Recent Commits to smarty:master

  • 25/08/2026 16:49

    Update SECURITY.md

    Update SECURITY.md
    
    point to https://github.com/smarty-php/smarty/security/advisories/new instead of email
  • 04/07/2026 8:37

    Fix double semicolon in getRightDelimiter method (#1202)

    Fix double semicolon in getRightDelimiter method (#1202)
  • 29/06/2026 7:46

    Merge branch 'release/5.8.4'

    Merge branch 'release/5.8.4'
  • 29/06/2026 7:46

    version bump

    version bump
  • 29/06/2026 7:45

    Fix TypeError for non-array static_classes in Security policy (#1198)

    Fix TypeError for non-array static_classes in Security policy (#1198)
  • 29/06/2026 7:40

    drop unused version attribute from docker-compose.yml

    drop unused version attribute from docker-compose.yml
  • 29/06/2026 6:47

    Security: validate nested stream wrapper in stream: resource (CWE-22)…

    Security: validate nested stream wrapper in stream: resource (CWE-22) (#1195)
    
    The built-in stream: resource type let a template bypass Security stream
    restrictions. BasePlugin::load() matches the 'stream' sysplugin before the
    stream_get_wrappers()/isTrustedStream() check, so a resource such as
    stream:php://filter/read=convert.base64-encode/resource=/path was opened by
    StreamPlugin::getContent() via fopen() on the nested php:// wrapper without
    ever validating it. This bypassed Security::$streams (including
    Security::$streams = null) and allowed reading arbitrary local files.
    
    Parse the wrapper scheme from the resolved path in StreamPlugin::getContent()
    and validate it with Security::isTrustedStream() before fopen(), giving the
    stream: resource the same check the direct wrapper path already receives.
    
    Adds regression tests covering the disabled-streams bypass, the
    not-on-allowlist case, and a positive test that an explicitly allowed wrapper
    still works.
    Tags:
  • 28/06/2026 19:15

    Merge branch 'release/5.8.3'

    Merge branch 'release/5.8.3'
  • 28/06/2026 19:15

    version bump

    version bump
  • 28/06/2026 19:14

    requirements for building docs, switched test-runner from mutagen to …

    requirements for building docs, switched test-runner from mutagen to basic docker compose
  • 28/06/2026 19:12

    fixed a regression from #1189 where a child template's block override…

    fixed a regression from #1189 where a child template's block override no longer applied to a template {include}d by the parent
    
    Fixes #1192
  • 24/06/2026 5:33

    update documentation for building and previewing with mkdocs, fix uni…

    update documentation for building and previewing with mkdocs, fix unit tests for windows
  • 24/06/2026 5:04

    Merge branch 'release/5.8.2'

    Merge branch 'release/5.8.2'
  • 24/06/2026 5:04

    version bump

    version bump
  • 23/06/2026 19:48

    Security: escape value-context attributes in html_image/html_select_d…

    Security: escape value-context attributes in html_image/html_select_date (CWE-79)
    
    {html_image} already escaped alt and pass-through attributes, but emitted
    file, path_prefix, href/link, width and height raw, letting an untrusted
    value break out of the generated tag. Escape these at output time; the
    unescaped values are still used for getimagesize()/DPI math. Escaping uses
    htmlspecialchars with double_encode=false, so existing entities and values
    like "100%" are preserved (no BC break for legitimate values).
    
    {html_select_date} treated day_size/month_size/year_size as strings and
    emitted them raw into size="…"; cast them to int to match
    {html_select_time} and close the breakout.
    
    The remaining flagged parameters (mailto extra; html_table *_attr/
    trailpad/caption/loop; html_radios/html_checkboxes separator;
    html_select_* *_extra/field_separator and the unrecognised-attribute
    pass-through) intentionally emit raw markup as documented, so escaping
    them would break backwards compatibility. Add a security note to those
    docs pages instead, telling authors to escape untrusted values themselves.
    
    Adds tests for html_image escaping (incl. benign-value/no-double-encode
    checks) and the html_select_date size cast.
    
    Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
  • 23/06/2026 19:21

    Security: stop {fetch} from following redirects past trusted_uri (CWE…

    Security: stop {fetch} from following redirects past trusted_uri (CWE-918)
    
    {fetch} validates the requested URL with Security::isTrustedUri(), but
    for non-http schemes (e.g. https) it reads the resource via
    file_get_contents(), which follows redirects by default. An open redirect
    on an otherwise trusted host could therefore be used to reach a
    non-trusted, internal target, bypassing the trusted_uri policy (SSRF).
    
    When a security policy is active, pass a stream context that disables
    redirect-following (follow_location => 0, max_redirects => 1) to
    file_get_contents() for remote resources. Behavior is unchanged when no
    security policy is set, since there is no trusted_uri to bypass.
    
    Adds a regression test using a custom stream wrapper that captures the
    context {fetch} passes to file_get_contents, plus a backwards-compat test
    for the no-security-policy case.
    
    Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
  • 23/06/2026 19:15

    Security: prevent symlink path traversal out of secure_dir (CWE-22)

    Security: prevent symlink path traversal out of secure_dir (CWE-22)
    
    Security::_checkDir() validated file access using Smarty::_realpath(),
    which only normalizes paths as strings and never follows symlinks. A
    symlink placed inside a trusted secure_dir/template directory therefore
    passed the trust check while file_get_contents() followed it to an
    arbitrary file (e.g. /etc/passwd), affecting {include} and {fetch} of
    local files.
    
    Resolve the requested file with native realpath() and re-validate the
    canonical, symlink-free path against the trusted directories. The trusted
    directories are canonicalized the same way so legitimate symlinked
    deployment paths (e.g. a Capistrano "current" release symlink, or macOS'
    /var -> /private/var) keep working. Falls back to string normalization
    only when the file does not yet exist on disk.
    
    Adds regression tests covering both the rejected escape and an allowed
    in-sandbox symlink, and documents the changelog convention in AGENTS.md.
    
    Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
  • 23/06/2026 18:50

    fix for Error: Attempt to assign property "step" on null closes issue…

    fix for Error: Attempt to assign property "step" on null closes issue #1036 (#1071)
    
    * fix for Error: Attempt to assign property "step" on null in extended templates + added tests closes issue #1036
  • 23/06/2026 18:04

    Merge branch 'release/5.8.1'

    Merge branch 'release/5.8.1'
  • 23/06/2026 18:04

    version bump

    version bump
  • 23/06/2026 18:03

    Added changelog for the fix for issue #1189

    Added changelog for the fix for issue #1189
  • 23/06/2026 17:52

    Agents instructions

    Agents instructions
  • 23/06/2026 17:50

    Bugfix/issue 1189 inheritance state leak (#1190)

    Bugfix/issue 1189 inheritance state leak (#1190)
    
    * Reproduce block override leakage in template inheritance
    * Fixes #1189
  • 15/05/2026 19:34

    fix: return type (#1180)

    fix: return type (#1180)
  • 03/05/2026 17:19

    update todos

    update todos
  • 03/05/2026 17:19

    Remove incomplete test cases for usesCompiler across multiple test files

    Remove incomplete test cases for usesCompiler across multiple test files
  • 13/04/2026 17:31

    Re-activate unit tests for user literals.

    Re-activate unit tests for user literals.
  • 13/04/2026 16:36

    Redirect test temp dirs to system temp directory

    Redirect test temp dirs to system temp directory
    
    * Redirect test temp dirs to system temp directory. Fixes #1178
    
    Move all test-generated output (compiled templates, cache files, and
    temporary template sources) from per-test-directory folders inside the
    working tree to a parallel structure under sys_get_temp_dir()/smarty-tests/.
    
    This removes 215 boilerplate .gitignore files from the repo and ensures
    running the test suite leaves zero uncommitted files in the working tree.
    
    All 2296 tests continue to pass with identical behavior.
    
    * Isolate each test class in a unique temp directory
    
    getTempDir() now appends a per-class uniqid token to the temp path, so
    concurrent or sequential test runs never share compiled/cached output.
    The token is generated lazily on first use and reset in
    tearDownAfterClass(), giving every test class a fresh isolated directory.
    
    As a result, the Bootstrap.php pre-run cleanup of smarty-tests/ is no
    longer needed for correctness (stale paths are unreachable) and was
    harmful to concurrent runs, so it has been removed.
    
    * Remove individualFolders dead code and spurious assertTrue from cleanDirs()
    
    - Remove the never-active individualFolders code path from setUpSmarty()
      (the constant was always true, making the branch unreachable)
    - Remove define('individualFolders') from Config.php and the constructor
    - Remove $this->assertTrue(true) from cleanDirs(): it existed solely to
      make testInit() count as a passing test; now that cleanDirs() is called
      from setUpSmarty() and from test methods directly, the assertion was
      spuriously inflating assertion counts
    - Add tests/**/templates_c/, cache/, templates_tmp/ to .gitignore to
      prevent stale test output from appearing as untracked files
    
    * Clean up each test class's unique temp dir in tearDownAfterClass()
    
    Add a private static removeDir() helper and call it from
    tearDownAfterClass() to recursively delete the per-class unique temp
    directory after each test class finishes. Cleanup failures are silently
    ignored (@ suppression) so they never cause test failures.
    
    Set KEEP_SMARTY_TEST_ARTIFACTS=1 in the environment to skip cleanup and
    keep the artifacts on disk for debugging.
    
    * cleanup of unused template files, non-shared files stored in __shared folder, no longer required calls to add template folders et cetera
    
    * fixed the unit tests
    
    * Apply suggestions from code review
    
    Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
    
    * remove useless resetting of static properties in tearDownAfterClass
    
    * changed an incorrect doc and formatted some code.
    
    * add changelog
    
    ---------
    
    Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
  • 10/04/2026 17:57

    Added AGENTS.md for improved vibe coding experience

    Added AGENTS.md for improved vibe coding experience
    Tags:
  • 15/02/2026 11:27

    Merge branch 'release/5.8.0'

    Merge branch 'release/5.8.0'
  • 15/02/2026 11:27

    version bump

    version bump
  • 15/02/2026 11:26

    changelogs

    changelogs
  • 15/02/2026 11:23

    Add support for Backed Enums (#1171)

    Add support for Backed Enums (#1171)
    
    * Add support for Backed Enums
    Fixes #1012
    
    Also added docs (and docs for matches operator)
  • 15/02/2026 10:44

    Regex matches operator (#1169)

    Regex matches operator (#1169)
    
    * Regex matches operator support
  • 10/02/2026 20:02

    Support for Laravel Collections style object chaining (#1168)

    Support for Laravel Collections style object chaining (#1168)
    
    * Support for Laravel Collections style object chaining for objects return from function calls implemented as modifiers
    Fixes #1151
    
    * explain publishing docs
    Tags:
  • 08/01/2026 7:21

    Fix static analysis warnings for isDot() and remove deprecated APC su…

    Fix static analysis warnings for isDot() and remove deprecated APC support (#1164)
    
    * Fix static analysis warnings for isDot()
    * Remove deprecated APC support
    * Remove redundant isDot() check and fix static analysis warnings
  • 21/12/2025 18:58

    Document missing inline implementation. Fixed #1152 (#1156)

    Document missing inline implementation. Fixed #1152 (#1156)
  • 19/11/2025 18:36

    Merge branch 'release/5.7.0'

    Merge branch 'release/5.7.0'
  • 19/11/2025 18:36

    version bump

    version bump
  • 19/11/2025 18:33

    Php8.5 support (#1138)

    Php8.5 support (#1138)
    
    * PHP 8.5 support (using RC docker image for php 8.5 unit tests)
  • 17/10/2025 9:45

    Non-canonical cast (boolean) fix (#1145)

    Non-canonical cast (boolean) fix (#1145)
  • 03/10/2025 18:22

    Merge branch 'release/5.6.0'

    Merge branch 'release/5.6.0'
  • 03/10/2025 18:22

    version bump

    version bump
  • 03/10/2025 18:19

    added changelog

    added changelog
  • 03/10/2025 18:17

    Add support for shorttags in functions (#1142)

    Add support for shorttags in functions (#1142)
    
    * Add support for shorttags in functions
    
    Co-authored-by: Anne Zijlstra <a.zijlstra@iwink.nl>
    Co-authored-by: Simon Wisselink <s.wisselink@iwink.nl>
  • 26/08/2025 5:38

    Merge branch 'release/5.5.2'

    Merge branch 'release/5.5.2'
  • 26/08/2025 5:38

    version bump

    version bump

Log in