PluginProbe
WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance / 4.7.0
WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance v4.7.0
4.7.0 4.6.1 4.6.0 4.5.5 4.5.4 4.5.3 4.5.2 3.2.20 3.2.21 3.2.22 3.2.3 3.2.5 3.2.6 3.2.7 3.2.9 3.3.0 3.3.1 3.3.2 3.4.0 3.4.1 3.4.2 3.5.0 3.6.0 3.7.0 3.7.1 All 111 releases
← All changes | js/handlebars/handlebars.js +164 -110 3.2.21 → 4.7.0 View file →
@@ -1,8 +1,8 @@
1 1 /**!
2 2
3 3 @license
4 - handlebars v4.7.8
4 + handlebars v4.7.9
5 5
6 6 Copyright (C) 2011-2019 by Yehuda Katz
7 7
8 8 Permission is hereby granted, free of charge, to any person obtaining a copy
@@ -91,25 +91,25 @@
91 91 var _handlebarsRuntime2 = _interopRequireDefault(_handlebarsRuntime);
92 92
93 93 // Compiler imports
94 94
95 - var _handlebarsCompilerAst = __webpack_require__(84);
95 + var _handlebarsCompilerAst = __webpack_require__(83);
96 96
97 97 var _handlebarsCompilerAst2 = _interopRequireDefault(_handlebarsCompilerAst);
98 98
99 - var _handlebarsCompilerBase = __webpack_require__(85);
99 + var _handlebarsCompilerBase = __webpack_require__(84);
100 100
101 - var _handlebarsCompilerCompiler = __webpack_require__(90);
101 + var _handlebarsCompilerCompiler = __webpack_require__(89);
102 102
103 - var _handlebarsCompilerJavascriptCompiler = __webpack_require__(91);
103 + var _handlebarsCompilerJavascriptCompiler = __webpack_require__(90);
104 104
105 105 var _handlebarsCompilerJavascriptCompiler2 = _interopRequireDefault(_handlebarsCompilerJavascriptCompiler);
106 106
107 - var _handlebarsCompilerVisitor = __webpack_require__(88);
107 + var _handlebarsCompilerVisitor = __webpack_require__(87);
108 108
109 109 var _handlebarsCompilerVisitor2 = _interopRequireDefault(_handlebarsCompilerVisitor);
110 110
111 - var _handlebarsNoConflict = __webpack_require__(83);
111 + var _handlebarsNoConflict = __webpack_require__(82);
112 112
113 113 var _handlebarsNoConflict2 = _interopRequireDefault(_handlebarsNoConflict);
114 114
115 115 var _create = _handlebarsRuntime2['default'].create;
@@ -177,9 +177,9 @@
177 177
178 178 // Each of these augment the Handlebars object. No need to setup here.
179 179 // (This is done to easily share code between commonjs and browse envs)
180 180
181 - var _handlebarsSafeString = __webpack_require__(77);
181 + var _handlebarsSafeString = __webpack_require__(76);
182 182
183 183 var _handlebarsSafeString2 = _interopRequireDefault(_handlebarsSafeString);
184 184
185 185 var _handlebarsException = __webpack_require__(6);
@@ -189,13 +189,13 @@
189 189 var _handlebarsUtils = __webpack_require__(5);
190 190
191 191 var Utils = _interopRequireWildcard(_handlebarsUtils);
192 192
193 - var _handlebarsRuntime = __webpack_require__(78);
193 + var _handlebarsRuntime = __webpack_require__(77);
194 194
195 195 var runtime = _interopRequireWildcard(_handlebarsRuntime);
196 196
197 - var _handlebarsNoConflict = __webpack_require__(83);
197 + var _handlebarsNoConflict = __webpack_require__(82);
198 198
199 199 var _handlebarsNoConflict2 = _interopRequireDefault(_handlebarsNoConflict);
200 200
201 201 // For compatibility and usage outside of module systems, make the Handlebars object a namespace
@@ -277,9 +277,9 @@
277 277 var _logger2 = _interopRequireDefault(_logger);
278 278
279 279 var _internalProtoAccess = __webpack_require__(73);
280 280
281 - var VERSION = '4.7.8';
281 + var VERSION = '4.7.9';
282 282 exports.VERSION = VERSION;
283 283 var COMPILER_REVISION = 8;
284 284 exports.COMPILER_REVISION = COMPILER_REVISION;
285 285 var LAST_COMPATIBLE_COMPILER_REVISION = 7;
@@ -654,9 +654,10 @@
654 654 function moveHelperToHooks(instance, helperName, keepHelper) {
655 655 if (instance.helpers[helperName]) {
656 656 instance.hooks[helperName] = instance.helpers[helperName];
657 657 if (!keepHelper) {
658 - delete instance.helpers[helperName];
658 + // Using delete is slow
659 + instance.helpers[helperName] = undefined;
659 660 }
660 661 }
661 662 }
662 663
@@ -2040,9 +2041,9 @@
2040 2041 exports.createProtoAccessControl = createProtoAccessControl;
2041 2042 exports.resultIsAllowed = resultIsAllowed;
2042 2043 exports.resetLoggedProperties = resetLoggedProperties;
2043 2044
2044 - var _createNewLookupObject = __webpack_require__(76);
2045 + var _utils = __webpack_require__(5);
2045 2046
2046 2047 var _logger = __webpack_require__(72);
2047 2048
2048 2049 var _logger2 = _interopRequireDefault(_logger);
@@ -2049,25 +2050,30 @@
2049 2050
2050 2051 var loggedProperties = _Object$create(null);
2051 2052
2052 2053 function createProtoAccessControl(runtimeOptions) {
2053 - var defaultMethodWhiteList = _Object$create(null);
2054 - defaultMethodWhiteList['constructor'] = false;
2055 - defaultMethodWhiteList['__defineGetter__'] = false;
2056 - defaultMethodWhiteList['__defineSetter__'] = false;
2057 - defaultMethodWhiteList['__lookupGetter__'] = false;
2054 + // Create an object with "null"-prototype to avoid truthy results on
2055 + // prototype properties.
2056 + var propertyWhiteList = _Object$create(null);
2057 + // eslint-disable-next-line no-proto
2058 + propertyWhiteList['__proto__'] = false;
2059 + _utils.extend(propertyWhiteList, runtimeOptions.allowedProtoProperties);
2058 2060
2059 - var defaultPropertyWhiteList = _Object$create(null);
2060 - // eslint-disable-next-line no-proto
2061 - defaultPropertyWhiteList['__proto__'] = false;
2061 + var methodWhiteList = _Object$create(null);
2062 + methodWhiteList['constructor'] = false;
2063 + methodWhiteList['__defineGetter__'] = false;
2064 + methodWhiteList['__defineSetter__'] = false;
2065 + methodWhiteList['__lookupGetter__'] = false;
2066 + methodWhiteList['__lookupSetter__'] = false;
2067 + _utils.extend(methodWhiteList, runtimeOptions.allowedProtoMethods);
2062 2068
2063 2069 return {
2064 2070 properties: {
2065 - whitelist: _createNewLookupObject.createNewLookupObject(defaultPropertyWhiteList, runtimeOptions.allowedProtoProperties),
2071 + whitelist: propertyWhiteList,
2066 2072 defaultValue: runtimeOptions.allowProtoPropertiesByDefault
2067 2073 },
2068 2074 methods: {
2069 - whitelist: _createNewLookupObject.createNewLookupObject(defaultMethodWhiteList, runtimeOptions.allowedProtoMethods),
2075 + whitelist: methodWhiteList,
2070 2076 defaultValue: runtimeOptions.allowProtoMethodsByDefault
2071 2077 }
2072 2078 };
2073 2079 }
@@ -2120,36 +2126,8 @@
2120 2126 };
2121 2127
2122 2128 /***/ }),
2123 2129 /* 76 */
2124 -/***/ (function(module, exports, __webpack_require__) {
2125 -
2126 - 'use strict';
2127 -
2128 - var _Object$create = __webpack_require__(74)['default'];
2129 -
2130 - exports.__esModule = true;
2131 - exports.createNewLookupObject = createNewLookupObject;
2132 -
2133 - var _utils = __webpack_require__(5);
2134 -
2135 - /**
2136 - * Create a new object with "null"-prototype to avoid truthy results on prototype properties.
2137 - * The resulting object can be used with "object[property]" to check if a property exists
2138 - * @param {...object} sources a varargs parameter of source objects that will be merged
2139 - * @returns {object}
2140 - */
2141 -
2142 - function createNewLookupObject() {
2143 - for (var _len = arguments.length, sources = Array(_len), _key = 0; _key < _len; _key++) {
2144 - sources[_key] = arguments[_key];
2145 - }
2146 -
2147 - return _utils.extend.apply(undefined, [_Object$create(null)].concat(sources));
2148 - }
2149 -
2150 -/***/ }),
2151 -/* 77 */
2152 2130 /***/ (function(module, exports) {
2153 2131
2154 2132 // Build out our basic SafeString type
2155 2133 'use strict';
@@ -2166,14 +2144,14 @@
2166 2144 exports['default'] = SafeString;
2167 2145 module.exports = exports['default'];
2168 2146
2169 2147 /***/ }),
2170 -/* 78 */
2148 +/* 77 */
2171 2149 /***/ (function(module, exports, __webpack_require__) {
2172 2150
2173 2151 'use strict';
2174 2152
2175 - var _Object$seal = __webpack_require__(79)['default'];
2153 + var _Object$seal = __webpack_require__(78)['default'];
2176 2154
2177 2155 var _Object$keys = __webpack_require__(60)['default'];
2178 2156
2179 2157 var _interopRequireWildcard = __webpack_require__(3)['default'];
@@ -2199,9 +2177,9 @@
2199 2177 var _base = __webpack_require__(4);
2200 2178
2201 2179 var _helpers = __webpack_require__(10);
2202 2180
2203 - var _internalWrapHelper = __webpack_require__(82);
2181 + var _internalWrapHelper = __webpack_require__(81);
2204 2182
2205 2183 var _internalProtoAccess = __webpack_require__(73);
2206 2184
2207 2185 function checkRevision(compilerInfo) {
@@ -2248,18 +2226,16 @@
2248 2226 }
2249 2227 }
2250 2228 partial = env.VM.resolvePartial.call(this, partial, context, options);
2251 2229
2252 - var extendedOptions = Utils.extend({}, options, {
2253 - hooks: this.hooks,
2254 - protoAccessControl: this.protoAccessControl
2255 - });
2230 + options.hooks = this.hooks;
2231 + options.protoAccessControl = this.protoAccessControl;
2256 2232
2257 - var result = env.VM.invokePartial.call(this, partial, context, extendedOptions);
2233 + var result = env.VM.invokePartial.call(this, partial, context, options);
2258 2234
2259 2235 if (result == null && env.compile) {
2260 2236 options.partials[options.name] = env.compile(partial, templateSpec.compilerOptions, env);
2261 - result = options.partials[options.name](context, extendedOptions);
2237 + result = options.partials[options.name](context, options);
2262 2238 }
2263 2239 if (result != null) {
2264 2240 if (options.indent) {
2265 2241 var lines = result.split('\n');
@@ -2306,9 +2282,9 @@
2306 2282 var len = depths.length;
2307 2283 for (var i = 0; i < len; i++) {
2308 2284 var result = depths[i] && container.lookupProperty(depths[i], name);
2309 2285 if (result != null) {
2310 - return depths[i][name];
2286 + return result;
2311 2287 }
2312 2288 }
2313 2289 },
2314 2290 lambda: function lambda(current, context) {
@@ -2388,10 +2364,11 @@
2388 2364 ret.isTop = true;
2389 2365
2390 2366 ret._setup = function (options) {
2391 2367 if (!options.partial) {
2392 - var mergedHelpers = Utils.extend({}, env.helpers, options.helpers);
2393 - wrapHelpersToPassLookupProperty(mergedHelpers, container);
2368 + var mergedHelpers = {};
2369 + addHelpers(mergedHelpers, env.helpers, container);
2370 + addHelpers(mergedHelpers, options.helpers, container);
2394 2371 container.helpers = mergedHelpers;
2395 2372
2396 2373 if (templateSpec.usePartial) {
2397 2374 // Use mergeIfNeeded here to prevent compiling global partials multiple times
@@ -2455,16 +2432,16 @@
2455 2432
2456 2433 function resolvePartial(partial, context, options) {
2457 2434 if (!partial) {
2458 2435 if (options.name === '@partial-block') {
2459 - partial = options.data['partial-block'];
2436 + partial = lookupOwnProperty(options.data, 'partial-block');
2460 2437 } else {
2461 - partial = options.partials[options.name];
2438 + partial = lookupOwnProperty(options.partials, options.name);
2462 2439 }
2463 2440 } else if (!partial.call && !options.name) {
2464 2441 // This is a dynamic partial that returned a string
2465 2442 options.name = partial;
2466 - partial = options.partials[partial];
2443 + partial = lookupOwnProperty(options.partials, partial);
2467 2444 }
2468 2445 return partial;
2469 2446 }
2470 2447
@@ -2469,9 +2446,9 @@
2469 2446 }
2470 2447
2471 2448 function invokePartial(partial, context, options) {
2472 2449 // Use the current closure context to save the partial-block if this partial
2473 - var currentPartialBlock = options.data && options.data['partial-block'];
2450 + var currentPartialBlock = lookupOwnProperty(options.data, 'partial-block');
2474 2451 options.partial = true;
2475 2452 if (options.ids) {
2476 2453 options.data.contextPath = options.ids[0] || options.data.contextPath;
2477 2454 }
@@ -2511,8 +2488,14 @@
2511 2488 function noop() {
2512 2489 return '';
2513 2490 }
2514 2491
2492 + function lookupOwnProperty(obj, name) {
2493 + if (obj && Object.prototype.hasOwnProperty.call(obj, name)) {
2494 + return obj[name];
2495 + }
2496 + }
2497 +
2515 2498 function initData(context, data) {
2516 2499 if (!data || !('root' in data)) {
2517 2500 data = data ? _base.createFrame(data) : {};
2518 2501 data.root = context;
@@ -2528,11 +2511,12 @@
2528 2511 }
2529 2512 return prog;
2530 2513 }
2531 2514
2532 - function wrapHelpersToPassLookupProperty(mergedHelpers, container) {
2533 - _Object$keys(mergedHelpers).forEach(function (helperName) {
2534 - var helper = mergedHelpers[helperName];
2515 + function addHelpers(mergedHelpers, helpers, container) {
2516 + if (!helpers) return;
2517 + _Object$keys(helpers).forEach(function (helperName) {
2518 + var helper = helpers[helperName];
2535 2519 mergedHelpers[helperName] = passLookupPropertyOption(helper, container);
2536 2520 });
2537 2521 }
2538 2522
@@ -2538,27 +2522,28 @@
2538 2522
2539 2523 function passLookupPropertyOption(helper, container) {
2540 2524 var lookupProperty = container.lookupProperty;
2541 2525 return _internalWrapHelper.wrapHelper(helper, function (options) {
2542 - return Utils.extend({ lookupProperty: lookupProperty }, options);
2526 + options.lookupProperty = lookupProperty;
2527 + return options;
2543 2528 });
2544 2529 }
2545 2530
2546 2531 /***/ }),
2547 -/* 79 */
2532 +/* 78 */
2548 2533 /***/ (function(module, exports, __webpack_require__) {
2549 2534
2550 - module.exports = { "default": __webpack_require__(80), __esModule: true };
2535 + module.exports = { "default": __webpack_require__(79), __esModule: true };
2551 2536
2552 2537 /***/ }),
2553 -/* 80 */
2538 +/* 79 */
2554 2539 /***/ (function(module, exports, __webpack_require__) {
2555 2540
2556 - __webpack_require__(81);
2541 + __webpack_require__(80);
2557 2542 module.exports = __webpack_require__(21).Object.seal;
2558 2543
2559 2544 /***/ }),
2560 -/* 81 */
2545 +/* 80 */
2561 2546 /***/ (function(module, exports, __webpack_require__) {
2562 2547
2563 2548 // 19.1.2.17 Object.seal(O)
2564 2549 var isObject = __webpack_require__(40);
@@ -2569,9 +2554,9 @@
2569 2554 };
2570 2555 });
2571 2556
2572 2557 /***/ }),
2573 -/* 82 */
2558 +/* 81 */
2574 2559 /***/ (function(module, exports) {
2575 2560
2576 2561 'use strict';
2577 2562
@@ -2592,9 +2577,9 @@
2592 2577 return wrapper;
2593 2578 }
2594 2579
2595 2580 /***/ }),
2596 -/* 83 */
2581 +/* 82 */
2597 2582 /***/ (function(module, exports) {
2598 2583
2599 2584 /* global globalThis */
2600 2585 'use strict';
@@ -2626,9 +2611,9 @@
2626 2611
2627 2612 module.exports = exports['default'];
2628 2613
2629 2614 /***/ }),
2630 -/* 84 */
2615 +/* 83 */
2631 2616 /***/ (function(module, exports) {
2632 2617
2633 2618 'use strict';
2634 2619
@@ -2661,13 +2646,15 @@
2661 2646 exports['default'] = AST;
2662 2647 module.exports = exports['default'];
2663 2648
2664 2649 /***/ }),
2665 -/* 85 */
2650 +/* 84 */
2666 2651 /***/ (function(module, exports, __webpack_require__) {
2667 2652
2668 2653 'use strict';
2669 2654
2655 + var _Object$keys = __webpack_require__(60)['default'];
2656 +
2670 2657 var _interopRequireDefault = __webpack_require__(1)['default'];
2671 2658
2672 2659 var _interopRequireWildcard = __webpack_require__(3)['default'];
2673 2660
@@ -2674,20 +2661,24 @@
2674 2661 exports.__esModule = true;
2675 2662 exports.parseWithoutProcessing = parseWithoutProcessing;
2676 2663 exports.parse = parse;
2677 2664
2678 - var _parser = __webpack_require__(86);
2665 + var _parser = __webpack_require__(85);
2679 2666
2680 2667 var _parser2 = _interopRequireDefault(_parser);
2681 2668
2682 - var _whitespaceControl = __webpack_require__(87);
2669 + var _whitespaceControl = __webpack_require__(86);
2683 2670
2684 2671 var _whitespaceControl2 = _interopRequireDefault(_whitespaceControl);
2685 2672
2686 - var _helpers = __webpack_require__(89);
2673 + var _helpers = __webpack_require__(88);
2687 2674
2688 2675 var Helpers = _interopRequireWildcard(_helpers);
2689 2676
2677 + var _exception = __webpack_require__(6);
2678 +
2679 + var _exception2 = _interopRequireDefault(_exception);
2680 +
2690 2681 var _utils = __webpack_require__(5);
2691 2682
2692 2683 exports.parser = _parser2['default'];
2693 2684
@@ -2696,8 +2687,11 @@
2696 2687
2697 2688 function parseWithoutProcessing(input, options) {
2698 2689 // Just return if an already-compiled AST was passed in.
2699 2690 if (input.type === 'Program') {
2691 + // When a pre-parsed AST is passed in, validate all node values to prevent
2692 + // code injection via type-confused literals.
2693 + validateInputAst(input);
2700 2694 return input;
2701 2695 }
2702 2696
2703 2697 _parser2['default'].yy = yy;
@@ -2718,10 +2712,62 @@
2718 2712
2719 2713 return strip.accept(ast);
2720 2714 }
2721 2715
2716 + function validateInputAst(ast) {
2717 + validateAstNode(ast);
2718 + }
2719 +
2720 + function validateAstNode(node) {
2721 + if (node == null) {
2722 + return;
2723 + }
2724 +
2725 + if (Array.isArray(node)) {
2726 + node.forEach(validateAstNode);
2727 + return;
2728 + }
2729 +
2730 + if (typeof node !== 'object') {
2731 + return;
2732 + }
2733 +
2734 + if (node.type === 'PathExpression') {
2735 + if (!isValidDepth(node.depth)) {
2736 + throw new _exception2['default']('Invalid AST: PathExpression.depth must be an integer');
2737 + }
2738 + if (!Array.isArray(node.parts)) {
2739 + throw new _exception2['default']('Invalid AST: PathExpression.parts must be an array');
2740 + }
2741 + for (var i = 0; i < node.parts.length; i++) {
2742 + if (typeof node.parts[i] !== 'string') {
2743 + throw new _exception2['default']('Invalid AST: PathExpression.parts must only contain strings');
2744 + }
2745 + }
2746 + } else if (node.type === 'NumberLiteral') {
2747 + if (typeof node.value !== 'number' || !isFinite(node.value)) {
2748 + throw new _exception2['default']('Invalid AST: NumberLiteral.value must be a number');
2749 + }
2750 + } else if (node.type === 'BooleanLiteral') {
2751 + if (typeof node.value !== 'boolean') {
2752 + throw new _exception2['default']('Invalid AST: BooleanLiteral.value must be a boolean');
2753 + }
2754 + }
2755 +
2756 + _Object$keys(node).forEach(function (propertyName) {
2757 + if (propertyName === 'loc') {
2758 + return;
2759 + }
2760 + validateAstNode(node[propertyName]);
2761 + });
2762 + }
2763 +
2764 + function isValidDepth(depth) {
2765 + return typeof depth === 'number' && isFinite(depth) && Math.floor(depth) === depth && depth >= 0;
2766 + }
2767 +
2722 2768 /***/ }),
2723 -/* 86 */
2769 +/* 85 */
2724 2770 /***/ (function(module, exports) {
2725 2771
2726 2772 // File ignored in coverage tests via setting in .istanbul.yml
2727 2773 /* Jison generated parser */
@@ -3447,9 +3493,9 @@
3447 3493 return 5;
3448 3494 break;
3449 3495 }
3450 3496 };
3451 - lexer.rules = [/^(?:[^\x00]*?(?=(\{\{)))/, /^(?:[^\x00]+)/, /^(?:[^\x00]{2,}?(?=(\{\{|\\\{\{|\\\\\{\{|$)))/, /^(?:\{\{\{\{(?=[^/]))/, /^(?:\{\{\{\{\/[^\s!"#%-,\.\/;->@\[-\^`\{-~]+(?=[=}\s\/.])\}\}\}\})/, /^(?:[^\x00]+?(?=(\{\{\{\{)))/, /^(?:[\s\S]*?--(~)?\}\})/, /^(?:\()/, /^(?:\))/, /^(?:\{\{\{\{)/, /^(?:\}\}\}\})/, /^(?:\{\{(~)?>)/, /^(?:\{\{(~)?#>)/, /^(?:\{\{(~)?#\*?)/, /^(?:\{\{(~)?\/)/, /^(?:\{\{(~)?\^\s*(~)?\}\})/, /^(?:\{\{(~)?\s*else\s*(~)?\}\})/, /^(?:\{\{(~)?\^)/, /^(?:\{\{(~)?\s*else\b)/, /^(?:\{\{(~)?\{)/, /^(?:\{\{(~)?&)/, /^(?:\{\{(~)?!--)/, /^(?:\{\{(~)?![\s\S]*?\}\})/, /^(?:\{\{(~)?\*?)/, /^(?:=)/, /^(?:\.\.)/, /^(?:\.(?=([=~}\s\/.)|])))/, /^(?:[\/.])/, /^(?:\s+)/, /^(?:\}(~)?\}\})/, /^(?:(~)?\}\})/, /^(?:"(\\["]|[^"])*")/, /^(?:'(\\[']|[^'])*')/, /^(?:@)/, /^(?:true(?=([~}\s)])))/, /^(?:false(?=([~}\s)])))/, /^(?:undefined(?=([~}\s)])))/, /^(?:null(?=([~}\s)])))/, /^(?:-?[0-9]+(?:\.[0-9]+)?(?=([~}\s)])))/, /^(?:as\s+\|)/, /^(?:\|)/, /^(?:([^\s!"#%-,\.\/;->@\[-\^`\{-~]+(?=([=~}\s\/.)|]))))/, /^(?:\[(\\\]|[^\]])*\])/, /^(?:.)/, /^(?:$)/];
3497 + lexer.rules = [/^(?:[^\x00]*?(?=(\{\{)))/, /^(?:[^\x00]+)/, /^(?:[^\x00]{2,}?(?=(\{\{|\\\{\{|\\\\\{\{|$)))/, /^(?:\{\{\{\{(?=[^\/]))/, /^(?:\{\{\{\{\/[^\s!"#%-,\.\/;->@\[-\^`\{-~]+(?=[=}\s\/.])\}\}\}\})/, /^(?:[^\x00]+?(?=(\{\{\{\{)))/, /^(?:[\s\S]*?--(~)?\}\})/, /^(?:\()/, /^(?:\))/, /^(?:\{\{\{\{)/, /^(?:\}\}\}\})/, /^(?:\{\{(~)?>)/, /^(?:\{\{(~)?#>)/, /^(?:\{\{(~)?#\*?)/, /^(?:\{\{(~)?\/)/, /^(?:\{\{(~)?\^\s*(~)?\}\})/, /^(?:\{\{(~)?\s*else\s*(~)?\}\})/, /^(?:\{\{(~)?\^)/, /^(?:\{\{(~)?\s*else\b)/, /^(?:\{\{(~)?\{)/, /^(?:\{\{(~)?&)/, /^(?:\{\{(~)?!--)/, /^(?:\{\{(~)?![\s\S]*?\}\})/, /^(?:\{\{(~)?\*?)/, /^(?:=)/, /^(?:\.\.)/, /^(?:\.(?=([=~}\s\/.)|])))/, /^(?:[\/.])/, /^(?:\s+)/, /^(?:\}(~)?\}\})/, /^(?:(~)?\}\})/, /^(?:"(\\["]|[^"])*")/, /^(?:'(\\[']|[^'])*')/, /^(?:@)/, /^(?:true(?=([~}\s)])))/, /^(?:false(?=([~}\s)])))/, /^(?:undefined(?=([~}\s)])))/, /^(?:null(?=([~}\s)])))/, /^(?:-?[0-9]+(?:\.[0-9]+)?(?=([~}\s)])))/, /^(?:as\s+\|)/, /^(?:\|)/, /^(?:([^\s!"#%-,\.\/;->@\[-\^`\{-~]+(?=([=~}\s\/.)|]))))/, /^(?:\[(\\\]|[^\]])*\])/, /^(?:.)/, /^(?:$)/];
3452 3498 lexer.conditions = { "mu": { "rules": [7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44], "inclusive": false }, "emu": { "rules": [2], "inclusive": false }, "com": { "rules": [6], "inclusive": false }, "raw": { "rules": [3, 4, 5], "inclusive": false }, "INITIAL": { "rules": [0, 1, 44], "inclusive": true } };
3453 3499 return lexer;
3454 3500 })();
3455 3501 parser.lexer = lexer;
@@ -3460,9 +3506,9 @@
3460 3506 })();exports["default"] = handlebars;
3461 3507 module.exports = exports["default"];
3462 3508
3463 3509 /***/ }),
3464 -/* 87 */
3510 +/* 86 */
3465 3511 /***/ (function(module, exports, __webpack_require__) {
3466 3512
3467 3513 'use strict';
3468 3514
@@ -3469,9 +3515,9 @@
3469 3515 var _interopRequireDefault = __webpack_require__(1)['default'];
3470 3516
3471 3517 exports.__esModule = true;
3472 3518
3473 - var _visitor = __webpack_require__(88);
3519 + var _visitor = __webpack_require__(87);
3474 3520
3475 3521 var _visitor2 = _interopRequireDefault(_visitor);
3476 3522
3477 3523 function WhitespaceControl() {
@@ -3684,9 +3730,9 @@
3684 3730 exports['default'] = WhitespaceControl;
3685 3731 module.exports = exports['default'];
3686 3732
3687 3733 /***/ }),
3688 -/* 88 */
3734 +/* 87 */
3689 3735 /***/ (function(module, exports, __webpack_require__) {
3690 3736
3691 3737 'use strict';
3692 3738
@@ -3827,9 +3873,9 @@
3827 3873 exports['default'] = Visitor;
3828 3874 module.exports = exports['default'];
3829 3875
3830 3876 /***/ }),
3831 -/* 89 */
3877 +/* 88 */
3832 3878 /***/ (function(module, exports, __webpack_require__) {
3833 3879
3834 3880 'use strict';
3835 3881
@@ -4058,9 +4104,9 @@
4058 4104 };
4059 4105 }
4060 4106
4061 4107 /***/ }),
4062 -/* 90 */
4108 +/* 89 */
4063 4109 /***/ (function(module, exports, __webpack_require__) {
4064 4110
4065 4111 /* eslint-disable new-cap */
4066 4112
@@ -4080,9 +4126,9 @@
4080 4126 var _exception2 = _interopRequireDefault(_exception);
4081 4127
4082 4128 var _utils = __webpack_require__(5);
4083 4129
4084 - var _ast = __webpack_require__(84);
4130 + var _ast = __webpack_require__(83);
4085 4131
4086 4132 var _ast2 = _interopRequireDefault(_ast);
4087 4133
4088 4134 var slice = [].slice;
@@ -4629,9 +4675,9 @@
4629 4675 }
4630 4676 }
4631 4677
4632 4678 /***/ }),
4633 -/* 91 */
4679 +/* 90 */
4634 4680 /***/ (function(module, exports, __webpack_require__) {
4635 4681
4636 4682 'use strict';
4637 4683
@@ -4648,9 +4694,9 @@
4648 4694 var _exception2 = _interopRequireDefault(_exception);
4649 4695
4650 4696 var _utils = __webpack_require__(5);
4651 4697
4652 - var _codeGen = __webpack_require__(92);
4698 + var _codeGen = __webpack_require__(91);
4653 4699
4654 4700 var _codeGen2 = _interopRequireDefault(_codeGen);
4655 4701
4656 4702 function Literal(value) {
@@ -4793,14 +4839,12 @@
4793 4839 var programs = _context.programs;
4794 4840 var decorators = _context.decorators;
4795 4841
4796 4842 for (i = 0, l = programs.length; i < l; i++) {
4797 - if (programs[i]) {
4798 - ret[i] = programs[i];
4799 - if (decorators[i]) {
4800 - ret[i + '_d'] = decorators[i];
4801 - ret.useDecorators = true;
4802 - }
4843 + ret[i] = programs[i];
4844 + if (decorators[i]) {
4845 + ret[i + '_d'] = decorators[i];
4846 + ret.useDecorators = true;
4803 4847 }
4804 4848 }
4805 4849
4806 4850 if (this.environment.usePartial) {
@@ -5124,22 +5168,23 @@
5124 5168
5125 5169 this.resolvePath('data', parts, 0, true, strict);
5126 5170 },
5127 5171
5128 - resolvePath: function resolvePath(type, parts, i, falsy, strict) {
5172 + resolvePath: function resolvePath(type, parts, startPartIndex, falsy, strict) {
5129 5173 // istanbul ignore next
5130 5174
5131 5175 var _this2 = this;
5132 5176
5133 5177 if (this.options.strict || this.options.assumeObjects) {
5134 - this.push(strictLookup(this.options.strict && strict, this, parts, i, type));
5178 + this.push(strictLookup(this.options.strict && strict, this, parts, startPartIndex, type));
5135 5179 return;
5136 5180 }
5137 5181
5138 5182 var len = parts.length;
5139 - for (; i < len; i++) {
5183 +
5184 + var _loop = function (i) {
5140 5185 /* eslint-disable no-loop-func */
5141 - this.replaceStack(function (current) {
5186 + _this2.replaceStack(function (current) {
5142 5187 var lookup = _this2.nameLookup(current, parts[i], type);
5143 5188 // We want to ensure that zero and false are handled properly if the context (falsy flag)
5144 5189 // needs to have the special handling for these values.
5145 5190 if (!falsy) {
@@ -5149,8 +5194,12 @@
5149 5194 return [' && ', lookup];
5150 5195 }
5151 5196 });
5152 5197 /* eslint-enable no-loop-func */
5198 + };
5199 +
5200 + for (var i = startPartIndex; i < len; i++) {
5201 + _loop(i);
5153 5202 }
5154 5203 },
5155 5204
5156 5205 // [resolvePossibleLambda]
@@ -5266,9 +5315,14 @@
5266 5315 registerDecorator: function registerDecorator(paramSize, name) {
5267 5316 var foundDecorator = this.nameLookup('decorators', name, 'decorator'),
5268 5317 options = this.setupHelperArgs(name, paramSize);
5269 5318
5270 - this.decorators.push(['fn = ', this.decorators.functionCall(foundDecorator, '', ['fn', 'props', 'container', options]), ' || fn;']);
5319 + // Store the resolved decorator in a variable and verify it is a function before
5320 + // calling it. Without this, unregistered decorators can cause an unhandled TypeError
5321 + // (calling undefined), which crashes the process — enabling Denial of Service.
5322 + this.decorators.push(['var decorator = ', foundDecorator, ';']);
5323 + this.decorators.push(['if (typeof decorator !== "function") { throw new Error(', this.quotedString('Missing decorator: "' + name + '"'), '); }']);
5324 + this.decorators.push(['fn = ', this.decorators.functionCall('decorator', '', ['fn', 'props', 'container', options]), ' || fn;']);
5271 5325 },
5272 5326
5273 5327 // [invokeHelper]
5274 5328 //
@@ -5449,10 +5503,10 @@
5449 5503
5450 5504 var existing = this.matchExistingProgram(child);
5451 5505
5452 5506 if (existing == null) {
5453 - this.context.programs.push(''); // Placeholder to prevent name conflicts for nested children
5454 - var index = this.context.programs.length;
5507 + // Placeholder to prevent name conflicts for nested children
5508 + var index = this.context.programs.push('') - 1;
5455 5509 child.index = index;
5456 5510 child.name = 'program' + index;
5457 5511 this.context.programs[index] = compiler.compile(child, options, this.context, !this.precompile);
5458 5512 this.context.decorators[index] = compiler.decorators;
@@ -5770,9 +5824,9 @@
5770 5824 JavaScriptCompiler.isValidJavaScriptVariableName = function (name) {
5771 5825 return !JavaScriptCompiler.RESERVED_WORDS[name] && /^[a-zA-Z_$][0-9a-zA-Z_$]*$/.test(name);
5772 5826 };
5773 5827
5774 - function strictLookup(requireTerminal, compiler, parts, i, type) {
5828 + function strictLookup(requireTerminal, compiler, parts, startPartIndex, type) {
5775 5829 var stack = compiler.popStack(),
5776 5830 len = parts.length;
5777 5831 if (requireTerminal) {
5778 5832 len--;
@@ -5777,14 +5831,14 @@
5777 5831 if (requireTerminal) {
5778 5832 len--;
5779 5833 }
5780 5834
5781 - for (; i < len; i++) {
5835 + for (var i = startPartIndex; i < len; i++) {
5782 5836 stack = compiler.nameLookup(stack, parts[i], type);
5783 5837 }
5784 5838
5785 5839 if (requireTerminal) {
5786 - return [compiler.aliasable('container.strict'), '(', stack, ', ', compiler.quotedString(parts[i]), ', ', JSON.stringify(compiler.source.currentLocation), ' )'];
5840 + return [compiler.aliasable('container.strict'), '(', stack, ', ', compiler.quotedString(parts[len]), ', ', JSON.stringify(compiler.source.currentLocation), ' )'];
5787 5841 } else {
5788 5842 return stack;
5789 5843 }
5790 5844 }
@@ -5792,9 +5846,9 @@
5792 5846 exports['default'] = JavaScriptCompiler;
5793 5847 module.exports = exports['default'];
5794 5848
5795 5849 /***/ }),
5796 -/* 92 */
5850 +/* 91 */
5797 5851 /***/ (function(module, exports, __webpack_require__) {
5798 5852
5799 5853 /* global define, require */
5800 5854 'use strict';