Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | Make json filter safe | René Kijewski | 2022-02-16 | 9 | -49/+191 | |
| | | | | | | | | | | | | | | | | | | | | | Previously the built-in json filter had an issue that made it unsafe to use in HTML data. When used in HTML attributes an attacker who is able to supply an arbitrary string that should be JSON encoded could close the containing HTML element e.g. with `"</div>"`, and write arbitrary HTML code afterwards as long as they use apostrophes instead of quotation marks. The programmer could make this use case safe by explicitly escaping the JSON result: `{{data|json|escape}}`. In a `<script>` context the json filter was not usable at all, because in scripts HTML escaped entities are not parsed outside of XHTML documents. Without using the safe filter an attacker could close the current script using `"</script>"`. This PR fixes the problem by always escaping less-than, greater-than, ampersand, and apostrophe characters using their JSON unicode escape sequence `\u00xx`. Unless the programmer explicitly uses the safe filter, quotation marks are HTML encoded as `"`. In scripts the programmer should use the safe filter, otherwise not. | |||||
* | Update actix-test requirement from =0.1.0-beta.12 to =0.1.0-beta.13 | dependabot[bot] | 2022-02-16 | 1 | -1/+1 | |
| | | | | | | | | | | | | | | Updates the requirements on [actix-test](https://github.com/actix/actix-web) to permit the latest version. - [Release notes](https://github.com/actix/actix-web/releases) - [Changelog](https://github.com/actix/actix-web/blob/master/CHANGES.md) - [Commits](https://github.com/actix/actix-web/compare/test-v0.1.0-beta.12...test-v0.1.0-beta.13) --- updated-dependencies: - dependency-name: actix-test dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> | |||||
* | askama_mendes: upgrade mendes to 0.0.62 (#636) | Dirkjan Ochtman | 2022-02-09 | 4 | -5/+5 | |
| | ||||||
* | Add markdown filter | René Kijewski | 2022-02-07 | 6 | -4/+176 | |
| | ||||||
* | Enable tracking of the offending span of an error | René Kijewski | 2022-02-07 | 2 | -9/+25 | |
| | ||||||
* | Remove unneeded external dependencies | René Kijewski | 2022-02-04 | 3 | -5/+5 | |
| | ||||||
* | Take reference to AST ident only once | René Kijewski | 2022-02-03 | 1 | -12/+17 | |
| | ||||||
* | Replace if-let with match | René Kijewski | 2022-02-03 | 1 | -4/+6 | |
| | ||||||
* | Replace custom Cow with actual Cow | René Kijewski | 2022-02-03 | 4 | -49/+45 | |
| | ||||||
* | Update README.md, sync with the book | René Kijewski | 2022-02-02 | 2 | -3/+4 | |
| | ||||||
* | actix: upgrade to actix 4-rc.1 | Dirkjan Ochtman | 2022-02-01 | 2 | -3/+3 | |
| | ||||||
* | Use exact trybuild version | René Kijewski | 2022-01-31 | 1 | -1/+1 | |
| | | | | | | | Sometimes for no obvious reason an old version is selected and the output is different in just about every ui test. Just pin it to the currently newest version and test if an updated version still works when a new version gets released. | |||||
* | Remove used optional dependency | René Kijewski | 2022-01-31 | 1 | -1/+0 | |
| | ||||||
* | Remove `panic!()` in `loop.cycle([])` | René Kijewski | 2022-01-31 | 3 | -1/+23 | |
| | ||||||
* | Don't wrap in StrLit just to extract the str imm. | René Kijewski | 2022-01-31 | 1 | -20/+4 | |
| | ||||||
* | Update comment in TemplateInput::new() | René Kijewski | 2022-01-31 | 1 | -1/+1 | |
| | ||||||
* | Make is_shadowing_variable() failable | René Kijewski | 2022-01-31 | 2 | -15/+27 | |
| | ||||||
* | Allow comments in `{% match %}` and remove panic! | René Kijewski | 2022-01-31 | 4 | -19/+55 | |
| | ||||||
* | Parse tuple expressions | René Kijewski | 2022-01-28 | 3 | -3/+245 | |
| | | | | | | | Askama understands how to destructure tuples in let and match statements, but it does not understand how to build a tuple. This PR fixes this shortcoming. | |||||
* | Implement error propagation expression: `?` (#590) | René Kijewski | 2022-01-28 | 4 | -6/+99 | |
| | | | | | | This change allows using the operator `?` in askama expressions. It works like the same operator in Rust: if a `Result` is `Ok`, it is unwrapped. If it is an error, then the `render()` method fails with this error value. | |||||
* | Unify handling of calls (#614) | René Kijewski | 2022-01-27 | 3 | -145/+239 | |
| | | | | | Instead of having `Expr::VarCall`, `Expr::PathCall` and `Expr::MethodCall`, this PR unifies the handling of calls by removing the former three variants, and introducing `Expr::Call`. | |||||
* | Replace `&PathBuf` with `&Path` | René Kijewski | 2022-01-24 | 3 | -12/+12 | |
| | | | | | PathBuf is to String like Path is to str, so `&PathBuf` is a pointer to a pointer. Clippy does not likes that. | |||||
* | Fix json/yaml features | Jannik Obermann | 2022-01-15 | 2 | -2/+4 | |
| | ||||||
* | Tweak attribute parsing some more | Dirkjan Ochtman | 2022-01-13 | 1 | -10/+7 | |
| | ||||||
* | Add unit tests if there is one `#[template(…)]` | René Kijewski | 2022-01-13 | 4 | -0/+36 | |
| | ||||||
* | Make sure '#[template(…)]' is given exactly once | René Kijewski | 2022-01-13 | 1 | -16/+22 | |
| | ||||||
* | Rename "meta" in proc_macro parser | René Kijewski | 2022-01-13 | 1 | -3/+3 | |
| | ||||||
* | README: Adds link to Jinja | hoijui | 2022-01-13 | 1 | -1/+1 | |
| | | | ... for those of us who do not know what it is. | |||||
* | Add template argument for contexts' hasher | René Kijewski | 2022-01-12 | 1 | -2/+2 | |
| | | | | | In askama_shared::generate a custom hasher for the contexts can be given, so Heritage needs to accept the argument to. | |||||
* | `&Option<T>` → `Option<&T>` | René Kijewski | 2022-01-12 | 2 | -4/+4 | |
| | ||||||
* | Fully qualify some more paths in generated code | René Kijewski | 2022-01-12 | 1 | -3/+3 | |
| | ||||||
* | Use Template::MIME_TYPE instead of extension | René Kijewski | 2022-01-07 | 8 | -43/+25 | |
| | ||||||
* | Determine Content-Type during compilation | René Kijewski | 2022-01-07 | 3 | -0/+22 | |
| | ||||||
* | Make TemplateInput::extension() reusable | René Kijewski | 2022-01-07 | 1 | -1/+7 | |
| | ||||||
* | Unshadow function escaping() | René Kijewski | 2022-01-07 | 1 | -3/+3 | |
| | ||||||
* | Move extension_to_mime_type() to askama_shared | René Kijewski | 2022-01-07 | 5 | -27/+37 | |
| | ||||||
* | Optimize parsing of ranges | René Kijewski | 2022-01-06 | 1 | -17/+13 | |
| | | | | | | | | | | Right now almost every expression needs to be parsed twice: `expr_any()` first parses the left-hand side of a range expression, and if no `..` or `..=` was found the left-hand expression is parsed again, this time as the result of the function. This diff removes the second parsing step by first looking for `.. (opt rhs)`, then for `lhs .. (opt rhs)`. | |||||
* | Add `#[inline]` to trivial trait implementations | René Kijewski | 2022-01-06 | 1 | -0/+9 | |
| | ||||||
* | Remove the iron integration from generator | René Kijewski | 2022-01-06 | 5 | -30/+0 | |
| | | | | | | | Issue #527 removed the askama_iron package, but not the integration if someone uses askama_derive's feature with "iron". The old askama_iron crate uses askama v0.10, so it will still work. | |||||
* | Add `#![forbid(unsafe_code)]` to all crates except askama_escape | René Kijewski | 2022-01-06 | 10 | -0/+10 | |
| | ||||||
* | Add `#![deny(unreachable_pub)]` to all crates | René Kijewski | 2022-01-06 | 11 | -0/+11 | |
| | ||||||
* | No needless boxing of the error | René Kijewski | 2022-01-06 | 1 | -3/+22 | |
| | ||||||
* | Omit implicit lifetimes | René Kijewski | 2022-01-06 | 5 | -9/+9 | |
| | ||||||
* | Add `#[derive(Debug)]` for public types | René Kijewski | 2022-01-06 | 1 | -0/+3 | |
| | ||||||
* | Same number of repeats in macro pattern and body | René Kijewski | 2022-01-06 | 1 | -1/+1 | |
| | ||||||
* | No need to build a String when it gets referenced as &str implicitly | René Kijewski | 2022-01-06 | 1 | -6/+0 | |
| | ||||||
* | Combine imports from the same module | René Kijewski | 2022-01-06 | 2 | -5/+2 | |
| | ||||||
* | Remove unused imports | René Kijewski | 2022-01-06 | 1 | -7/+0 | |
| | ||||||
* | Update for actix-web beta | René Kijewski | 2022-01-05 | 4 | -32/+25 | |
| | ||||||
* | Use strict matching for prereleases | Dirkjan Ochtman | 2022-01-05 | 1 | -4/+5 | |
| |