variable.go 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656
  1. package pongo2
  2. import (
  3. "bytes"
  4. "fmt"
  5. "reflect"
  6. "strconv"
  7. "strings"
  8. )
  9. const (
  10. varTypeInt = iota
  11. varTypeIdent
  12. )
  13. type variablePart struct {
  14. typ int
  15. s string
  16. i int
  17. is_function_call bool
  18. calling_args []functionCallArgument // needed for a function call, represents all argument nodes (INode supports nested function calls)
  19. }
  20. type functionCallArgument interface {
  21. Evaluate(*ExecutionContext) (*Value, *Error)
  22. }
  23. // TODO: Add location tokens
  24. type stringResolver struct {
  25. location_token *Token
  26. val string
  27. }
  28. type intResolver struct {
  29. location_token *Token
  30. val int
  31. }
  32. type floatResolver struct {
  33. location_token *Token
  34. val float64
  35. }
  36. type boolResolver struct {
  37. location_token *Token
  38. val bool
  39. }
  40. type variableResolver struct {
  41. location_token *Token
  42. parts []*variablePart
  43. }
  44. type nodeFilteredVariable struct {
  45. location_token *Token
  46. resolver IEvaluator
  47. filterChain []*filterCall
  48. }
  49. type nodeVariable struct {
  50. location_token *Token
  51. expr IEvaluator
  52. }
  53. func (expr *nodeFilteredVariable) Execute(ctx *ExecutionContext, buffer *bytes.Buffer) *Error {
  54. value, err := expr.Evaluate(ctx)
  55. if err != nil {
  56. return err
  57. }
  58. buffer.WriteString(value.String())
  59. return nil
  60. }
  61. func (expr *variableResolver) Execute(ctx *ExecutionContext, buffer *bytes.Buffer) *Error {
  62. value, err := expr.Evaluate(ctx)
  63. if err != nil {
  64. return err
  65. }
  66. buffer.WriteString(value.String())
  67. return nil
  68. }
  69. func (expr *stringResolver) Execute(ctx *ExecutionContext, buffer *bytes.Buffer) *Error {
  70. value, err := expr.Evaluate(ctx)
  71. if err != nil {
  72. return err
  73. }
  74. buffer.WriteString(value.String())
  75. return nil
  76. }
  77. func (expr *intResolver) Execute(ctx *ExecutionContext, buffer *bytes.Buffer) *Error {
  78. value, err := expr.Evaluate(ctx)
  79. if err != nil {
  80. return err
  81. }
  82. buffer.WriteString(value.String())
  83. return nil
  84. }
  85. func (expr *floatResolver) Execute(ctx *ExecutionContext, buffer *bytes.Buffer) *Error {
  86. value, err := expr.Evaluate(ctx)
  87. if err != nil {
  88. return err
  89. }
  90. buffer.WriteString(value.String())
  91. return nil
  92. }
  93. func (expr *boolResolver) Execute(ctx *ExecutionContext, buffer *bytes.Buffer) *Error {
  94. value, err := expr.Evaluate(ctx)
  95. if err != nil {
  96. return err
  97. }
  98. buffer.WriteString(value.String())
  99. return nil
  100. }
  101. func (v *nodeFilteredVariable) GetPositionToken() *Token {
  102. return v.location_token
  103. }
  104. func (v *variableResolver) GetPositionToken() *Token {
  105. return v.location_token
  106. }
  107. func (v *stringResolver) GetPositionToken() *Token {
  108. return v.location_token
  109. }
  110. func (v *intResolver) GetPositionToken() *Token {
  111. return v.location_token
  112. }
  113. func (v *floatResolver) GetPositionToken() *Token {
  114. return v.location_token
  115. }
  116. func (v *boolResolver) GetPositionToken() *Token {
  117. return v.location_token
  118. }
  119. func (s *stringResolver) Evaluate(ctx *ExecutionContext) (*Value, *Error) {
  120. return AsValue(s.val), nil
  121. }
  122. func (i *intResolver) Evaluate(ctx *ExecutionContext) (*Value, *Error) {
  123. return AsValue(i.val), nil
  124. }
  125. func (f *floatResolver) Evaluate(ctx *ExecutionContext) (*Value, *Error) {
  126. return AsValue(f.val), nil
  127. }
  128. func (b *boolResolver) Evaluate(ctx *ExecutionContext) (*Value, *Error) {
  129. return AsValue(b.val), nil
  130. }
  131. func (s *stringResolver) FilterApplied(name string) bool {
  132. return false
  133. }
  134. func (i *intResolver) FilterApplied(name string) bool {
  135. return false
  136. }
  137. func (f *floatResolver) FilterApplied(name string) bool {
  138. return false
  139. }
  140. func (b *boolResolver) FilterApplied(name string) bool {
  141. return false
  142. }
  143. func (nv *nodeVariable) FilterApplied(name string) bool {
  144. return nv.expr.FilterApplied(name)
  145. }
  146. func (nv *nodeVariable) Execute(ctx *ExecutionContext, buffer *bytes.Buffer) *Error {
  147. value, err := nv.expr.Evaluate(ctx)
  148. if err != nil {
  149. return err
  150. }
  151. if !nv.expr.FilterApplied("safe") && !value.safe && value.IsString() && ctx.Autoescape {
  152. // apply escape filter
  153. value, err = filters["escape"](value, nil)
  154. if err != nil {
  155. return err
  156. }
  157. }
  158. buffer.WriteString(value.String())
  159. return nil
  160. }
  161. func (vr *variableResolver) FilterApplied(name string) bool {
  162. return false
  163. }
  164. func (vr *variableResolver) String() string {
  165. parts := make([]string, 0, len(vr.parts))
  166. for _, p := range vr.parts {
  167. switch p.typ {
  168. case varTypeInt:
  169. parts = append(parts, strconv.Itoa(p.i))
  170. case varTypeIdent:
  171. parts = append(parts, p.s)
  172. default:
  173. panic("unimplemented")
  174. }
  175. }
  176. return strings.Join(parts, ".")
  177. }
  178. func (vr *variableResolver) resolve(ctx *ExecutionContext) (*Value, error) {
  179. var current reflect.Value
  180. var is_safe bool
  181. for idx, part := range vr.parts {
  182. if idx == 0 {
  183. // We're looking up the first part of the variable.
  184. // First we're having a look in our private
  185. // context (e. g. information provided by tags, like the forloop)
  186. val, in_private := ctx.Private[vr.parts[0].s]
  187. if !in_private {
  188. // Nothing found? Then have a final lookup in the public context
  189. val = ctx.Public[vr.parts[0].s]
  190. }
  191. current = reflect.ValueOf(val) // Get the initial value
  192. } else {
  193. // Next parts, resolve it from current
  194. // Before resolving the pointer, let's see if we have a method to call
  195. // Problem with resolving the pointer is we're changing the receiver
  196. is_func := false
  197. if part.typ == varTypeIdent {
  198. func_value := current.MethodByName(part.s)
  199. if func_value.IsValid() {
  200. current = func_value
  201. is_func = true
  202. }
  203. }
  204. if !is_func {
  205. // If current a pointer, resolve it
  206. if current.Kind() == reflect.Ptr {
  207. current = current.Elem()
  208. if !current.IsValid() {
  209. // Value is not valid (anymore)
  210. return AsValue(nil), nil
  211. }
  212. }
  213. // Look up which part must be called now
  214. switch part.typ {
  215. case varTypeInt:
  216. // Calling an index is only possible for:
  217. // * slices/arrays/strings
  218. switch current.Kind() {
  219. case reflect.String, reflect.Array, reflect.Slice:
  220. current = current.Index(part.i)
  221. default:
  222. return nil, fmt.Errorf("Can't access an index on type %s (variable %s)",
  223. current.Kind().String(), vr.String())
  224. }
  225. case varTypeIdent:
  226. // debugging:
  227. // fmt.Printf("now = %s (kind: %s)\n", part.s, current.Kind().String())
  228. // Calling a field or key
  229. switch current.Kind() {
  230. case reflect.Struct:
  231. current = current.FieldByName(part.s)
  232. case reflect.Map:
  233. current = current.MapIndex(reflect.ValueOf(part.s))
  234. default:
  235. return nil, fmt.Errorf("Can't access a field by name on type %s (variable %s)",
  236. current.Kind().String(), vr.String())
  237. }
  238. default:
  239. panic("unimplemented")
  240. }
  241. }
  242. }
  243. if !current.IsValid() {
  244. // Value is not valid (anymore)
  245. return AsValue(nil), nil
  246. }
  247. // If current is a reflect.ValueOf(pongo2.Value), then unpack it
  248. // Happens in function calls (as a return value) or by injecting
  249. // into the execution context (e.g. in a for-loop)
  250. if current.Type() == reflect.TypeOf(&Value{}) {
  251. tmp_value := current.Interface().(*Value)
  252. current = tmp_value.val
  253. is_safe = tmp_value.safe
  254. }
  255. // Check whether this is an interface and resolve it where required
  256. if current.Kind() == reflect.Interface {
  257. current = reflect.ValueOf(current.Interface())
  258. }
  259. // Check if the part is a function call
  260. if part.is_function_call || current.Kind() == reflect.Func {
  261. // Check for callable
  262. if current.Kind() != reflect.Func {
  263. return nil, fmt.Errorf("'%s' is not a function (it is %s).", vr.String(), current.Kind().String())
  264. }
  265. // Check for correct function syntax and types
  266. // func(*Value, ...) *Value
  267. t := current.Type()
  268. // Input arguments
  269. if len(part.calling_args) != t.NumIn() && !(len(part.calling_args) >= t.NumIn()-1 && t.IsVariadic()) {
  270. return nil,
  271. fmt.Errorf("Function input argument count (%d) of '%s' must be equal to the calling argument count (%d).",
  272. t.NumIn(), vr.String(), len(part.calling_args))
  273. }
  274. // Output arguments
  275. if t.NumOut() != 1 {
  276. return nil, fmt.Errorf("'%s' must have exactly 1 output argument.", vr.String())
  277. }
  278. // Evaluate all parameters
  279. parameters := make([]reflect.Value, 0)
  280. num_args := t.NumIn()
  281. is_variadic := t.IsVariadic()
  282. var fn_arg reflect.Type
  283. for idx, arg := range part.calling_args {
  284. pv, err := arg.Evaluate(ctx)
  285. if err != nil {
  286. return nil, err
  287. }
  288. if is_variadic {
  289. if idx >= t.NumIn()-1 {
  290. fn_arg = t.In(num_args - 1).Elem()
  291. } else {
  292. fn_arg = t.In(idx)
  293. }
  294. } else {
  295. fn_arg = t.In(idx)
  296. }
  297. if fn_arg != reflect.TypeOf(new(Value)) {
  298. // Function's argument is not a *pongo2.Value, then we have to check whether input argument is of the same type as the function's argument
  299. if !is_variadic {
  300. if fn_arg != reflect.TypeOf(pv.Interface()) && fn_arg.Kind() != reflect.Interface {
  301. return nil, fmt.Errorf("Function input argument %d of '%s' must be of type %s or *pongo2.Value (not %T).",
  302. idx, vr.String(), fn_arg.String(), pv.Interface())
  303. } else {
  304. // Function's argument has another type, using the interface-value
  305. parameters = append(parameters, reflect.ValueOf(pv.Interface()))
  306. }
  307. } else {
  308. if fn_arg != reflect.TypeOf(pv.Interface()) && fn_arg.Kind() != reflect.Interface {
  309. return nil, fmt.Errorf("Function variadic input argument of '%s' must be of type %s or *pongo2.Value (not %T).",
  310. vr.String(), fn_arg.String(), pv.Interface())
  311. } else {
  312. // Function's argument has another type, using the interface-value
  313. parameters = append(parameters, reflect.ValueOf(pv.Interface()))
  314. }
  315. }
  316. } else {
  317. // Function's argument is a *pongo2.Value
  318. parameters = append(parameters, reflect.ValueOf(pv))
  319. }
  320. }
  321. // Call it and get first return parameter back
  322. rv := current.Call(parameters)[0]
  323. if rv.Type() != reflect.TypeOf(new(Value)) {
  324. current = reflect.ValueOf(rv.Interface())
  325. } else {
  326. // Return the function call value
  327. current = rv.Interface().(*Value).val
  328. is_safe = rv.Interface().(*Value).safe
  329. }
  330. }
  331. }
  332. if !current.IsValid() {
  333. // Value is not valid (e. g. NIL value)
  334. return AsValue(nil), nil
  335. }
  336. return &Value{val: current, safe: is_safe}, nil
  337. }
  338. func (vr *variableResolver) Evaluate(ctx *ExecutionContext) (*Value, *Error) {
  339. value, err := vr.resolve(ctx)
  340. if err != nil {
  341. return AsValue(nil), ctx.Error(err.Error(), vr.location_token)
  342. }
  343. return value, nil
  344. }
  345. func (v *nodeFilteredVariable) FilterApplied(name string) bool {
  346. for _, filter := range v.filterChain {
  347. if filter.name == name {
  348. return true
  349. }
  350. }
  351. return false
  352. }
  353. func (v *nodeFilteredVariable) Evaluate(ctx *ExecutionContext) (*Value, *Error) {
  354. value, err := v.resolver.Evaluate(ctx)
  355. if err != nil {
  356. return nil, err
  357. }
  358. for _, filter := range v.filterChain {
  359. value, err = filter.Execute(value, ctx)
  360. if err != nil {
  361. return nil, err
  362. }
  363. }
  364. return value, nil
  365. }
  366. // IDENT | IDENT.(IDENT|NUMBER)...
  367. func (p *Parser) parseVariableOrLiteral() (IEvaluator, *Error) {
  368. t := p.Current()
  369. if t == nil {
  370. return nil, p.Error("Unexpected EOF, expected a number, string, keyword or identifier.", p.last_token)
  371. }
  372. // Is first part a number or a string, there's nothing to resolve (because there's only to return the value then)
  373. switch t.Typ {
  374. case TokenNumber:
  375. p.Consume()
  376. // One exception to the rule that we don't have float64 literals is at the beginning
  377. // of an expression (or a variable name). Since we know we started with an integer
  378. // which can't obviously be a variable name, we can check whether the first number
  379. // is followed by dot (and then a number again). If so we're converting it to a float64.
  380. if p.Match(TokenSymbol, ".") != nil {
  381. // float64
  382. t2 := p.MatchType(TokenNumber)
  383. if t2 == nil {
  384. return nil, p.Error("Expected a number after the '.'.", nil)
  385. }
  386. f, err := strconv.ParseFloat(fmt.Sprintf("%s.%s", t.Val, t2.Val), 64)
  387. if err != nil {
  388. return nil, p.Error(err.Error(), t)
  389. }
  390. fr := &floatResolver{
  391. location_token: t,
  392. val: f,
  393. }
  394. return fr, nil
  395. } else {
  396. i, err := strconv.Atoi(t.Val)
  397. if err != nil {
  398. return nil, p.Error(err.Error(), t)
  399. }
  400. nr := &intResolver{
  401. location_token: t,
  402. val: i,
  403. }
  404. return nr, nil
  405. }
  406. case TokenString:
  407. p.Consume()
  408. sr := &stringResolver{
  409. location_token: t,
  410. val: t.Val,
  411. }
  412. return sr, nil
  413. case TokenKeyword:
  414. p.Consume()
  415. switch t.Val {
  416. case "true":
  417. br := &boolResolver{
  418. location_token: t,
  419. val: true,
  420. }
  421. return br, nil
  422. case "false":
  423. br := &boolResolver{
  424. location_token: t,
  425. val: false,
  426. }
  427. return br, nil
  428. default:
  429. return nil, p.Error("This keyword is not allowed here.", nil)
  430. }
  431. }
  432. resolver := &variableResolver{
  433. location_token: t,
  434. }
  435. // First part of a variable MUST be an identifier
  436. if t.Typ != TokenIdentifier {
  437. return nil, p.Error("Expected either a number, string, keyword or identifier.", t)
  438. }
  439. resolver.parts = append(resolver.parts, &variablePart{
  440. typ: varTypeIdent,
  441. s: t.Val,
  442. })
  443. p.Consume() // we consumed the first identifier of the variable name
  444. variableLoop:
  445. for p.Remaining() > 0 {
  446. t = p.Current()
  447. if p.Match(TokenSymbol, ".") != nil {
  448. // Next variable part (can be either NUMBER or IDENT)
  449. t2 := p.Current()
  450. if t2 != nil {
  451. switch t2.Typ {
  452. case TokenIdentifier:
  453. resolver.parts = append(resolver.parts, &variablePart{
  454. typ: varTypeIdent,
  455. s: t2.Val,
  456. })
  457. p.Consume() // consume: IDENT
  458. continue variableLoop
  459. case TokenNumber:
  460. i, err := strconv.Atoi(t2.Val)
  461. if err != nil {
  462. return nil, p.Error(err.Error(), t2)
  463. }
  464. resolver.parts = append(resolver.parts, &variablePart{
  465. typ: varTypeInt,
  466. i: i,
  467. })
  468. p.Consume() // consume: NUMBER
  469. continue variableLoop
  470. default:
  471. return nil, p.Error("This token is not allowed within a variable name.", t2)
  472. }
  473. } else {
  474. // EOF
  475. return nil, p.Error("Unexpected EOF, expected either IDENTIFIER or NUMBER after DOT.",
  476. p.last_token)
  477. }
  478. } else if p.Match(TokenSymbol, "(") != nil {
  479. // Function call
  480. // FunctionName '(' Comma-separated list of expressions ')'
  481. part := resolver.parts[len(resolver.parts)-1]
  482. part.is_function_call = true
  483. argumentLoop:
  484. for {
  485. if p.Remaining() == 0 {
  486. return nil, p.Error("Unexpected EOF, expected function call argument list.", p.last_token)
  487. }
  488. if p.Peek(TokenSymbol, ")") == nil {
  489. // No closing bracket, so we're parsing an expression
  490. expr_arg, err := p.ParseExpression()
  491. if err != nil {
  492. return nil, err
  493. }
  494. part.calling_args = append(part.calling_args, expr_arg)
  495. if p.Match(TokenSymbol, ")") != nil {
  496. // If there's a closing bracket after an expression, we will stop parsing the arguments
  497. break argumentLoop
  498. } else {
  499. // If there's NO closing bracket, there MUST be an comma
  500. if p.Match(TokenSymbol, ",") == nil {
  501. return nil, p.Error("Missing comma or closing bracket after argument.", nil)
  502. }
  503. }
  504. } else {
  505. // We got a closing bracket, so stop parsing arguments
  506. p.Consume()
  507. break argumentLoop
  508. }
  509. }
  510. // We're done parsing the function call, next variable part
  511. continue variableLoop
  512. }
  513. // No dot or function call? Then we're done with the variable parsing
  514. break
  515. }
  516. return resolver, nil
  517. }
  518. func (p *Parser) parseVariableOrLiteralWithFilter() (*nodeFilteredVariable, *Error) {
  519. v := &nodeFilteredVariable{
  520. location_token: p.Current(),
  521. }
  522. // Parse the variable name
  523. resolver, err := p.parseVariableOrLiteral()
  524. if err != nil {
  525. return nil, err
  526. }
  527. v.resolver = resolver
  528. // Parse all the filters
  529. filterLoop:
  530. for p.Match(TokenSymbol, "|") != nil {
  531. // Parse one single filter
  532. filter, err := p.parseFilter()
  533. if err != nil {
  534. return nil, err
  535. }
  536. // Check sandbox filter restriction
  537. if _, is_banned := p.template.set.bannedFilters[filter.name]; is_banned {
  538. return nil, p.Error(fmt.Sprintf("Usage of filter '%s' is not allowed (sandbox restriction active).", filter.name), nil)
  539. }
  540. v.filterChain = append(v.filterChain, filter)
  541. continue filterLoop
  542. return nil, p.Error("This token is not allowed within a variable.", nil)
  543. }
  544. return v, nil
  545. }
  546. func (p *Parser) parseVariableElement() (INode, *Error) {
  547. node := &nodeVariable{
  548. location_token: p.Current(),
  549. }
  550. p.Consume() // consume '{{'
  551. expr, err := p.ParseExpression()
  552. if err != nil {
  553. return nil, err
  554. }
  555. node.expr = expr
  556. if p.Match(TokenSymbol, "}}") == nil {
  557. return nil, p.Error("'}}' expected", nil)
  558. }
  559. return node, nil
  560. }