mirror of
https://github.com/pantor/inja.git
synced 2026-10-05 03:50:33 +00:00
Throw instead of crashing on a pipe with no preceding expression (#351)
{{ | upper }} makes Parser::parse_expression call arguments.back() on an empty vector, which is undefined behavior and aborts under hardened standard libraries. Throw 'too few arguments' (matching add_operator) when there is no expression before the '|'.
This commit is contained in:
@@ -360,6 +360,9 @@ class Parser {
|
||||
}
|
||||
auto func = std::make_shared<FunctionNode>(tok.text, tok.text.data() - tmpl.content.c_str());
|
||||
// add first parameter as last value from arguments
|
||||
if (arguments.empty()) {
|
||||
throw_parser_error("too few arguments");
|
||||
}
|
||||
func->number_args += 1;
|
||||
func->arguments.emplace_back(arguments.back());
|
||||
arguments.pop_back();
|
||||
|
||||
@@ -1816,6 +1816,9 @@ class Parser {
|
||||
}
|
||||
auto func = std::make_shared<FunctionNode>(tok.text, tok.text.data() - tmpl.content.c_str());
|
||||
// add first parameter as last value from arguments
|
||||
if (arguments.empty()) {
|
||||
throw_parser_error("too few arguments");
|
||||
}
|
||||
func->number_args += 1;
|
||||
func->arguments.emplace_back(arguments.back());
|
||||
arguments.pop_back();
|
||||
|
||||
@@ -159,6 +159,9 @@ Yeah!
|
||||
CHECK(env.render("{{ brother.name | upper }}", data) == "CHRIS");
|
||||
CHECK(env.render("{{ brother.name | upper | lower }}", data) == "chris");
|
||||
CHECK(env.render("{{ [\"C\", \"A\", \"B\"] | sort | join(\",\") }}", data) == "A,B,C");
|
||||
|
||||
CHECK_THROWS_WITH(env.render("{{ | upper }}", data), "[inja.exception.parser_error] (at 1:6) too few arguments");
|
||||
CHECK_THROWS_WITH(env.render("{{ upper(| lower) }}", data), "[inja.exception.parser_error] (at 1:12) too few arguments");
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user