define "global" , see mochajs/mocha#1159
  - in builtins.js: revert "console.log" to old value just
    after using the mock (in log-helper tests), because
    mocha calls "console.log" on failure, before
    "afterEach"
2018-09-04 00:15:02 +02:00
Nils Knappmeier 148b19182d Merge branch '4.x' 2018-05-31 23:16:44 +02:00
Nils Knappmeier 30df8a1ac7 Testcase for accessing @root from a partial-block
related to #1445
2018-05-31 23:12:08 +02:00
Nils Knappmeier f21f900cf5 Merge branch '4.x'
# Conflicts:
#	.eslintrc.js
#	lib/precompiler.js
#	package.json
#	release-notes.md
2017-11-09 10:42:54 +01:00
Nils Knappmeier 7729aa956b Update grunt-eslint to 20.1.0 2017-10-21 15:42:27 +02:00
Nils Knappmeier 79309659e1 Gracefully handle missing uglify-js dependency
closes #1391

uglify-js is an optional dependency and should be treated as such.
This commit gracefully handles MODULE_NOT_FOUND errors while loading
uglify.

- Check for existing uglify-js (and load uglify-js) only if minification
  was activated
- Use "require.resolve" to check if uglify exists. Otherwise, a missing
  dependency of uglify-js would cause the same behavior as missing
  uglify-js. (Only a warning, no error)
- The code to load and run uglify is put into a single for readability
  purposes
- Tests use a mockup Module._resolveFilename to simulate the missing module.
  This function is used by both "require" and "require.resolve", so both
  are mocked equally.

(cherry picked from commit d5caa56)
2017-10-17 22:18:56 +02:00
Nils Knappmeier d5caa56d6c Gracefully handle missing uglify-js dependency
closes #1391

uglify-js is an optional dependency and should be treated as such.
This commit gracefully handles MODULE_NOT_FOUND errors while loading
uglify.

- Check for existing uglify-js (and load uglify-js) only if minification
  was activated
- Use "require.resolve" to check if uglify exists. Otherwise, a missing
  dependency of uglify-js would cause the same behavior as missing
  uglify-js. (Only a warning, no error)
- The code to load and run uglify is put into a single for readability
  purposes
- Tests use a mockup Module._resolveFilename to simulate the missing module.
  This function is used by both "require" and "require.resolve", so both
  are mocked equally.
2017-10-17 22:17:37 +02:00
Nils Knappmeier 7b74175e0e Merge branch '4.x' 2017-08-23 22:31:54 +02:00
Nils Knappmeier 5b76f041b3 Fix build on Windows
Closes #1233

- Handle path-separators properly. Use "path.sep" instead of "/".
  Or use "require.resolve()" if possible
- Use "execFile" instead of "exec" to run the Handlebars executable.
  This prevents problems due to (missing) shell escaping.
- Use explicit call to "node" in order to run the executable on Windows.
- Add "appveyor"-CI in order to run regular tests on Windows.
2017-08-23 22:29:30 +02:00
Nils Knappmeier fb26f69485 Merge branch '4.x'
# Conflicts:
#	CONTRIBUTING.md
#	lib/handlebars/compiler/compiler.js
#	package.json
#	spec/compiler.js
2017-05-21 14:20:32 +02:00
Nils Knappmeier 8a836e2272 Handlebars.compile() does not modify "options" anymore
Fixes #1327

- This commit creates a shallow copy of the "options" passed to
  Handlebars.compile() in order to prevent modifications
- Note that "new Handlebars.Compiler().compile(..., options)" still
  modify the options object. This might change in the future, if
  anybody needs a fix for that.
2017-05-21 13:20:48 +02:00
Nils Knappmeier 680ec9666a Merge branch '4.x' into wycats-master
# Conflicts:
#	package.json
2017-05-13 01:00:35 +02:00
Nils Knappmeier a00c598266 Allow partial-blocks to be executed without "options"
Closes #1341

If the @partial-block is called as parameter of a helper (like in
{{#if @partial-block}}...{{/if}}, the partialBlockWrapper is executed
without "options"-parameter. It should still work in without an error
in such a case.
2017-05-02 22:48:15 +02:00
Nils Knappmeier 714a4c4482 Merge branch '4.x' into wycats-master
# Conflicts:
#	spec/regressions.js
2017-03-25 15:04:37 +01:00
Nils Knappmeier c8f4b570c1 Fix context-stack when calling block-helpers on null values
Fixes #1319

Original behaviour:
- When a block-helper was called on a null-context, an empty object was used
  as context instead. (#1093)
- The runtime verifies that whether the current context equals the
  last context and adds the current context to the stack, if it is not.
  This is done, so that inside a block-helper, the ".." path can be used
  to go back to the parent element.
- If the helper is called on a "null" element, the context was added, even
  though it shouldn't be, because the "null != {}"

Fix:
- The commit replaces "null" by the identifiable "container.nullContext"
  instead of "{}". "nullContext" is a sealed empty object.
- An additional check in the runtime verifies that the context is
  only added to the stack, if it is not the nullContext.

Backwards compatibility within 4.0.x-versions:
- This commit changes the compiler and compiled templates would not work
  with runtime-versions 4.0.0 - 4.0.6, because of the "nullContext"
  property. That's way, the compiled code reads
  "(container.nullContext || {})" so that the behavior will degrade
  gracefully with older runtime versions: Everything else will work
  fine, but GH-1319 will still be broken, if you use a newer compiler
  with a pre 4.0.7 runtime.
2017-03-25 15:00:58 +01:00
Nils Knappmeier 0fa10b6e87 Merge branch '4.x'
# Conflicts:
#	Gruntfile.js
#	lib/handlebars/exception.js
#	spec/partials.js
#	spec/regressions.js
2017-02-14 22:41:46 +01:00
Nils Knappmeier 63a8e0caa2 Add more tests for partial-blocks and inline partials
- Multiple partial-blocks at different nesting levels
- Calling partial-blocks twice with nested partial-blocks
- Calling the partial-block from within the #each-helper
- nested inline partials with partial-blocks on different nesting levels
- nested inline partials (twice at each level)
2017-02-14 22:18:30 +01:00
Nils Knappmeier 5a164d0ca5 Fix for #1252: Using @partial-block twice in a template not possible
Fixes #1252
- This fix treats partial-blocks more like closures and uses the closure-context of
  the "invokePartial"-function to store the @partial-block for the partial.
- Adds a tes for the fix
2017-02-14 22:18:30 +01:00
Joonas Lahtinen 01b0f656bb Avoid duplicate "sourceMappingURL=" lines.
Avoid duplicate // sourceMappingURL=... lines when minifying AND
generating a map. UglifyJS2 will write the line when minifying.

(cherry picked from commit 660a117)
2017-02-14 22:01:13 +01:00
Joonas Lahtinen 660a117536 Avoid duplicate "sourceMappingURL=" lines.
Avoid duplicate // sourceMappingURL=... lines when minifying AND
generating a map. UglifyJS2 will write the line when minifying.
2017-02-14 21:57:00 +01:00
Nils Knappmeier a023cb4dd9 Make "column"-property of Errors enumerable
Fixes #1284

Appearently, there is a use-case of stringifying the error in order to
evaluated its properties on another system. There was a regression
from 4.0.5  to 4.0.6 that the column-property of compilation errors
was not  enumerable anymore in 4.0.6 (due to  commit 20c965c) and
thus was not included in the output of "JSON.stringify".
2016-12-30 16:33:32 +01:00
Nils Knappmeier c7dc353956 Testcase to verify that compile-errors have a column-property
Related to #1284

The test ensures that the property is there, because it is important to
some people.
2016-12-30 16:33:32 +01:00