Recent Commits to smarty:master

  • 29/06/2026 7:46

    Merge branch 'release/5.8.4'

    Merge branch 'release/5.8.4'
  • 29/06/2026 7:46

    version bump

    version bump
  • 29/06/2026 7:45

    Fix TypeError for non-array static_classes in Security policy (#1198)

    Fix TypeError for non-array static_classes in Security policy (#1198)
  • 29/06/2026 7:40

    drop unused version attribute from docker-compose.yml

    drop unused version attribute from docker-compose.yml
  • 29/06/2026 6:47

    Security: validate nested stream wrapper in stream: resource (CWE-22)…

    Security: validate nested stream wrapper in stream: resource (CWE-22) (#1195)
    
    The built-in stream: resource type let a template bypass Security stream
    restrictions. BasePlugin::load() matches the 'stream' sysplugin before the
    stream_get_wrappers()/isTrustedStream() check, so a resource such as
    stream:php://filter/read=convert.base64-encode/resource=/path was opened by
    StreamPlugin::getContent() via fopen() on the nested php:// wrapper without
    ever validating it. This bypassed Security::$streams (including
    Security::$streams = null) and allowed reading arbitrary local files.
    
    Parse the wrapper scheme from the resolved path in StreamPlugin::getContent()
    and validate it with Security::isTrustedStream() before fopen(), giving the
    stream: resource the same check the direct wrapper path already receives.
    
    Adds regression tests covering the disabled-streams bypass, the
    not-on-allowlist case, and a positive test that an explicitly allowed wrapper
    still works.
    Tags:
  • 28/06/2026 19:15

    Merge branch 'release/5.8.3'

    Merge branch 'release/5.8.3'
  • 28/06/2026 19:15

    version bump

    version bump
  • 28/06/2026 19:14

    requirements for building docs, switched test-runner from mutagen to …

    requirements for building docs, switched test-runner from mutagen to basic docker compose
  • 28/06/2026 19:12

    fixed a regression from #1189 where a child template's block override…

    fixed a regression from #1189 where a child template's block override no longer applied to a template {include}d by the parent
    
    Fixes #1192
  • 24/06/2026 5:33

    update documentation for building and previewing with mkdocs, fix uni…

    update documentation for building and previewing with mkdocs, fix unit tests for windows
  • 24/06/2026 5:04

    Merge branch 'release/5.8.2'

    Merge branch 'release/5.8.2'
  • 24/06/2026 5:04

    version bump

    version bump
  • 23/06/2026 19:48

    Security: escape value-context attributes in html_image/html_select_d…

    Security: escape value-context attributes in html_image/html_select_date (CWE-79)
    
    {html_image} already escaped alt and pass-through attributes, but emitted
    file, path_prefix, href/link, width and height raw, letting an untrusted
    value break out of the generated tag. Escape these at output time; the
    unescaped values are still used for getimagesize()/DPI math. Escaping uses
    htmlspecialchars with double_encode=false, so existing entities and values
    like "100%" are preserved (no BC break for legitimate values).
    
    {html_select_date} treated day_size/month_size/year_size as strings and
    emitted them raw into size="…"; cast them to int to match
    {html_select_time} and close the breakout.
    
    The remaining flagged parameters (mailto extra; html_table *_attr/
    trailpad/caption/loop; html_radios/html_checkboxes separator;
    html_select_* *_extra/field_separator and the unrecognised-attribute
    pass-through) intentionally emit raw markup as documented, so escaping
    them would break backwards compatibility. Add a security note to those
    docs pages instead, telling authors to escape untrusted values themselves.
    
    Adds tests for html_image escaping (incl. benign-value/no-double-encode
    checks) and the html_select_date size cast.
    
    Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
  • 23/06/2026 19:21

    Security: stop {fetch} from following redirects past trusted_uri (CWE…

    Security: stop {fetch} from following redirects past trusted_uri (CWE-918)
    
    {fetch} validates the requested URL with Security::isTrustedUri(), but
    for non-http schemes (e.g. https) it reads the resource via
    file_get_contents(), which follows redirects by default. An open redirect
    on an otherwise trusted host could therefore be used to reach a
    non-trusted, internal target, bypassing the trusted_uri policy (SSRF).
    
    When a security policy is active, pass a stream context that disables
    redirect-following (follow_location => 0, max_redirects => 1) to
    file_get_contents() for remote resources. Behavior is unchanged when no
    security policy is set, since there is no trusted_uri to bypass.
    
    Adds a regression test using a custom stream wrapper that captures the
    context {fetch} passes to file_get_contents, plus a backwards-compat test
    for the no-security-policy case.
    
    Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
  • 23/06/2026 19:15

    Security: prevent symlink path traversal out of secure_dir (CWE-22)

    Security: prevent symlink path traversal out of secure_dir (CWE-22)
    
    Security::_checkDir() validated file access using Smarty::_realpath(),
    which only normalizes paths as strings and never follows symlinks. A
    symlink placed inside a trusted secure_dir/template directory therefore
    passed the trust check while file_get_contents() followed it to an
    arbitrary file (e.g. /etc/passwd), affecting {include} and {fetch} of
    local files.
    
    Resolve the requested file with native realpath() and re-validate the
    canonical, symlink-free path against the trusted directories. The trusted
    directories are canonicalized the same way so legitimate symlinked
    deployment paths (e.g. a Capistrano "current" release symlink, or macOS'
    /var -> /private/var) keep working. Falls back to string normalization
    only when the file does not yet exist on disk.
    
    Adds regression tests covering both the rejected escape and an allowed
    in-sandbox symlink, and documents the changelog convention in AGENTS.md.
    
    Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
  • 23/06/2026 18:50

    fix for Error: Attempt to assign property "step" on null closes issue…

    fix for Error: Attempt to assign property "step" on null closes issue #1036 (#1071)
    
    * fix for Error: Attempt to assign property "step" on null in extended templates + added tests closes issue #1036
  • 23/06/2026 18:04

    Merge branch 'release/5.8.1'

    Merge branch 'release/5.8.1'
  • 23/06/2026 18:04

    version bump

    version bump
  • 23/06/2026 18:03

    Added changelog for the fix for issue #1189

    Added changelog for the fix for issue #1189
  • 23/06/2026 17:52

    Agents instructions

    Agents instructions
  • 23/06/2026 17:50

    Bugfix/issue 1189 inheritance state leak (#1190)

    Bugfix/issue 1189 inheritance state leak (#1190)
    
    * Reproduce block override leakage in template inheritance
    * Fixes #1189

Log in