58 Commits

Author SHA1 Message Date
Nils Knappmeier e97685e989 style: reformat all files using prettier 2019-12-03 22:37:15 +01:00
Nils Knappmeier 2078c727c6 Disallow calling "helperMissing" and "blockHelperMissing" directly
closes #1558
2019-09-24 07:31:19 +02:00
kpdecker 9f59de9657 Fix lint errors under latest eslint 2015-10-31 13:32:43 -05:00
kpdecker 0aef72cb8e Update to latest eslint 2015-09-01 17:56:32 -05:00
kpdecker 83b8e846a3 Escape = in HTML content
There was a potential XSS exploit when using unquoted attributes that this should help reduce.

Fixes #1083
2015-09-01 01:44:35 -05:00
kpdecker efddc3c09c Increase code coverage 2015-08-01 22:01:16 -05:00
kpdecker 15b55a307b Move helpers into separate modules 2015-08-01 17:54:47 -05:00
kpdecker fc13400b6f Remove jshint completely 2015-04-27 10:19:49 -05:00
kpdecker 4bed826d0e Update for let and optional parameters 2015-04-20 02:38:28 -05:00
kpdecker e3d3eda2e1 Add full support for es6
Converts the tool chain to use babel, eslint, and webpack vs. the previous proprietary solutions.

Additionally begins enforcing additional linting concerns as well as updates the code to reflect these rules.

Fixes #855
Fixes #993
2015-04-16 16:43:01 -05:00
kpdecker ab96073c6b Optimize hot path in escapeExpression
Avoid deoptimizations in v8 due to the duct type check on string instances.

Partial fix for #973
2015-03-16 22:06:01 -05:00
kpdecker 0a9fc171b0 Fix block param evaluation under older IE 2014-12-27 13:13:52 -06:00
kpdecker 396795c983 Implement block parameters
Fixes #907
2014-12-26 00:31:57 -06:00
kpdecker 203df9d5b7 Remove unused vars and add jshint checking 2014-12-16 12:57:46 -06:00
kpdecker 01a22e61df Use toHTML vs. instanceof checks for SafeString
Allows for us to play nicely in environments such as Node that could have multiple versions of the library loaded. Also allows for implementors to provide their own behavior, provided they know what they are doing.

Fixes #886
2014-11-08 17:46:53 -06:00
kpdecker 4f01f650dc Render false literal as “false”
Fixes #827
2014-08-25 23:35:43 -05:00
kpdecker cb22ee5681 Increase test coverage a touch 2014-08-14 12:25:35 -05:00
kpdecker 49fcf10de2 Add contextPath tracking in builtin helpers 2014-01-17 23:15:18 -06:00
Blake Embrey 13633e7896 Improve usefulness of extend util, properly use namespace property, update setup options to use a hash helper. 2014-01-16 21:24:26 +10:00
kpdecker f17cb3ecac Run jshint on output
Allows us to execute jshint in non-forced mode.
2013-12-01 15:40:08 -06:00
kpdecker eb53f2e844 Allow extend to work with non-prototyped objects
ES6 modules do not extend the Object prototype so this blows up under the latest version of the transpiler.
2013-12-01 11:36:28 -06:00
kpdecker affbcbb79e Unify isArray/isFunction/toString implementations
Restores Array.isArray polyfill for all use cases.

Fixes #645
2013-11-05 18:07:33 -06:00
kpdecker 9769045e04 Cleanup unused var warnings 2013-10-09 03:53:09 -07:00
kpdecker e75839b185 Break safe string out into standalone module 2013-10-01 21:18:10 -05:00
kpdecker 6a23391a9a Break exception class out into a standalone module 2013-10-01 21:14:18 -05:00
kpdecker cb0c45b29f Merge branch 'master' into es6-modules
Conflicts:
	Gruntfile.js
	Rakefile
	dist/handlebars.js
	dist/handlebars.runtime.js
	lib/handlebars.js
	lib/handlebars/base.js
	lib/handlebars/runtime.js
	lib/handlebars/utils.js
	package.json
2013-09-02 18:19:18 -05:00
kpdecker 192887cedc Merge commit '87b5d4ee61605b026506e92c9e8873d867c5f150' into es6-modules
Conflicts:
	dist/handlebars.js
	dist/handlebars.runtime.js
	lib/handlebars/base.js
	lib/handlebars/utils.js
2013-09-02 16:19:28 -05:00
kpdecker 623fdad59f Simplify falsy handling 2013-08-24 22:20:23 -05:00
kpdecker 6e6acaac0d Unify isFunction/isArray handling 2013-08-24 22:20:12 -05:00
kpdecker eb1cda6fdc jshint 2013-08-24 12:06:25 -05:00
Parker Selbert d02c90c0fb Use the ('' + string) form of string coercion
Using string.toString() will throw errors in current versions of Safari
(6.0.5 currently) for some values. The error is a particularly cryptic
"Type Error: type error", which no indication as to the value that
caused the error. By using the '' + string form of coercion the error
doesn't seem to occur.

Depending on the browser used there is a sizable performance increase
in using the concatenation form of coercion. In instances where there
is not a performance improvement (i.e. Firefox), the speed difference
is entirely negligable. See: http://jsperf.com/convert-to-string-bj/3
2013-08-14 22:11:59 -05:00
Yehuda Katz 88ee4757e7 Initial work on ES6 modules 2013-07-01 13:59:58 -07:00
Tommy Messbauer 090ee7c59a added local pointer to handlerbars.utils to allow this to browserify properly for IE 2013-05-09 17:17:34 -05:00
kpdecker 4429ffa9f3 Allow multiple partial and helper registration
Fixes #369
2013-04-07 18:04:51 -05:00
kpdecker 671c07e699 Force toString in escapeExpression
Fixes #211
2013-04-06 14:46:04 -05:00
kpdecker 3e86bb0f64 Remove unnecessary child scopes 2013-02-16 13:08:46 -06:00
Tommy Messbauer 1ca7462497 merge 2013-02-11 23:00:47 -06:00
kpdecker 5f56d6582f Simplify isEmpty 2013-01-13 15:53:06 -06:00
Tommy Messbauer db975b42a0 Merged upstream master and ran unit tests 2012-11-26 10:26:15 -06:00
Tommy Messbauer 7963218495 Factory update with tabs to spaces.. sorry :( 2012-11-26 09:39:08 -06:00
Peter Wagenet 39832c0633 Fix handling of Errors in Chrome 2012-11-02 10:39:49 -07:00
Tommy Messbauer 7c4813b417 Commiting initial factory code 2012-08-29 12:48:22 -05:00
Brian Palmer bd9a84a0b7 properly handle amperstands when HTML escaping
escapeExpression, when given a string like ">", was simply returning
">", not escaping the amperstand. This is incorrect, and makes it
impossible to have Handlebars properly escape a
string like "Escaped, <b> looks like: &lt;b&gt;"

If the intention of the user is to not escape these characters, then
{{{}}} or {{&}} should be used
2012-02-29 11:25:51 -07:00
Peter Wagenet 2ea95ca08d Fixed whitespace and semi-colons 2012-02-08 20:49:49 -08:00
Yehuda Katz 7a0bf9d332 Handlebars errors should copy the message over 2011-12-27 13:18:54 -08:00
kpdecker 4a9270aa38 Fix module loading within node 2011-07-30 12:18:56 -05:00
tomhuda 059a80661d * Remove legacy support for inverse sections as additional parameters.
* Unify inverse and normal block helpers
* Make Handlebars.Exception inherit from JS Error
2011-07-07 23:09:33 -07:00
gleitz be8f4f6fb9 Updated the boolean functions to work with YUI compressor. Linted other files for consistency 2011-06-22 13:54:17 -04:00
Ryan Grove 2f4644529c Remove / from the list of escaped chars and add `.
It's probably fine not to escape /, since its only danger is in ending
entities (like &amp/). This isn't a problem for us, since the badChars
regex won't allow it and the & will get escaped.

It turns out ` can be used to quote attribute values in IE, so it needs
to be escaped along with " and '.
2011-05-09 15:19:23 -07:00
Ryan Grove b291a1ad8c Add ", ', and / to the list of chars that need HTML escaping.
Previously, only < and > were escaped. This meant that any Handlebars
template that used user input in an HTML attribute value was wide open
to a trivial XSS exploit. Note that unquoted attribute values are still
open to attack, but this set of characters at least brings Handlebars in
line with other Mustache implementations and other template languages.

See the OWASP XSS prevention cheat sheet (rule #1) for the rationale
behind escaping these characters:

https://www.owasp.org/index.php/XSS_(Cross_Site_Scripting)_Prevention_Cheat_Sheet
2011-04-25 11:15:53 -07:00