From ad5bc5b5caaa5f00057f795d31b28742c4a4fd47 Mon Sep 17 00:00:00 2001 From: Michael Hawkins Date: Tue, 6 Sep 2022 12:05:52 +0800 Subject: [PATCH] MDL-68066 output: Apply disable lambda rendering to Mustache renderer --- lib/mustache/readme_moodle.txt | 2 ++ lib/outputrenderers.php | 5 +++- .../core_renderer_template_exploit_test.php | 25 +++---------------- 3 files changed, 10 insertions(+), 22 deletions(-) diff --git a/lib/mustache/readme_moodle.txt b/lib/mustache/readme_moodle.txt index f5811755c63..1c187bd371d 100644 --- a/lib/mustache/readme_moodle.txt +++ b/lib/mustache/readme_moodle.txt @@ -18,3 +18,5 @@ Note: All this changes need to be reviewed on every upgrade and, if they have been already applied upstream for the release being used, can be removed from the list. If still not available upstream, they will need to be re-applied. +1) If the relevant pull request has not been accepted yet, apply the following commit, so we are able to disable unnecessary rendering: + https://github.com/bobthecow/mustache.php/pull/402/commits/db771014c7e346438f68077813ebdda3fdae12df# diff --git a/lib/outputrenderers.php b/lib/outputrenderers.php index 3a89521d699..1a4db9c3fdf 100644 --- a/lib/outputrenderers.php +++ b/lib/outputrenderers.php @@ -129,7 +129,10 @@ class renderer_base { // Don't allow the JavaScript helper to be executed from within another // helper. If it's allowed it can be used by users to inject malicious // JS into the page. - 'blacklistednestedhelpers' => ['js'])); + 'blacklistednestedhelpers' => ['js'], + // Disable lambda rendering - content in helpers is already rendered, no need to render it again. + 'disable_lambda_rendering' => true, + )); } diff --git a/lib/tests/core_renderer_template_exploit_test.php b/lib/tests/core_renderer_template_exploit_test.php index 873ec025de8..ae48fe8f7dd 100644 --- a/lib/tests/core_renderer_template_exploit_test.php +++ b/lib/tests/core_renderer_template_exploit_test.php @@ -90,7 +90,7 @@ class core_renderer_template_exploit_testcase extends advanced_testcase { 'test1' => $norender, ], 'js' => 'some nasty JS', - 'expected' => 'core, move, some text', + 'expected' => 'core, move, some text {{}}', 'include' => false ], 'js helper not nested' => [ @@ -133,7 +133,7 @@ class core_renderer_template_exploit_testcase extends advanced_testcase { 'testpix' => $singlerender ], 'js' => 'some nasty JS', - 'expected' => 'core, move,', + 'expected' => 'core, move, {{}}', 'include' => false ], 'js in context double depth with single render' => [ @@ -149,7 +149,7 @@ class core_renderer_template_exploit_testcase extends advanced_testcase { 'testpix' => $singlerender ], 'js' => 'some nasty JS', - 'expected' => 'core, move, {{#js}} some nasty JS {{/js}}', + 'expected' => 'core, move, {{second}}', 'include' => false ], 'js in context double depth with recursive render' => [ @@ -269,24 +269,7 @@ class core_renderer_template_exploit_testcase extends advanced_testcase { 'testpix' => $singlerender ], 'js' => 'some nasty JS', - 'expected' => 'core, move,', - 'include' => false - ], - 'partial double nested with js from context single render' => [ - 'templates' => [ - 'test' => '{{#testpix}} core, move, {{foo}}{{/testpix}}', - 'test2' => '{{#js}} some nasty JS {{/js}}', - ], - 'torender' => 'test', - 'context' => [ - 'foo' => '{{{bar}}}', - 'bar' => '{{> test2}}' - ], - 'helpers' => [ - 'testpix' => $singlerender - ], - 'js' => 'some nasty JS', - 'expected' => 'core, move, {{> test2}}', + 'expected' => 'core, move, {{> test2}}', 'include' => false ], 'partial double nested with js from context recursive render' => [