Throw instead of crashing on a pipe with no preceding expression (#351)

{{ | upper }} makes Parser::parse_expression call arguments.back() on an empty vector, which is undefined behavior and aborts under hardened standard libraries. Throw 'too few arguments' (matching add_operator) when there is no expression before the '|'.
This commit is contained in:
Enrique Avina
2026-09-30 07:09:08 +02:00
committed by GitHub
parent 446379d2ba
commit 02f86731a3
3 changed files with 9 additions and 0 deletions
+3
View File
@@ -360,6 +360,9 @@ class Parser {
}
auto func = std::make_shared<FunctionNode>(tok.text, tok.text.data() - tmpl.content.c_str());
// add first parameter as last value from arguments
if (arguments.empty()) {
throw_parser_error("too few arguments");
}
func->number_args += 1;
func->arguments.emplace_back(arguments.back());
arguments.pop_back();
+3
View File
@@ -1816,6 +1816,9 @@ class Parser {
}
auto func = std::make_shared<FunctionNode>(tok.text, tok.text.data() - tmpl.content.c_str());
// add first parameter as last value from arguments
if (arguments.empty()) {
throw_parser_error("too few arguments");
}
func->number_args += 1;
func->arguments.emplace_back(arguments.back());
arguments.pop_back();
+3
View File
@@ -159,6 +159,9 @@ Yeah!
CHECK(env.render("{{ brother.name | upper }}", data) == "CHRIS");
CHECK(env.render("{{ brother.name | upper | lower }}", data) == "chris");
CHECK(env.render("{{ [\"C\", \"A\", \"B\"] | sort | join(\",\") }}", data) == "A,B,C");
CHECK_THROWS_WITH(env.render("{{ | upper }}", data), "[inja.exception.parser_error] (at 1:6) too few arguments");
CHECK_THROWS_WITH(env.render("{{ upper(| lower) }}", data), "[inja.exception.parser_error] (at 1:12) too few arguments");
}
}