d03b6ecfc4
Disallow access to prototype properties and methods by default.
Access to properties is always checked via
`Object.prototype.hasOwnProperty.call(parent, propertyName)`.
New runtime options:
- **allowedProtoMethods**: a string-to-boolean map of property-names that are allowed if they are methods of the parent object.
- **allowedProtoProperties**: a string-to-boolean map of property-names that are allowed if they are properties but not methods of the parent object.
```js
const template = handlebars.compile('{{aString.trim}}')
const result = template({ aString: ' abc ' })
// result is empty, because trim is defined at String prototype
```
```js
const template = handlebars.compile('{{aString.trim}}')
const result = template({ aString: ' abc ' }, {
allowedProtoMethods: {
trim: true
}
})
// result = 'abc'
```
Implementation details: The method now "container.lookupProperty"
handles the prototype-checks and the white-lists. It is used in
- JavaScriptCompiler#nameLookup
- The "lookup"-helper (passed to all helpers as "options.lookupProperty")
- The "lookup" function at the container, which is used for recursive lookups in "compat" mode
Compatibility:
- **Old precompiled templates work with new runtimes**: The "options.lookupPropery"-function is passed to the helper by a wrapper, not by the compiled templated.
- **New templates work with old runtimes**: The template contains a function that is used as fallback if the "lookupProperty"-function cannot be found at the container. However, the runtime-options "allowedProtoProperties" and "allowedProtoMethods" only work with the newest runtime.
BREAKING CHANGE:
- access to prototype properties is forbidden completely by default
110 lines
3.9 KiB
JavaScript
110 lines
3.9 KiB
JavaScript
describe('javascript-compiler api', function() {
|
|
if (!Handlebars.JavaScriptCompiler) {
|
|
return;
|
|
}
|
|
|
|
describe('#nameLookup', function() {
|
|
var $superName;
|
|
beforeEach(function() {
|
|
$superName = handlebarsEnv.JavaScriptCompiler.prototype.nameLookup;
|
|
});
|
|
afterEach(function() {
|
|
handlebarsEnv.JavaScriptCompiler.prototype.nameLookup = $superName;
|
|
});
|
|
|
|
it('should allow override', function() {
|
|
handlebarsEnv.JavaScriptCompiler.prototype.nameLookup = function(
|
|
parent,
|
|
name
|
|
) {
|
|
return parent + '.bar_' + name;
|
|
};
|
|
/* eslint-disable camelcase */
|
|
shouldCompileTo('{{foo}}', { bar_foo: 'food' }, 'food');
|
|
/* eslint-enable camelcase */
|
|
});
|
|
|
|
// Tests nameLookup dot vs. bracket behavior. Bracket is required in certain cases
|
|
// to avoid errors in older browsers.
|
|
it('should handle reserved words', function() {
|
|
shouldCompileTo('{{foo}} {{~null~}}', { foo: 'food' }, 'food');
|
|
});
|
|
});
|
|
describe('#compilerInfo', function() {
|
|
var $superCheck, $superInfo;
|
|
beforeEach(function() {
|
|
$superCheck = handlebarsEnv.VM.checkRevision;
|
|
$superInfo = handlebarsEnv.JavaScriptCompiler.prototype.compilerInfo;
|
|
});
|
|
afterEach(function() {
|
|
handlebarsEnv.VM.checkRevision = $superCheck;
|
|
handlebarsEnv.JavaScriptCompiler.prototype.compilerInfo = $superInfo;
|
|
});
|
|
it('should allow compilerInfo override', function() {
|
|
handlebarsEnv.JavaScriptCompiler.prototype.compilerInfo = function() {
|
|
return 'crazy';
|
|
};
|
|
handlebarsEnv.VM.checkRevision = function(compilerInfo) {
|
|
if (compilerInfo !== 'crazy') {
|
|
throw new Error("It didn't work");
|
|
}
|
|
};
|
|
shouldCompileTo('{{foo}} ', { foo: 'food' }, 'food ');
|
|
});
|
|
});
|
|
describe('buffer', function() {
|
|
var $superAppend, $superCreate;
|
|
beforeEach(function() {
|
|
handlebarsEnv.JavaScriptCompiler.prototype.forceBuffer = true;
|
|
$superAppend = handlebarsEnv.JavaScriptCompiler.prototype.appendToBuffer;
|
|
$superCreate =
|
|
handlebarsEnv.JavaScriptCompiler.prototype.initializeBuffer;
|
|
});
|
|
afterEach(function() {
|
|
handlebarsEnv.JavaScriptCompiler.prototype.forceBuffer = false;
|
|
handlebarsEnv.JavaScriptCompiler.prototype.appendToBuffer = $superAppend;
|
|
handlebarsEnv.JavaScriptCompiler.prototype.initializeBuffer = $superCreate;
|
|
});
|
|
|
|
it('should allow init buffer override', function() {
|
|
handlebarsEnv.JavaScriptCompiler.prototype.initializeBuffer = function() {
|
|
return this.quotedString('foo_');
|
|
};
|
|
shouldCompileTo('{{foo}} ', { foo: 'food' }, 'foo_food ');
|
|
});
|
|
it('should allow append buffer override', function() {
|
|
handlebarsEnv.JavaScriptCompiler.prototype.appendToBuffer = function(
|
|
string
|
|
) {
|
|
return $superAppend.call(this, [string, ' + "_foo"']);
|
|
};
|
|
shouldCompileTo('{{foo}}', { foo: 'food' }, 'food_foo');
|
|
});
|
|
});
|
|
|
|
describe('#isValidJavaScriptVariableName', function() {
|
|
// It is there and accessible and could be used by someone. That's why we don't remove it
|
|
// it 4.x. But if we keep it, we add a test
|
|
// This test should not encourage you to use the function. It is not needed any more
|
|
// and might be removed in 5.0
|
|
['test', 'abc123', 'abc_123'].forEach(function(validVariableName) {
|
|
it("should return true for '" + validVariableName + "'", function() {
|
|
expect(
|
|
handlebarsEnv.JavaScriptCompiler.isValidJavaScriptVariableName(
|
|
validVariableName
|
|
)
|
|
).to.be.true();
|
|
});
|
|
});
|
|
[('123test', 'abc()', 'abc.cde')].forEach(function(invalidVariableName) {
|
|
it("should return true for '" + invalidVariableName + "'", function() {
|
|
expect(
|
|
handlebarsEnv.JavaScriptCompiler.isValidJavaScriptVariableName(
|
|
invalidVariableName
|
|
)
|
|
).to.be.false();
|
|
});
|
|
});
|
|
});
|
|
});
|