619 Commits

Author SHA1 Message Date
Ryan Grove b324d002ca Allow ids to contain hyphens. Fixes #36.
Previously, a mustache like {{foo-bar}} would generate a
parse error, which was a departure from the behavior of
other Mustache implementations.
2011-04-28 22:30:21 -07:00
Ryan Grove b291a1ad8c Add ", ', and / to the list of chars that need HTML escaping.
Previously, only < and > were escaped. This meant that any Handlebars
template that used user input in an HTML attribute value was wide open
to a trivial XSS exploit. Note that unquoted attribute values are still
open to attack, but this set of characters at least brings Handlebars in
line with other Mustache implementations and other template languages.

See the OWASP XSS prevention cheat sheet (rule #1) for the rationale
behind escaping these characters:

https://www.owasp.org/index.php/XSS_(Cross_Site_Scripting)_Prevention_Cheat_Sheet
2011-04-25 11:15:53 -07:00
Ryan Grove dec196b4d9 The "if" block helper shouldn't treat empty arrays as truthy.
Given the data {foo: []}, the following template previously considered
foo to be truthy when it shouldn't have:

    {{#if foo}}
      You should not see me!
    {{else}}
      You should see me!
    {{/if}}
2011-04-20 16:56:37 -07:00
tomhuda 6a80531513 Merge branch 'master' of https://github.com/tf/handlebars.js into tf-master 2011-03-26 14:04:49 -07:00
Tim Fischbach a1b1b160cf inserting missing return statement in unless helper (fixes issue #51) 2011-03-09 11:51:00 +01:00
tomhuda a7bb51d8a5 DRY up some code that converts program AST nodes to opcodes. 2011-03-04 15:17:32 -08:00
tomhuda 357710f136 Add support for block hashes and clean up mustache/program code 2011-03-04 15:10:22 -08:00
tomhuda ca9b9671a5 Add Hash arguments to simple mustaches (TODO: add Hash args to block helpers) 2011-03-04 00:11:03 -08:00
tomhuda e0aa705f71 Add support for hash args in the tokenizer and parser 2011-03-03 21:33:28 -08:00
Jason Davies 0397f875c5 Merge branch 'master' of http://github.com/wycats/handlebars.js 2011-02-28 22:23:11 +00:00
Jason Davies 2cf88d4e77 Fix backslash escaping 2011-02-28 22:23:02 +00:00
tomhuda 32d7e52182 Helpers take precedence over context properties with the same name. This is useful in scenarios where your context object is inherited from another system (such as a framework or JSON API) that may contain properties that conflict with helpers you explicitly define. 2011-02-25 23:01:11 -08:00
tomhuda 2b319bef2f Make the function passed to a block helper have an identical signature to top-level template methods 2011-02-14 16:05:01 -08:00
tomhuda d7f93c09e7 Subclasses should be able to replace the compiler - this is needed so that child views are compiled using the updated semantics of the parent compiler 2011-02-11 20:11:52 -08:00
tomhuda 299a0e81e3 data is passed to block helpers 2011-02-11 20:11:23 -08:00
tomhuda 88e7003331 * Added a few public API methods to JavaScriptCompiler.prototype, so it can be subclassed.
* made it possible to define an alternate name lookup scheme (so that {{foo}} does not have to be
    context.foo, but can instead be something like context.get('foo'))
  * made it possible to substitute an alternate buffer instead of the default empty String and override how
    the compiled template appends to the buffer
* Added the concept of template-local data. In order to enable template-local data, pass true
  as the second parameter to the template compiler. Then, pass in the data as the fourth
  parameter (context, helpers, partials, data). These signatures may change before the 1.0 release.
2011-02-11 17:03:12 -08:00
Alan Johnson 2eb1b30870 Merge branch 'master' of github.com:wycats/handlebars.js 2011-02-10 06:27:12 -05:00
Alan Johnson 40dd2c9750 Updated if helper - missed it in the last cleanup. It no longer supports methods as arguments. 2011-02-10 06:27:03 -05:00
wycats aaaafb4400 Makes Handlebars work in contexts without a global object (node) 2011-02-08 14:31:09 -08:00
Alan Johnson ac4d34dbe3 Backed out function helpers. 2011-01-25 21:21:57 -05:00
Alan Johnson 116a8a5202 Merge branch 'master' of https://github.com/gixug/handlebars.js into gixug-master 2011-01-25 19:59:34 -05:00
David Stone ea553b511b IE 7 hates trailing commas 2011-01-25 10:24:53 -08:00
Raimonds Simanovskis ada5a95f9c improved "with" and "each" helpers to support function as argument 2011-01-23 11:55:48 +02:00
Alan Johnson 65b421ee4d Merged 2011-01-22 10:30:44 -05:00
Alex Stupka 8ab1ffae17 Use prototype toString method to avoid native types being returned.
* For example, mozilla returns [xpconnect native prototype wrapper] vs [object Function]
2011-01-17 15:42:27 -08:00
wycats b7c649617b noop should return an empty String, not undefined 2011-01-11 23:16:03 -08:00
wycats 1974aa5277 If the partial is not found, an exception should be thrown 2010-12-29 19:23:23 -08:00
wycats e20c57c9b2 Move compile to the right spot 2010-12-29 19:09:55 -08:00
wycats 5170e1459f Don't need runtime anymore for normal operation 2010-12-29 18:34:13 -08:00
wycats bf6c74aa83 Restructure things more simply 2010-12-29 18:21:43 -08:00
wycats 9a1d7c018d Make {{#if foo}} handle empty Arrays 2010-12-28 15:47:15 -08:00
wycats 0da3065987 Clean up after-effects of Jison fix 2010-12-28 15:46:26 -08:00
Raimonds Simanovskis b319730031 improved "if" helper to support function as argument 2010-12-28 13:37:42 +02:00
wycats 72fa62529e Merge branch 'master' of https://github.com/zaach/handlebars.js into zaach-master 2010-12-27 13:02:20 -08:00
wycats 16ed2cd3f1 Refactoring and performance enhancements on the VM compiler 2010-12-21 09:47:27 -08:00
wycats d87ae129c0 Add a #with helper 2010-12-21 09:47:01 -08:00
wycats 8fccd21283 escapeExpressions should return "" for falsy values 2010-12-21 09:46:50 -08:00
wycats e0246d7dfc #each should handle undefined or null values 2010-12-21 09:46:22 -08:00
wycats fc0d721b96 Use pluggable logger rather the puts 2010-12-21 09:45:59 -08:00
wycats 355565bb04 Fix missing whitespaces in error message 2010-12-21 09:39:05 -08:00
Zach Carter faea35f8fa Merging with latest master 2010-12-20 02:25:25 -05:00
wycats 8f502ffbe7 Add #each and #if built-in helpers for more readable iteration and conditionals 2010-12-19 00:06:55 -08:00
wycats f4ae0c27fe Allow reserved words to be used without slowing down most operations in browsers with faster foo.bar vs. foo['bar']. 2010-12-19 00:06:30 -08:00
wycats b418ef6eb2 Add optimized compiled version of handlebars, which should be significantly faster. Use Handlebars.VM.compile instead of Handlebars.compile to use the optimized version.
Major TODOS:

* clean up a bunch of code duplication in the compiler
* reorganize the compiler
* add support for debug symbols which would make it possible
  to provide information about what part of the source caused
  a runtime error.
2010-12-18 23:27:34 -08:00
wycats e15d675a64 Everything is working now on the new VM except for partials and inverse sections 2010-12-15 23:42:53 -08:00
Zach Carter 97536f897e Switch to Jison's lexer. 2010-12-14 19:07:05 -05:00
wycats ec948c7382 Small restructuring. Have I mentioned how much I hate having to write modules that work in both CommonJS and the browser? 2010-12-12 13:33:17 -08:00
wycats 9fcd85bbac Allow helperMissing to apply to simple mustaches (paves the way to support things like link_to in a Rails context) 2010-12-11 18:43:58 -08:00
wycats 215754c268 Make helperMissing a built-in feature 2010-12-11 18:28:37 -08:00
wycats 5097c18912 Make it possible to register helpers and partials and then skip passing in the helpers or partials later 2010-12-11 18:10:56 -08:00