| @@ -1,8 +1,8 @@ | ||
| 1 | 1 | /**! |
| 2 | 2 | |
| 3 | 3 | @license |
| 4 | - handlebars v4.7.8 | |
| 4 | + handlebars v4.7.9 | |
| 5 | 5 | |
| 6 | 6 | Copyright (C) 2011-2019 by Yehuda Katz |
| 7 | 7 | |
| 8 | 8 | Permission is hereby granted, free of charge, to any person obtaining a copy |
| @@ -91,25 +91,25 @@ | ||
| 91 | 91 | var _handlebarsRuntime2 = _interopRequireDefault(_handlebarsRuntime); |
| 92 | 92 | |
| 93 | 93 | // Compiler imports |
| 94 | 94 | |
| 95 | - var _handlebarsCompilerAst = __webpack_require__(84); | |
| 95 | + var _handlebarsCompilerAst = __webpack_require__(83); | |
| 96 | 96 | |
| 97 | 97 | var _handlebarsCompilerAst2 = _interopRequireDefault(_handlebarsCompilerAst); |
| 98 | 98 | |
| 99 | - var _handlebarsCompilerBase = __webpack_require__(85); | |
| 99 | + var _handlebarsCompilerBase = __webpack_require__(84); | |
| 100 | 100 | |
| 101 | - var _handlebarsCompilerCompiler = __webpack_require__(90); | |
| 101 | + var _handlebarsCompilerCompiler = __webpack_require__(89); | |
| 102 | 102 | |
| 103 | - var _handlebarsCompilerJavascriptCompiler = __webpack_require__(91); | |
| 103 | + var _handlebarsCompilerJavascriptCompiler = __webpack_require__(90); | |
| 104 | 104 | |
| 105 | 105 | var _handlebarsCompilerJavascriptCompiler2 = _interopRequireDefault(_handlebarsCompilerJavascriptCompiler); |
| 106 | 106 | |
| 107 | - var _handlebarsCompilerVisitor = __webpack_require__(88); | |
| 107 | + var _handlebarsCompilerVisitor = __webpack_require__(87); | |
| 108 | 108 | |
| 109 | 109 | var _handlebarsCompilerVisitor2 = _interopRequireDefault(_handlebarsCompilerVisitor); |
| 110 | 110 | |
| 111 | - var _handlebarsNoConflict = __webpack_require__(83); | |
| 111 | + var _handlebarsNoConflict = __webpack_require__(82); | |
| 112 | 112 | |
| 113 | 113 | var _handlebarsNoConflict2 = _interopRequireDefault(_handlebarsNoConflict); |
| 114 | 114 | |
| 115 | 115 | var _create = _handlebarsRuntime2['default'].create; |
| @@ -177,9 +177,9 @@ | ||
| 177 | 177 | |
| 178 | 178 | // Each of these augment the Handlebars object. No need to setup here. |
| 179 | 179 | // (This is done to easily share code between commonjs and browse envs) |
| 180 | 180 | |
| 181 | - var _handlebarsSafeString = __webpack_require__(77); | |
| 181 | + var _handlebarsSafeString = __webpack_require__(76); | |
| 182 | 182 | |
| 183 | 183 | var _handlebarsSafeString2 = _interopRequireDefault(_handlebarsSafeString); |
| 184 | 184 | |
| 185 | 185 | var _handlebarsException = __webpack_require__(6); |
| @@ -189,13 +189,13 @@ | ||
| 189 | 189 | var _handlebarsUtils = __webpack_require__(5); |
| 190 | 190 | |
| 191 | 191 | var Utils = _interopRequireWildcard(_handlebarsUtils); |
| 192 | 192 | |
| 193 | - var _handlebarsRuntime = __webpack_require__(78); | |
| 193 | + var _handlebarsRuntime = __webpack_require__(77); | |
| 194 | 194 | |
| 195 | 195 | var runtime = _interopRequireWildcard(_handlebarsRuntime); |
| 196 | 196 | |
| 197 | - var _handlebarsNoConflict = __webpack_require__(83); | |
| 197 | + var _handlebarsNoConflict = __webpack_require__(82); | |
| 198 | 198 | |
| 199 | 199 | var _handlebarsNoConflict2 = _interopRequireDefault(_handlebarsNoConflict); |
| 200 | 200 | |
| 201 | 201 | // For compatibility and usage outside of module systems, make the Handlebars object a namespace |
| @@ -277,9 +277,9 @@ | ||
| 277 | 277 | var _logger2 = _interopRequireDefault(_logger); |
| 278 | 278 | |
| 279 | 279 | var _internalProtoAccess = __webpack_require__(73); |
| 280 | 280 | |
| 281 | - var VERSION = '4.7.8'; | |
| 281 | + var VERSION = '4.7.9'; | |
| 282 | 282 | exports.VERSION = VERSION; |
| 283 | 283 | var COMPILER_REVISION = 8; |
| 284 | 284 | exports.COMPILER_REVISION = COMPILER_REVISION; |
| 285 | 285 | var LAST_COMPATIBLE_COMPILER_REVISION = 7; |
| @@ -654,9 +654,10 @@ | ||
| 654 | 654 | function moveHelperToHooks(instance, helperName, keepHelper) { |
| 655 | 655 | if (instance.helpers[helperName]) { |
| 656 | 656 | instance.hooks[helperName] = instance.helpers[helperName]; |
| 657 | 657 | if (!keepHelper) { |
| 658 | - delete instance.helpers[helperName]; | |
| 658 | + // Using delete is slow | |
| 659 | + instance.helpers[helperName] = undefined; | |
| 659 | 660 | } |
| 660 | 661 | } |
| 661 | 662 | } |
| 662 | 663 | |
| @@ -2040,9 +2041,9 @@ | ||
| 2040 | 2041 | exports.createProtoAccessControl = createProtoAccessControl; |
| 2041 | 2042 | exports.resultIsAllowed = resultIsAllowed; |
| 2042 | 2043 | exports.resetLoggedProperties = resetLoggedProperties; |
| 2043 | 2044 | |
| 2044 | - var _createNewLookupObject = __webpack_require__(76); | |
| 2045 | + var _utils = __webpack_require__(5); | |
| 2045 | 2046 | |
| 2046 | 2047 | var _logger = __webpack_require__(72); |
| 2047 | 2048 | |
| 2048 | 2049 | var _logger2 = _interopRequireDefault(_logger); |
| @@ -2049,25 +2050,30 @@ | ||
| 2049 | 2050 | |
| 2050 | 2051 | var loggedProperties = _Object$create(null); |
| 2051 | 2052 | |
| 2052 | 2053 | function createProtoAccessControl(runtimeOptions) { |
| 2053 | - var defaultMethodWhiteList = _Object$create(null); | |
| 2054 | - defaultMethodWhiteList['constructor'] = false; | |
| 2055 | - defaultMethodWhiteList['__defineGetter__'] = false; | |
| 2056 | - defaultMethodWhiteList['__defineSetter__'] = false; | |
| 2057 | - defaultMethodWhiteList['__lookupGetter__'] = false; | |
| 2054 | + // Create an object with "null"-prototype to avoid truthy results on | |
| 2055 | + // prototype properties. | |
| 2056 | + var propertyWhiteList = _Object$create(null); | |
| 2057 | + // eslint-disable-next-line no-proto | |
| 2058 | + propertyWhiteList['__proto__'] = false; | |
| 2059 | + _utils.extend(propertyWhiteList, runtimeOptions.allowedProtoProperties); | |
| 2058 | 2060 | |
| 2059 | - var defaultPropertyWhiteList = _Object$create(null); | |
| 2060 | - // eslint-disable-next-line no-proto | |
| 2061 | - defaultPropertyWhiteList['__proto__'] = false; | |
| 2061 | + var methodWhiteList = _Object$create(null); | |
| 2062 | + methodWhiteList['constructor'] = false; | |
| 2063 | + methodWhiteList['__defineGetter__'] = false; | |
| 2064 | + methodWhiteList['__defineSetter__'] = false; | |
| 2065 | + methodWhiteList['__lookupGetter__'] = false; | |
| 2066 | + methodWhiteList['__lookupSetter__'] = false; | |
| 2067 | + _utils.extend(methodWhiteList, runtimeOptions.allowedProtoMethods); | |
| 2062 | 2068 | |
| 2063 | 2069 | return { |
| 2064 | 2070 | properties: { |
| 2065 | - whitelist: _createNewLookupObject.createNewLookupObject(defaultPropertyWhiteList, runtimeOptions.allowedProtoProperties), | |
| 2071 | + whitelist: propertyWhiteList, | |
| 2066 | 2072 | defaultValue: runtimeOptions.allowProtoPropertiesByDefault |
| 2067 | 2073 | }, |
| 2068 | 2074 | methods: { |
| 2069 | - whitelist: _createNewLookupObject.createNewLookupObject(defaultMethodWhiteList, runtimeOptions.allowedProtoMethods), | |
| 2075 | + whitelist: methodWhiteList, | |
| 2070 | 2076 | defaultValue: runtimeOptions.allowProtoMethodsByDefault |
| 2071 | 2077 | } |
| 2072 | 2078 | }; |
| 2073 | 2079 | } |
| @@ -2120,36 +2126,8 @@ | ||
| 2120 | 2126 | }; |
| 2121 | 2127 | |
| 2122 | 2128 | /***/ }), |
| 2123 | 2129 | /* 76 */ |
| 2124 | -/***/ (function(module, exports, __webpack_require__) { | |
| 2125 | - | |
| 2126 | - 'use strict'; | |
| 2127 | - | |
| 2128 | - var _Object$create = __webpack_require__(74)['default']; | |
| 2129 | - | |
| 2130 | - exports.__esModule = true; | |
| 2131 | - exports.createNewLookupObject = createNewLookupObject; | |
| 2132 | - | |
| 2133 | - var _utils = __webpack_require__(5); | |
| 2134 | - | |
| 2135 | - /** | |
| 2136 | - * Create a new object with "null"-prototype to avoid truthy results on prototype properties. | |
| 2137 | - * The resulting object can be used with "object[property]" to check if a property exists | |
| 2138 | - * @param {...object} sources a varargs parameter of source objects that will be merged | |
| 2139 | - * @returns {object} | |
| 2140 | - */ | |
| 2141 | - | |
| 2142 | - function createNewLookupObject() { | |
| 2143 | - for (var _len = arguments.length, sources = Array(_len), _key = 0; _key < _len; _key++) { | |
| 2144 | - sources[_key] = arguments[_key]; | |
| 2145 | - } | |
| 2146 | - | |
| 2147 | - return _utils.extend.apply(undefined, [_Object$create(null)].concat(sources)); | |
| 2148 | - } | |
| 2149 | - | |
| 2150 | -/***/ }), | |
| 2151 | -/* 77 */ | |
| 2152 | 2130 | /***/ (function(module, exports) { |
| 2153 | 2131 | |
| 2154 | 2132 | // Build out our basic SafeString type |
| 2155 | 2133 | 'use strict'; |
| @@ -2166,14 +2144,14 @@ | ||
| 2166 | 2144 | exports['default'] = SafeString; |
| 2167 | 2145 | module.exports = exports['default']; |
| 2168 | 2146 | |
| 2169 | 2147 | /***/ }), |
| 2170 | -/* 78 */ | |
| 2148 | +/* 77 */ | |
| 2171 | 2149 | /***/ (function(module, exports, __webpack_require__) { |
| 2172 | 2150 | |
| 2173 | 2151 | 'use strict'; |
| 2174 | 2152 | |
| 2175 | - var _Object$seal = __webpack_require__(79)['default']; | |
| 2153 | + var _Object$seal = __webpack_require__(78)['default']; | |
| 2176 | 2154 | |
| 2177 | 2155 | var _Object$keys = __webpack_require__(60)['default']; |
| 2178 | 2156 | |
| 2179 | 2157 | var _interopRequireWildcard = __webpack_require__(3)['default']; |
| @@ -2199,9 +2177,9 @@ | ||
| 2199 | 2177 | var _base = __webpack_require__(4); |
| 2200 | 2178 | |
| 2201 | 2179 | var _helpers = __webpack_require__(10); |
| 2202 | 2180 | |
| 2203 | - var _internalWrapHelper = __webpack_require__(82); | |
| 2181 | + var _internalWrapHelper = __webpack_require__(81); | |
| 2204 | 2182 | |
| 2205 | 2183 | var _internalProtoAccess = __webpack_require__(73); |
| 2206 | 2184 | |
| 2207 | 2185 | function checkRevision(compilerInfo) { |
| @@ -2248,18 +2226,16 @@ | ||
| 2248 | 2226 | } |
| 2249 | 2227 | } |
| 2250 | 2228 | partial = env.VM.resolvePartial.call(this, partial, context, options); |
| 2251 | 2229 | |
| 2252 | - var extendedOptions = Utils.extend({}, options, { | |
| 2253 | - hooks: this.hooks, | |
| 2254 | - protoAccessControl: this.protoAccessControl | |
| 2255 | - }); | |
| 2230 | + options.hooks = this.hooks; | |
| 2231 | + options.protoAccessControl = this.protoAccessControl; | |
| 2256 | 2232 | |
| 2257 | - var result = env.VM.invokePartial.call(this, partial, context, extendedOptions); | |
| 2233 | + var result = env.VM.invokePartial.call(this, partial, context, options); | |
| 2258 | 2234 | |
| 2259 | 2235 | if (result == null && env.compile) { |
| 2260 | 2236 | options.partials[options.name] = env.compile(partial, templateSpec.compilerOptions, env); |
| 2261 | - result = options.partials[options.name](context, extendedOptions); | |
| 2237 | + result = options.partials[options.name](context, options); | |
| 2262 | 2238 | } |
| 2263 | 2239 | if (result != null) { |
| 2264 | 2240 | if (options.indent) { |
| 2265 | 2241 | var lines = result.split('\n'); |
| @@ -2306,9 +2282,9 @@ | ||
| 2306 | 2282 | var len = depths.length; |
| 2307 | 2283 | for (var i = 0; i < len; i++) { |
| 2308 | 2284 | var result = depths[i] && container.lookupProperty(depths[i], name); |
| 2309 | 2285 | if (result != null) { |
| 2310 | - return depths[i][name]; | |
| 2286 | + return result; | |
| 2311 | 2287 | } |
| 2312 | 2288 | } |
| 2313 | 2289 | }, |
| 2314 | 2290 | lambda: function lambda(current, context) { |
| @@ -2388,10 +2364,11 @@ | ||
| 2388 | 2364 | ret.isTop = true; |
| 2389 | 2365 | |
| 2390 | 2366 | ret._setup = function (options) { |
| 2391 | 2367 | if (!options.partial) { |
| 2392 | - var mergedHelpers = Utils.extend({}, env.helpers, options.helpers); | |
| 2393 | - wrapHelpersToPassLookupProperty(mergedHelpers, container); | |
| 2368 | + var mergedHelpers = {}; | |
| 2369 | + addHelpers(mergedHelpers, env.helpers, container); | |
| 2370 | + addHelpers(mergedHelpers, options.helpers, container); | |
| 2394 | 2371 | container.helpers = mergedHelpers; |
| 2395 | 2372 | |
| 2396 | 2373 | if (templateSpec.usePartial) { |
| 2397 | 2374 | // Use mergeIfNeeded here to prevent compiling global partials multiple times |
| @@ -2455,16 +2432,16 @@ | ||
| 2455 | 2432 | |
| 2456 | 2433 | function resolvePartial(partial, context, options) { |
| 2457 | 2434 | if (!partial) { |
| 2458 | 2435 | if (options.name === '@partial-block') { |
| 2459 | - partial = options.data['partial-block']; | |
| 2436 | + partial = lookupOwnProperty(options.data, 'partial-block'); | |
| 2460 | 2437 | } else { |
| 2461 | - partial = options.partials[options.name]; | |
| 2438 | + partial = lookupOwnProperty(options.partials, options.name); | |
| 2462 | 2439 | } |
| 2463 | 2440 | } else if (!partial.call && !options.name) { |
| 2464 | 2441 | // This is a dynamic partial that returned a string |
| 2465 | 2442 | options.name = partial; |
| 2466 | - partial = options.partials[partial]; | |
| 2443 | + partial = lookupOwnProperty(options.partials, partial); | |
| 2467 | 2444 | } |
| 2468 | 2445 | return partial; |
| 2469 | 2446 | } |
| 2470 | 2447 | |
| @@ -2469,9 +2446,9 @@ | ||
| 2469 | 2446 | } |
| 2470 | 2447 | |
| 2471 | 2448 | function invokePartial(partial, context, options) { |
| 2472 | 2449 | // Use the current closure context to save the partial-block if this partial |
| 2473 | - var currentPartialBlock = options.data && options.data['partial-block']; | |
| 2450 | + var currentPartialBlock = lookupOwnProperty(options.data, 'partial-block'); | |
| 2474 | 2451 | options.partial = true; |
| 2475 | 2452 | if (options.ids) { |
| 2476 | 2453 | options.data.contextPath = options.ids[0] || options.data.contextPath; |
| 2477 | 2454 | } |
| @@ -2511,8 +2488,14 @@ | ||
| 2511 | 2488 | function noop() { |
| 2512 | 2489 | return ''; |
| 2513 | 2490 | } |
| 2514 | 2491 | |
| 2492 | + function lookupOwnProperty(obj, name) { | |
| 2493 | + if (obj && Object.prototype.hasOwnProperty.call(obj, name)) { | |
| 2494 | + return obj[name]; | |
| 2495 | + } | |
| 2496 | + } | |
| 2497 | + | |
| 2515 | 2498 | function initData(context, data) { |
| 2516 | 2499 | if (!data || !('root' in data)) { |
| 2517 | 2500 | data = data ? _base.createFrame(data) : {}; |
| 2518 | 2501 | data.root = context; |
| @@ -2528,11 +2511,12 @@ | ||
| 2528 | 2511 | } |
| 2529 | 2512 | return prog; |
| 2530 | 2513 | } |
| 2531 | 2514 | |
| 2532 | - function wrapHelpersToPassLookupProperty(mergedHelpers, container) { | |
| 2533 | - _Object$keys(mergedHelpers).forEach(function (helperName) { | |
| 2534 | - var helper = mergedHelpers[helperName]; | |
| 2515 | + function addHelpers(mergedHelpers, helpers, container) { | |
| 2516 | + if (!helpers) return; | |
| 2517 | + _Object$keys(helpers).forEach(function (helperName) { | |
| 2518 | + var helper = helpers[helperName]; | |
| 2535 | 2519 | mergedHelpers[helperName] = passLookupPropertyOption(helper, container); |
| 2536 | 2520 | }); |
| 2537 | 2521 | } |
| 2538 | 2522 | |
| @@ -2538,27 +2522,28 @@ | ||
| 2538 | 2522 | |
| 2539 | 2523 | function passLookupPropertyOption(helper, container) { |
| 2540 | 2524 | var lookupProperty = container.lookupProperty; |
| 2541 | 2525 | return _internalWrapHelper.wrapHelper(helper, function (options) { |
| 2542 | - return Utils.extend({ lookupProperty: lookupProperty }, options); | |
| 2526 | + options.lookupProperty = lookupProperty; | |
| 2527 | + return options; | |
| 2543 | 2528 | }); |
| 2544 | 2529 | } |
| 2545 | 2530 | |
| 2546 | 2531 | /***/ }), |
| 2547 | -/* 79 */ | |
| 2532 | +/* 78 */ | |
| 2548 | 2533 | /***/ (function(module, exports, __webpack_require__) { |
| 2549 | 2534 | |
| 2550 | - module.exports = { "default": __webpack_require__(80), __esModule: true }; | |
| 2535 | + module.exports = { "default": __webpack_require__(79), __esModule: true }; | |
| 2551 | 2536 | |
| 2552 | 2537 | /***/ }), |
| 2553 | -/* 80 */ | |
| 2538 | +/* 79 */ | |
| 2554 | 2539 | /***/ (function(module, exports, __webpack_require__) { |
| 2555 | 2540 | |
| 2556 | - __webpack_require__(81); | |
| 2541 | + __webpack_require__(80); | |
| 2557 | 2542 | module.exports = __webpack_require__(21).Object.seal; |
| 2558 | 2543 | |
| 2559 | 2544 | /***/ }), |
| 2560 | -/* 81 */ | |
| 2545 | +/* 80 */ | |
| 2561 | 2546 | /***/ (function(module, exports, __webpack_require__) { |
| 2562 | 2547 | |
| 2563 | 2548 | // 19.1.2.17 Object.seal(O) |
| 2564 | 2549 | var isObject = __webpack_require__(40); |
| @@ -2569,9 +2554,9 @@ | ||
| 2569 | 2554 | }; |
| 2570 | 2555 | }); |
| 2571 | 2556 | |
| 2572 | 2557 | /***/ }), |
| 2573 | -/* 82 */ | |
| 2558 | +/* 81 */ | |
| 2574 | 2559 | /***/ (function(module, exports) { |
| 2575 | 2560 | |
| 2576 | 2561 | 'use strict'; |
| 2577 | 2562 | |
| @@ -2592,9 +2577,9 @@ | ||
| 2592 | 2577 | return wrapper; |
| 2593 | 2578 | } |
| 2594 | 2579 | |
| 2595 | 2580 | /***/ }), |
| 2596 | -/* 83 */ | |
| 2581 | +/* 82 */ | |
| 2597 | 2582 | /***/ (function(module, exports) { |
| 2598 | 2583 | |
| 2599 | 2584 | /* global globalThis */ |
| 2600 | 2585 | 'use strict'; |
| @@ -2626,9 +2611,9 @@ | ||
| 2626 | 2611 | |
| 2627 | 2612 | module.exports = exports['default']; |
| 2628 | 2613 | |
| 2629 | 2614 | /***/ }), |
| 2630 | -/* 84 */ | |
| 2615 | +/* 83 */ | |
| 2631 | 2616 | /***/ (function(module, exports) { |
| 2632 | 2617 | |
| 2633 | 2618 | 'use strict'; |
| 2634 | 2619 | |
| @@ -2661,13 +2646,15 @@ | ||
| 2661 | 2646 | exports['default'] = AST; |
| 2662 | 2647 | module.exports = exports['default']; |
| 2663 | 2648 | |
| 2664 | 2649 | /***/ }), |
| 2665 | -/* 85 */ | |
| 2650 | +/* 84 */ | |
| 2666 | 2651 | /***/ (function(module, exports, __webpack_require__) { |
| 2667 | 2652 | |
| 2668 | 2653 | 'use strict'; |
| 2669 | 2654 | |
| 2655 | + var _Object$keys = __webpack_require__(60)['default']; | |
| 2656 | + | |
| 2670 | 2657 | var _interopRequireDefault = __webpack_require__(1)['default']; |
| 2671 | 2658 | |
| 2672 | 2659 | var _interopRequireWildcard = __webpack_require__(3)['default']; |
| 2673 | 2660 | |
| @@ -2674,20 +2661,24 @@ | ||
| 2674 | 2661 | exports.__esModule = true; |
| 2675 | 2662 | exports.parseWithoutProcessing = parseWithoutProcessing; |
| 2676 | 2663 | exports.parse = parse; |
| 2677 | 2664 | |
| 2678 | - var _parser = __webpack_require__(86); | |
| 2665 | + var _parser = __webpack_require__(85); | |
| 2679 | 2666 | |
| 2680 | 2667 | var _parser2 = _interopRequireDefault(_parser); |
| 2681 | 2668 | |
| 2682 | - var _whitespaceControl = __webpack_require__(87); | |
| 2669 | + var _whitespaceControl = __webpack_require__(86); | |
| 2683 | 2670 | |
| 2684 | 2671 | var _whitespaceControl2 = _interopRequireDefault(_whitespaceControl); |
| 2685 | 2672 | |
| 2686 | - var _helpers = __webpack_require__(89); | |
| 2673 | + var _helpers = __webpack_require__(88); | |
| 2687 | 2674 | |
| 2688 | 2675 | var Helpers = _interopRequireWildcard(_helpers); |
| 2689 | 2676 | |
| 2677 | + var _exception = __webpack_require__(6); | |
| 2678 | + | |
| 2679 | + var _exception2 = _interopRequireDefault(_exception); | |
| 2680 | + | |
| 2690 | 2681 | var _utils = __webpack_require__(5); |
| 2691 | 2682 | |
| 2692 | 2683 | exports.parser = _parser2['default']; |
| 2693 | 2684 | |
| @@ -2696,8 +2687,11 @@ | ||
| 2696 | 2687 | |
| 2697 | 2688 | function parseWithoutProcessing(input, options) { |
| 2698 | 2689 | // Just return if an already-compiled AST was passed in. |
| 2699 | 2690 | if (input.type === 'Program') { |
| 2691 | + // When a pre-parsed AST is passed in, validate all node values to prevent | |
| 2692 | + // code injection via type-confused literals. | |
| 2693 | + validateInputAst(input); | |
| 2700 | 2694 | return input; |
| 2701 | 2695 | } |
| 2702 | 2696 | |
| 2703 | 2697 | _parser2['default'].yy = yy; |
| @@ -2718,10 +2712,62 @@ | ||
| 2718 | 2712 | |
| 2719 | 2713 | return strip.accept(ast); |
| 2720 | 2714 | } |
| 2721 | 2715 | |
| 2716 | + function validateInputAst(ast) { | |
| 2717 | + validateAstNode(ast); | |
| 2718 | + } | |
| 2719 | + | |
| 2720 | + function validateAstNode(node) { | |
| 2721 | + if (node == null) { | |
| 2722 | + return; | |
| 2723 | + } | |
| 2724 | + | |
| 2725 | + if (Array.isArray(node)) { | |
| 2726 | + node.forEach(validateAstNode); | |
| 2727 | + return; | |
| 2728 | + } | |
| 2729 | + | |
| 2730 | + if (typeof node !== 'object') { | |
| 2731 | + return; | |
| 2732 | + } | |
| 2733 | + | |
| 2734 | + if (node.type === 'PathExpression') { | |
| 2735 | + if (!isValidDepth(node.depth)) { | |
| 2736 | + throw new _exception2['default']('Invalid AST: PathExpression.depth must be an integer'); | |
| 2737 | + } | |
| 2738 | + if (!Array.isArray(node.parts)) { | |
| 2739 | + throw new _exception2['default']('Invalid AST: PathExpression.parts must be an array'); | |
| 2740 | + } | |
| 2741 | + for (var i = 0; i < node.parts.length; i++) { | |
| 2742 | + if (typeof node.parts[i] !== 'string') { | |
| 2743 | + throw new _exception2['default']('Invalid AST: PathExpression.parts must only contain strings'); | |
| 2744 | + } | |
| 2745 | + } | |
| 2746 | + } else if (node.type === 'NumberLiteral') { | |
| 2747 | + if (typeof node.value !== 'number' || !isFinite(node.value)) { | |
| 2748 | + throw new _exception2['default']('Invalid AST: NumberLiteral.value must be a number'); | |
| 2749 | + } | |
| 2750 | + } else if (node.type === 'BooleanLiteral') { | |
| 2751 | + if (typeof node.value !== 'boolean') { | |
| 2752 | + throw new _exception2['default']('Invalid AST: BooleanLiteral.value must be a boolean'); | |
| 2753 | + } | |
| 2754 | + } | |
| 2755 | + | |
| 2756 | + _Object$keys(node).forEach(function (propertyName) { | |
| 2757 | + if (propertyName === 'loc') { | |
| 2758 | + return; | |
| 2759 | + } | |
| 2760 | + validateAstNode(node[propertyName]); | |
| 2761 | + }); | |
| 2762 | + } | |
| 2763 | + | |
| 2764 | + function isValidDepth(depth) { | |
| 2765 | + return typeof depth === 'number' && isFinite(depth) && Math.floor(depth) === depth && depth >= 0; | |
| 2766 | + } | |
| 2767 | + | |
| 2722 | 2768 | /***/ }), |
| 2723 | -/* 86 */ | |
| 2769 | +/* 85 */ | |
| 2724 | 2770 | /***/ (function(module, exports) { |
| 2725 | 2771 | |
| 2726 | 2772 | // File ignored in coverage tests via setting in .istanbul.yml |
| 2727 | 2773 | /* Jison generated parser */ |
| @@ -3447,9 +3493,9 @@ | ||
| 3447 | 3493 | return 5; |
| 3448 | 3494 | break; |
| 3449 | 3495 | } |
| 3450 | 3496 | }; |
| 3451 | - lexer.rules = [/^(?:[^\x00]*?(?=(\{\{)))/, /^(?:[^\x00]+)/, /^(?:[^\x00]{2,}?(?=(\{\{|\\\{\{|\\\\\{\{|$)))/, /^(?:\{\{\{\{(?=[^/]))/, /^(?:\{\{\{\{\/[^\s!"#%-,\.\/;->@\[-\^`\{-~]+(?=[=}\s\/.])\}\}\}\})/, /^(?:[^\x00]+?(?=(\{\{\{\{)))/, /^(?:[\s\S]*?--(~)?\}\})/, /^(?:\()/, /^(?:\))/, /^(?:\{\{\{\{)/, /^(?:\}\}\}\})/, /^(?:\{\{(~)?>)/, /^(?:\{\{(~)?#>)/, /^(?:\{\{(~)?#\*?)/, /^(?:\{\{(~)?\/)/, /^(?:\{\{(~)?\^\s*(~)?\}\})/, /^(?:\{\{(~)?\s*else\s*(~)?\}\})/, /^(?:\{\{(~)?\^)/, /^(?:\{\{(~)?\s*else\b)/, /^(?:\{\{(~)?\{)/, /^(?:\{\{(~)?&)/, /^(?:\{\{(~)?!--)/, /^(?:\{\{(~)?![\s\S]*?\}\})/, /^(?:\{\{(~)?\*?)/, /^(?:=)/, /^(?:\.\.)/, /^(?:\.(?=([=~}\s\/.)|])))/, /^(?:[\/.])/, /^(?:\s+)/, /^(?:\}(~)?\}\})/, /^(?:(~)?\}\})/, /^(?:"(\\["]|[^"])*")/, /^(?:'(\\[']|[^'])*')/, /^(?:@)/, /^(?:true(?=([~}\s)])))/, /^(?:false(?=([~}\s)])))/, /^(?:undefined(?=([~}\s)])))/, /^(?:null(?=([~}\s)])))/, /^(?:-?[0-9]+(?:\.[0-9]+)?(?=([~}\s)])))/, /^(?:as\s+\|)/, /^(?:\|)/, /^(?:([^\s!"#%-,\.\/;->@\[-\^`\{-~]+(?=([=~}\s\/.)|]))))/, /^(?:\[(\\\]|[^\]])*\])/, /^(?:.)/, /^(?:$)/]; | |
| 3497 | + lexer.rules = [/^(?:[^\x00]*?(?=(\{\{)))/, /^(?:[^\x00]+)/, /^(?:[^\x00]{2,}?(?=(\{\{|\\\{\{|\\\\\{\{|$)))/, /^(?:\{\{\{\{(?=[^\/]))/, /^(?:\{\{\{\{\/[^\s!"#%-,\.\/;->@\[-\^`\{-~]+(?=[=}\s\/.])\}\}\}\})/, /^(?:[^\x00]+?(?=(\{\{\{\{)))/, /^(?:[\s\S]*?--(~)?\}\})/, /^(?:\()/, /^(?:\))/, /^(?:\{\{\{\{)/, /^(?:\}\}\}\})/, /^(?:\{\{(~)?>)/, /^(?:\{\{(~)?#>)/, /^(?:\{\{(~)?#\*?)/, /^(?:\{\{(~)?\/)/, /^(?:\{\{(~)?\^\s*(~)?\}\})/, /^(?:\{\{(~)?\s*else\s*(~)?\}\})/, /^(?:\{\{(~)?\^)/, /^(?:\{\{(~)?\s*else\b)/, /^(?:\{\{(~)?\{)/, /^(?:\{\{(~)?&)/, /^(?:\{\{(~)?!--)/, /^(?:\{\{(~)?![\s\S]*?\}\})/, /^(?:\{\{(~)?\*?)/, /^(?:=)/, /^(?:\.\.)/, /^(?:\.(?=([=~}\s\/.)|])))/, /^(?:[\/.])/, /^(?:\s+)/, /^(?:\}(~)?\}\})/, /^(?:(~)?\}\})/, /^(?:"(\\["]|[^"])*")/, /^(?:'(\\[']|[^'])*')/, /^(?:@)/, /^(?:true(?=([~}\s)])))/, /^(?:false(?=([~}\s)])))/, /^(?:undefined(?=([~}\s)])))/, /^(?:null(?=([~}\s)])))/, /^(?:-?[0-9]+(?:\.[0-9]+)?(?=([~}\s)])))/, /^(?:as\s+\|)/, /^(?:\|)/, /^(?:([^\s!"#%-,\.\/;->@\[-\^`\{-~]+(?=([=~}\s\/.)|]))))/, /^(?:\[(\\\]|[^\]])*\])/, /^(?:.)/, /^(?:$)/]; | |
| 3452 | 3498 | lexer.conditions = { "mu": { "rules": [7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44], "inclusive": false }, "emu": { "rules": [2], "inclusive": false }, "com": { "rules": [6], "inclusive": false }, "raw": { "rules": [3, 4, 5], "inclusive": false }, "INITIAL": { "rules": [0, 1, 44], "inclusive": true } }; |
| 3453 | 3499 | return lexer; |
| 3454 | 3500 | })(); |
| 3455 | 3501 | parser.lexer = lexer; |
| @@ -3460,9 +3506,9 @@ | ||
| 3460 | 3506 | })();exports["default"] = handlebars; |
| 3461 | 3507 | module.exports = exports["default"]; |
| 3462 | 3508 | |
| 3463 | 3509 | /***/ }), |
| 3464 | -/* 87 */ | |
| 3510 | +/* 86 */ | |
| 3465 | 3511 | /***/ (function(module, exports, __webpack_require__) { |
| 3466 | 3512 | |
| 3467 | 3513 | 'use strict'; |
| 3468 | 3514 | |
| @@ -3469,9 +3515,9 @@ | ||
| 3469 | 3515 | var _interopRequireDefault = __webpack_require__(1)['default']; |
| 3470 | 3516 | |
| 3471 | 3517 | exports.__esModule = true; |
| 3472 | 3518 | |
| 3473 | - var _visitor = __webpack_require__(88); | |
| 3519 | + var _visitor = __webpack_require__(87); | |
| 3474 | 3520 | |
| 3475 | 3521 | var _visitor2 = _interopRequireDefault(_visitor); |
| 3476 | 3522 | |
| 3477 | 3523 | function WhitespaceControl() { |
| @@ -3684,9 +3730,9 @@ | ||
| 3684 | 3730 | exports['default'] = WhitespaceControl; |
| 3685 | 3731 | module.exports = exports['default']; |
| 3686 | 3732 | |
| 3687 | 3733 | /***/ }), |
| 3688 | -/* 88 */ | |
| 3734 | +/* 87 */ | |
| 3689 | 3735 | /***/ (function(module, exports, __webpack_require__) { |
| 3690 | 3736 | |
| 3691 | 3737 | 'use strict'; |
| 3692 | 3738 | |
| @@ -3827,9 +3873,9 @@ | ||
| 3827 | 3873 | exports['default'] = Visitor; |
| 3828 | 3874 | module.exports = exports['default']; |
| 3829 | 3875 | |
| 3830 | 3876 | /***/ }), |
| 3831 | -/* 89 */ | |
| 3877 | +/* 88 */ | |
| 3832 | 3878 | /***/ (function(module, exports, __webpack_require__) { |
| 3833 | 3879 | |
| 3834 | 3880 | 'use strict'; |
| 3835 | 3881 | |
| @@ -4058,9 +4104,9 @@ | ||
| 4058 | 4104 | }; |
| 4059 | 4105 | } |
| 4060 | 4106 | |
| 4061 | 4107 | /***/ }), |
| 4062 | -/* 90 */ | |
| 4108 | +/* 89 */ | |
| 4063 | 4109 | /***/ (function(module, exports, __webpack_require__) { |
| 4064 | 4110 | |
| 4065 | 4111 | /* eslint-disable new-cap */ |
| 4066 | 4112 | |
| @@ -4080,9 +4126,9 @@ | ||
| 4080 | 4126 | var _exception2 = _interopRequireDefault(_exception); |
| 4081 | 4127 | |
| 4082 | 4128 | var _utils = __webpack_require__(5); |
| 4083 | 4129 | |
| 4084 | - var _ast = __webpack_require__(84); | |
| 4130 | + var _ast = __webpack_require__(83); | |
| 4085 | 4131 | |
| 4086 | 4132 | var _ast2 = _interopRequireDefault(_ast); |
| 4087 | 4133 | |
| 4088 | 4134 | var slice = [].slice; |
| @@ -4629,9 +4675,9 @@ | ||
| 4629 | 4675 | } |
| 4630 | 4676 | } |
| 4631 | 4677 | |
| 4632 | 4678 | /***/ }), |
| 4633 | -/* 91 */ | |
| 4679 | +/* 90 */ | |
| 4634 | 4680 | /***/ (function(module, exports, __webpack_require__) { |
| 4635 | 4681 | |
| 4636 | 4682 | 'use strict'; |
| 4637 | 4683 | |
| @@ -4648,9 +4694,9 @@ | ||
| 4648 | 4694 | var _exception2 = _interopRequireDefault(_exception); |
| 4649 | 4695 | |
| 4650 | 4696 | var _utils = __webpack_require__(5); |
| 4651 | 4697 | |
| 4652 | - var _codeGen = __webpack_require__(92); | |
| 4698 | + var _codeGen = __webpack_require__(91); | |
| 4653 | 4699 | |
| 4654 | 4700 | var _codeGen2 = _interopRequireDefault(_codeGen); |
| 4655 | 4701 | |
| 4656 | 4702 | function Literal(value) { |
| @@ -4793,14 +4839,12 @@ | ||
| 4793 | 4839 | var programs = _context.programs; |
| 4794 | 4840 | var decorators = _context.decorators; |
| 4795 | 4841 | |
| 4796 | 4842 | for (i = 0, l = programs.length; i < l; i++) { |
| 4797 | - if (programs[i]) { | |
| 4798 | - ret[i] = programs[i]; | |
| 4799 | - if (decorators[i]) { | |
| 4800 | - ret[i + '_d'] = decorators[i]; | |
| 4801 | - ret.useDecorators = true; | |
| 4802 | - } | |
| 4843 | + ret[i] = programs[i]; | |
| 4844 | + if (decorators[i]) { | |
| 4845 | + ret[i + '_d'] = decorators[i]; | |
| 4846 | + ret.useDecorators = true; | |
| 4803 | 4847 | } |
| 4804 | 4848 | } |
| 4805 | 4849 | |
| 4806 | 4850 | if (this.environment.usePartial) { |
| @@ -5124,22 +5168,23 @@ | ||
| 5124 | 5168 | |
| 5125 | 5169 | this.resolvePath('data', parts, 0, true, strict); |
| 5126 | 5170 | }, |
| 5127 | 5171 | |
| 5128 | - resolvePath: function resolvePath(type, parts, i, falsy, strict) { | |
| 5172 | + resolvePath: function resolvePath(type, parts, startPartIndex, falsy, strict) { | |
| 5129 | 5173 | // istanbul ignore next |
| 5130 | 5174 | |
| 5131 | 5175 | var _this2 = this; |
| 5132 | 5176 | |
| 5133 | 5177 | if (this.options.strict || this.options.assumeObjects) { |
| 5134 | - this.push(strictLookup(this.options.strict && strict, this, parts, i, type)); | |
| 5178 | + this.push(strictLookup(this.options.strict && strict, this, parts, startPartIndex, type)); | |
| 5135 | 5179 | return; |
| 5136 | 5180 | } |
| 5137 | 5181 | |
| 5138 | 5182 | var len = parts.length; |
| 5139 | - for (; i < len; i++) { | |
| 5183 | + | |
| 5184 | + var _loop = function (i) { | |
| 5140 | 5185 | /* eslint-disable no-loop-func */ |
| 5141 | - this.replaceStack(function (current) { | |
| 5186 | + _this2.replaceStack(function (current) { | |
| 5142 | 5187 | var lookup = _this2.nameLookup(current, parts[i], type); |
| 5143 | 5188 | // We want to ensure that zero and false are handled properly if the context (falsy flag) |
| 5144 | 5189 | // needs to have the special handling for these values. |
| 5145 | 5190 | if (!falsy) { |
| @@ -5149,8 +5194,12 @@ | ||
| 5149 | 5194 | return [' && ', lookup]; |
| 5150 | 5195 | } |
| 5151 | 5196 | }); |
| 5152 | 5197 | /* eslint-enable no-loop-func */ |
| 5198 | + }; | |
| 5199 | + | |
| 5200 | + for (var i = startPartIndex; i < len; i++) { | |
| 5201 | + _loop(i); | |
| 5153 | 5202 | } |
| 5154 | 5203 | }, |
| 5155 | 5204 | |
| 5156 | 5205 | // [resolvePossibleLambda] |
| @@ -5266,9 +5315,14 @@ | ||
| 5266 | 5315 | registerDecorator: function registerDecorator(paramSize, name) { |
| 5267 | 5316 | var foundDecorator = this.nameLookup('decorators', name, 'decorator'), |
| 5268 | 5317 | options = this.setupHelperArgs(name, paramSize); |
| 5269 | 5318 | |
| 5270 | - this.decorators.push(['fn = ', this.decorators.functionCall(foundDecorator, '', ['fn', 'props', 'container', options]), ' || fn;']); | |
| 5319 | + // Store the resolved decorator in a variable and verify it is a function before | |
| 5320 | + // calling it. Without this, unregistered decorators can cause an unhandled TypeError | |
| 5321 | + // (calling undefined), which crashes the process — enabling Denial of Service. | |
| 5322 | + this.decorators.push(['var decorator = ', foundDecorator, ';']); | |
| 5323 | + this.decorators.push(['if (typeof decorator !== "function") { throw new Error(', this.quotedString('Missing decorator: "' + name + '"'), '); }']); | |
| 5324 | + this.decorators.push(['fn = ', this.decorators.functionCall('decorator', '', ['fn', 'props', 'container', options]), ' || fn;']); | |
| 5271 | 5325 | }, |
| 5272 | 5326 | |
| 5273 | 5327 | // [invokeHelper] |
| 5274 | 5328 | // |
| @@ -5449,10 +5503,10 @@ | ||
| 5449 | 5503 | |
| 5450 | 5504 | var existing = this.matchExistingProgram(child); |
| 5451 | 5505 | |
| 5452 | 5506 | if (existing == null) { |
| 5453 | - this.context.programs.push(''); // Placeholder to prevent name conflicts for nested children | |
| 5454 | - var index = this.context.programs.length; | |
| 5507 | + // Placeholder to prevent name conflicts for nested children | |
| 5508 | + var index = this.context.programs.push('') - 1; | |
| 5455 | 5509 | child.index = index; |
| 5456 | 5510 | child.name = 'program' + index; |
| 5457 | 5511 | this.context.programs[index] = compiler.compile(child, options, this.context, !this.precompile); |
| 5458 | 5512 | this.context.decorators[index] = compiler.decorators; |
| @@ -5770,9 +5824,9 @@ | ||
| 5770 | 5824 | JavaScriptCompiler.isValidJavaScriptVariableName = function (name) { |
| 5771 | 5825 | return !JavaScriptCompiler.RESERVED_WORDS[name] && /^[a-zA-Z_$][0-9a-zA-Z_$]*$/.test(name); |
| 5772 | 5826 | }; |
| 5773 | 5827 | |
| 5774 | - function strictLookup(requireTerminal, compiler, parts, i, type) { | |
| 5828 | + function strictLookup(requireTerminal, compiler, parts, startPartIndex, type) { | |
| 5775 | 5829 | var stack = compiler.popStack(), |
| 5776 | 5830 | len = parts.length; |
| 5777 | 5831 | if (requireTerminal) { |
| 5778 | 5832 | len--; |
| @@ -5777,14 +5831,14 @@ | ||
| 5777 | 5831 | if (requireTerminal) { |
| 5778 | 5832 | len--; |
| 5779 | 5833 | } |
| 5780 | 5834 | |
| 5781 | - for (; i < len; i++) { | |
| 5835 | + for (var i = startPartIndex; i < len; i++) { | |
| 5782 | 5836 | stack = compiler.nameLookup(stack, parts[i], type); |
| 5783 | 5837 | } |
| 5784 | 5838 | |
| 5785 | 5839 | if (requireTerminal) { |
| 5786 | - return [compiler.aliasable('container.strict'), '(', stack, ', ', compiler.quotedString(parts[i]), ', ', JSON.stringify(compiler.source.currentLocation), ' )']; | |
| 5840 | + return [compiler.aliasable('container.strict'), '(', stack, ', ', compiler.quotedString(parts[len]), ', ', JSON.stringify(compiler.source.currentLocation), ' )']; | |
| 5787 | 5841 | } else { |
| 5788 | 5842 | return stack; |
| 5789 | 5843 | } |
| 5790 | 5844 | } |
| @@ -5792,9 +5846,9 @@ | ||
| 5792 | 5846 | exports['default'] = JavaScriptCompiler; |
| 5793 | 5847 | module.exports = exports['default']; |
| 5794 | 5848 | |
| 5795 | 5849 | /***/ }), |
| 5796 | -/* 92 */ | |
| 5850 | +/* 91 */ | |
| 5797 | 5851 | /***/ (function(module, exports, __webpack_require__) { |
| 5798 | 5852 | |
| 5799 | 5853 | /* global define, require */ |
| 5800 | 5854 | 'use strict'; |