variable.go 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693
  1. package pongo2
  2. import (
  3. "fmt"
  4. "reflect"
  5. "strconv"
  6. "strings"
  7. )
  8. const (
  9. varTypeInt = iota
  10. varTypeIdent
  11. )
  12. var (
  13. typeOfValuePtr = reflect.TypeOf(new(Value))
  14. typeOfExecCtxPtr = reflect.TypeOf(new(ExecutionContext))
  15. )
  16. type variablePart struct {
  17. typ int
  18. s string
  19. i int
  20. isFunctionCall bool
  21. callingArgs []functionCallArgument // needed for a function call, represents all argument nodes (INode supports nested function calls)
  22. }
  23. type functionCallArgument interface {
  24. Evaluate(*ExecutionContext) (*Value, *Error)
  25. }
  26. // TODO: Add location tokens
  27. type stringResolver struct {
  28. locationToken *Token
  29. val string
  30. }
  31. type intResolver struct {
  32. locationToken *Token
  33. val int
  34. }
  35. type floatResolver struct {
  36. locationToken *Token
  37. val float64
  38. }
  39. type boolResolver struct {
  40. locationToken *Token
  41. val bool
  42. }
  43. type variableResolver struct {
  44. locationToken *Token
  45. parts []*variablePart
  46. }
  47. type nodeFilteredVariable struct {
  48. locationToken *Token
  49. resolver IEvaluator
  50. filterChain []*filterCall
  51. }
  52. type nodeVariable struct {
  53. locationToken *Token
  54. expr IEvaluator
  55. }
  56. type executionCtxEval struct{}
  57. func (v *nodeFilteredVariable) Execute(ctx *ExecutionContext, writer TemplateWriter) *Error {
  58. value, err := v.Evaluate(ctx)
  59. if err != nil {
  60. return err
  61. }
  62. writer.WriteString(value.String())
  63. return nil
  64. }
  65. func (vr *variableResolver) Execute(ctx *ExecutionContext, writer TemplateWriter) *Error {
  66. value, err := vr.Evaluate(ctx)
  67. if err != nil {
  68. return err
  69. }
  70. writer.WriteString(value.String())
  71. return nil
  72. }
  73. func (s *stringResolver) Execute(ctx *ExecutionContext, writer TemplateWriter) *Error {
  74. value, err := s.Evaluate(ctx)
  75. if err != nil {
  76. return err
  77. }
  78. writer.WriteString(value.String())
  79. return nil
  80. }
  81. func (i *intResolver) Execute(ctx *ExecutionContext, writer TemplateWriter) *Error {
  82. value, err := i.Evaluate(ctx)
  83. if err != nil {
  84. return err
  85. }
  86. writer.WriteString(value.String())
  87. return nil
  88. }
  89. func (f *floatResolver) Execute(ctx *ExecutionContext, writer TemplateWriter) *Error {
  90. value, err := f.Evaluate(ctx)
  91. if err != nil {
  92. return err
  93. }
  94. writer.WriteString(value.String())
  95. return nil
  96. }
  97. func (b *boolResolver) Execute(ctx *ExecutionContext, writer TemplateWriter) *Error {
  98. value, err := b.Evaluate(ctx)
  99. if err != nil {
  100. return err
  101. }
  102. writer.WriteString(value.String())
  103. return nil
  104. }
  105. func (v *nodeFilteredVariable) GetPositionToken() *Token {
  106. return v.locationToken
  107. }
  108. func (vr *variableResolver) GetPositionToken() *Token {
  109. return vr.locationToken
  110. }
  111. func (s *stringResolver) GetPositionToken() *Token {
  112. return s.locationToken
  113. }
  114. func (i *intResolver) GetPositionToken() *Token {
  115. return i.locationToken
  116. }
  117. func (f *floatResolver) GetPositionToken() *Token {
  118. return f.locationToken
  119. }
  120. func (b *boolResolver) GetPositionToken() *Token {
  121. return b.locationToken
  122. }
  123. func (s *stringResolver) Evaluate(ctx *ExecutionContext) (*Value, *Error) {
  124. return AsValue(s.val), nil
  125. }
  126. func (i *intResolver) Evaluate(ctx *ExecutionContext) (*Value, *Error) {
  127. return AsValue(i.val), nil
  128. }
  129. func (f *floatResolver) Evaluate(ctx *ExecutionContext) (*Value, *Error) {
  130. return AsValue(f.val), nil
  131. }
  132. func (b *boolResolver) Evaluate(ctx *ExecutionContext) (*Value, *Error) {
  133. return AsValue(b.val), nil
  134. }
  135. func (s *stringResolver) FilterApplied(name string) bool {
  136. return false
  137. }
  138. func (i *intResolver) FilterApplied(name string) bool {
  139. return false
  140. }
  141. func (f *floatResolver) FilterApplied(name string) bool {
  142. return false
  143. }
  144. func (b *boolResolver) FilterApplied(name string) bool {
  145. return false
  146. }
  147. func (nv *nodeVariable) FilterApplied(name string) bool {
  148. return nv.expr.FilterApplied(name)
  149. }
  150. func (nv *nodeVariable) Execute(ctx *ExecutionContext, writer TemplateWriter) *Error {
  151. value, err := nv.expr.Evaluate(ctx)
  152. if err != nil {
  153. return err
  154. }
  155. if !nv.expr.FilterApplied("safe") && !value.safe && value.IsString() && ctx.Autoescape {
  156. // apply escape filter
  157. value, err = filters["escape"](value, nil)
  158. if err != nil {
  159. return err
  160. }
  161. }
  162. writer.WriteString(value.String())
  163. return nil
  164. }
  165. func (executionCtxEval) Evaluate(ctx *ExecutionContext) (*Value, *Error) {
  166. return AsValue(ctx), nil
  167. }
  168. func (vr *variableResolver) FilterApplied(name string) bool {
  169. return false
  170. }
  171. func (vr *variableResolver) String() string {
  172. parts := make([]string, 0, len(vr.parts))
  173. for _, p := range vr.parts {
  174. switch p.typ {
  175. case varTypeInt:
  176. parts = append(parts, strconv.Itoa(p.i))
  177. case varTypeIdent:
  178. parts = append(parts, p.s)
  179. default:
  180. panic("unimplemented")
  181. }
  182. }
  183. return strings.Join(parts, ".")
  184. }
  185. func (vr *variableResolver) resolve(ctx *ExecutionContext) (*Value, error) {
  186. var current reflect.Value
  187. var isSafe bool
  188. for idx, part := range vr.parts {
  189. if idx == 0 {
  190. // We're looking up the first part of the variable.
  191. // First we're having a look in our private
  192. // context (e. g. information provided by tags, like the forloop)
  193. val, inPrivate := ctx.Private[vr.parts[0].s]
  194. if !inPrivate {
  195. // Nothing found? Then have a final lookup in the public context
  196. val = ctx.Public[vr.parts[0].s]
  197. }
  198. current = reflect.ValueOf(val) // Get the initial value
  199. } else {
  200. // Next parts, resolve it from current
  201. // Before resolving the pointer, let's see if we have a method to call
  202. // Problem with resolving the pointer is we're changing the receiver
  203. isFunc := false
  204. if part.typ == varTypeIdent {
  205. funcValue := current.MethodByName(part.s)
  206. if funcValue.IsValid() {
  207. current = funcValue
  208. isFunc = true
  209. }
  210. }
  211. if !isFunc {
  212. // If current a pointer, resolve it
  213. if current.Kind() == reflect.Ptr {
  214. current = current.Elem()
  215. if !current.IsValid() {
  216. // Value is not valid (anymore)
  217. return AsValue(nil), nil
  218. }
  219. }
  220. // Look up which part must be called now
  221. switch part.typ {
  222. case varTypeInt:
  223. // Calling an index is only possible for:
  224. // * slices/arrays/strings
  225. switch current.Kind() {
  226. case reflect.String, reflect.Array, reflect.Slice:
  227. if part.i >= 0 && current.Len() > part.i {
  228. current = current.Index(part.i)
  229. } else {
  230. // In Django, exceeding the length of a list is just empty.
  231. return AsValue(nil), nil
  232. }
  233. default:
  234. return nil, fmt.Errorf("Can't access an index on type %s (variable %s)",
  235. current.Kind().String(), vr.String())
  236. }
  237. case varTypeIdent:
  238. // debugging:
  239. // fmt.Printf("now = %s (kind: %s)\n", part.s, current.Kind().String())
  240. // Calling a field or key
  241. switch current.Kind() {
  242. case reflect.Struct:
  243. current = current.FieldByName(part.s)
  244. case reflect.Map:
  245. current = current.MapIndex(reflect.ValueOf(part.s))
  246. default:
  247. return nil, fmt.Errorf("Can't access a field by name on type %s (variable %s)",
  248. current.Kind().String(), vr.String())
  249. }
  250. default:
  251. panic("unimplemented")
  252. }
  253. }
  254. }
  255. if !current.IsValid() {
  256. // Value is not valid (anymore)
  257. return AsValue(nil), nil
  258. }
  259. // If current is a reflect.ValueOf(pongo2.Value), then unpack it
  260. // Happens in function calls (as a return value) or by injecting
  261. // into the execution context (e.g. in a for-loop)
  262. if current.Type() == typeOfValuePtr {
  263. tmpValue := current.Interface().(*Value)
  264. current = tmpValue.val
  265. isSafe = tmpValue.safe
  266. }
  267. // Check whether this is an interface and resolve it where required
  268. if current.Kind() == reflect.Interface {
  269. current = reflect.ValueOf(current.Interface())
  270. }
  271. // Check if the part is a function call
  272. if part.isFunctionCall || current.Kind() == reflect.Func {
  273. // Check for callable
  274. if current.Kind() != reflect.Func {
  275. return nil, fmt.Errorf("'%s' is not a function (it is %s)", vr.String(), current.Kind().String())
  276. }
  277. // Check for correct function syntax and types
  278. // func(*Value, ...) *Value
  279. t := current.Type()
  280. currArgs := part.callingArgs
  281. // If an implicit ExecCtx is needed
  282. if t.NumIn() > 0 && t.In(0) == typeOfExecCtxPtr {
  283. currArgs = append([]functionCallArgument{executionCtxEval{}}, currArgs...)
  284. }
  285. // Input arguments
  286. if len(currArgs) != t.NumIn() && !(len(currArgs) >= t.NumIn()-1 && t.IsVariadic()) {
  287. return nil,
  288. fmt.Errorf("Function input argument count (%d) of '%s' must be equal to the calling argument count (%d).",
  289. t.NumIn(), vr.String(), len(currArgs))
  290. }
  291. // Output arguments
  292. if t.NumOut() != 1 && t.NumOut() != 2 {
  293. return nil, fmt.Errorf("'%s' must have exactly 1 or 2 output arguments, the second argument must be of type error", vr.String())
  294. }
  295. // Evaluate all parameters
  296. var parameters []reflect.Value
  297. numArgs := t.NumIn()
  298. isVariadic := t.IsVariadic()
  299. var fnArg reflect.Type
  300. for idx, arg := range currArgs {
  301. pv, err := arg.Evaluate(ctx)
  302. if err != nil {
  303. return nil, err
  304. }
  305. if isVariadic {
  306. if idx >= t.NumIn()-1 {
  307. fnArg = t.In(numArgs - 1).Elem()
  308. } else {
  309. fnArg = t.In(idx)
  310. }
  311. } else {
  312. fnArg = t.In(idx)
  313. }
  314. if fnArg != typeOfValuePtr {
  315. // Function's argument is not a *pongo2.Value, then we have to check whether input argument is of the same type as the function's argument
  316. if !isVariadic {
  317. if fnArg != reflect.TypeOf(pv.Interface()) && fnArg.Kind() != reflect.Interface {
  318. return nil, fmt.Errorf("Function input argument %d of '%s' must be of type %s or *pongo2.Value (not %T).",
  319. idx, vr.String(), fnArg.String(), pv.Interface())
  320. }
  321. // Function's argument has another type, using the interface-value
  322. parameters = append(parameters, reflect.ValueOf(pv.Interface()))
  323. } else {
  324. if fnArg != reflect.TypeOf(pv.Interface()) && fnArg.Kind() != reflect.Interface {
  325. return nil, fmt.Errorf("Function variadic input argument of '%s' must be of type %s or *pongo2.Value (not %T).",
  326. vr.String(), fnArg.String(), pv.Interface())
  327. }
  328. // Function's argument has another type, using the interface-value
  329. parameters = append(parameters, reflect.ValueOf(pv.Interface()))
  330. }
  331. } else {
  332. // Function's argument is a *pongo2.Value
  333. parameters = append(parameters, reflect.ValueOf(pv))
  334. }
  335. }
  336. // Check if any of the values are invalid
  337. for _, p := range parameters {
  338. if p.Kind() == reflect.Invalid {
  339. return nil, fmt.Errorf("Calling a function using an invalid parameter")
  340. }
  341. }
  342. // Call it and get first return parameter back
  343. values := current.Call(parameters)
  344. rv := values[0]
  345. if t.NumOut() == 2 {
  346. e := values[1].Interface()
  347. if e != nil {
  348. err, ok := e.(error)
  349. if !ok {
  350. return nil, fmt.Errorf("The second return value is not an error")
  351. }
  352. if err != nil {
  353. return nil, err
  354. }
  355. }
  356. }
  357. if rv.Type() != typeOfValuePtr {
  358. current = reflect.ValueOf(rv.Interface())
  359. } else {
  360. // Return the function call value
  361. current = rv.Interface().(*Value).val
  362. isSafe = rv.Interface().(*Value).safe
  363. }
  364. }
  365. if !current.IsValid() {
  366. // Value is not valid (e. g. NIL value)
  367. return AsValue(nil), nil
  368. }
  369. }
  370. return &Value{val: current, safe: isSafe}, nil
  371. }
  372. func (vr *variableResolver) Evaluate(ctx *ExecutionContext) (*Value, *Error) {
  373. value, err := vr.resolve(ctx)
  374. if err != nil {
  375. return AsValue(nil), ctx.Error(err.Error(), vr.locationToken)
  376. }
  377. return value, nil
  378. }
  379. func (v *nodeFilteredVariable) FilterApplied(name string) bool {
  380. for _, filter := range v.filterChain {
  381. if filter.name == name {
  382. return true
  383. }
  384. }
  385. return false
  386. }
  387. func (v *nodeFilteredVariable) Evaluate(ctx *ExecutionContext) (*Value, *Error) {
  388. value, err := v.resolver.Evaluate(ctx)
  389. if err != nil {
  390. return nil, err
  391. }
  392. for _, filter := range v.filterChain {
  393. value, err = filter.Execute(value, ctx)
  394. if err != nil {
  395. return nil, err
  396. }
  397. }
  398. return value, nil
  399. }
  400. // IDENT | IDENT.(IDENT|NUMBER)...
  401. func (p *Parser) parseVariableOrLiteral() (IEvaluator, *Error) {
  402. t := p.Current()
  403. if t == nil {
  404. return nil, p.Error("Unexpected EOF, expected a number, string, keyword or identifier.", p.lastToken)
  405. }
  406. // Is first part a number or a string, there's nothing to resolve (because there's only to return the value then)
  407. switch t.Typ {
  408. case TokenNumber:
  409. p.Consume()
  410. // One exception to the rule that we don't have float64 literals is at the beginning
  411. // of an expression (or a variable name). Since we know we started with an integer
  412. // which can't obviously be a variable name, we can check whether the first number
  413. // is followed by dot (and then a number again). If so we're converting it to a float64.
  414. if p.Match(TokenSymbol, ".") != nil {
  415. // float64
  416. t2 := p.MatchType(TokenNumber)
  417. if t2 == nil {
  418. return nil, p.Error("Expected a number after the '.'.", nil)
  419. }
  420. f, err := strconv.ParseFloat(fmt.Sprintf("%s.%s", t.Val, t2.Val), 64)
  421. if err != nil {
  422. return nil, p.Error(err.Error(), t)
  423. }
  424. fr := &floatResolver{
  425. locationToken: t,
  426. val: f,
  427. }
  428. return fr, nil
  429. }
  430. i, err := strconv.Atoi(t.Val)
  431. if err != nil {
  432. return nil, p.Error(err.Error(), t)
  433. }
  434. nr := &intResolver{
  435. locationToken: t,
  436. val: i,
  437. }
  438. return nr, nil
  439. case TokenString:
  440. p.Consume()
  441. sr := &stringResolver{
  442. locationToken: t,
  443. val: t.Val,
  444. }
  445. return sr, nil
  446. case TokenKeyword:
  447. p.Consume()
  448. switch t.Val {
  449. case "true":
  450. br := &boolResolver{
  451. locationToken: t,
  452. val: true,
  453. }
  454. return br, nil
  455. case "false":
  456. br := &boolResolver{
  457. locationToken: t,
  458. val: false,
  459. }
  460. return br, nil
  461. default:
  462. return nil, p.Error("This keyword is not allowed here.", nil)
  463. }
  464. }
  465. resolver := &variableResolver{
  466. locationToken: t,
  467. }
  468. // First part of a variable MUST be an identifier
  469. if t.Typ != TokenIdentifier {
  470. return nil, p.Error("Expected either a number, string, keyword or identifier.", t)
  471. }
  472. resolver.parts = append(resolver.parts, &variablePart{
  473. typ: varTypeIdent,
  474. s: t.Val,
  475. })
  476. p.Consume() // we consumed the first identifier of the variable name
  477. variableLoop:
  478. for p.Remaining() > 0 {
  479. t = p.Current()
  480. if p.Match(TokenSymbol, ".") != nil {
  481. // Next variable part (can be either NUMBER or IDENT)
  482. t2 := p.Current()
  483. if t2 != nil {
  484. switch t2.Typ {
  485. case TokenIdentifier:
  486. resolver.parts = append(resolver.parts, &variablePart{
  487. typ: varTypeIdent,
  488. s: t2.Val,
  489. })
  490. p.Consume() // consume: IDENT
  491. continue variableLoop
  492. case TokenNumber:
  493. i, err := strconv.Atoi(t2.Val)
  494. if err != nil {
  495. return nil, p.Error(err.Error(), t2)
  496. }
  497. resolver.parts = append(resolver.parts, &variablePart{
  498. typ: varTypeInt,
  499. i: i,
  500. })
  501. p.Consume() // consume: NUMBER
  502. continue variableLoop
  503. default:
  504. return nil, p.Error("This token is not allowed within a variable name.", t2)
  505. }
  506. } else {
  507. // EOF
  508. return nil, p.Error("Unexpected EOF, expected either IDENTIFIER or NUMBER after DOT.",
  509. p.lastToken)
  510. }
  511. } else if p.Match(TokenSymbol, "(") != nil {
  512. // Function call
  513. // FunctionName '(' Comma-separated list of expressions ')'
  514. part := resolver.parts[len(resolver.parts)-1]
  515. part.isFunctionCall = true
  516. argumentLoop:
  517. for {
  518. if p.Remaining() == 0 {
  519. return nil, p.Error("Unexpected EOF, expected function call argument list.", p.lastToken)
  520. }
  521. if p.Peek(TokenSymbol, ")") == nil {
  522. // No closing bracket, so we're parsing an expression
  523. exprArg, err := p.ParseExpression()
  524. if err != nil {
  525. return nil, err
  526. }
  527. part.callingArgs = append(part.callingArgs, exprArg)
  528. if p.Match(TokenSymbol, ")") != nil {
  529. // If there's a closing bracket after an expression, we will stop parsing the arguments
  530. break argumentLoop
  531. } else {
  532. // If there's NO closing bracket, there MUST be an comma
  533. if p.Match(TokenSymbol, ",") == nil {
  534. return nil, p.Error("Missing comma or closing bracket after argument.", nil)
  535. }
  536. }
  537. } else {
  538. // We got a closing bracket, so stop parsing arguments
  539. p.Consume()
  540. break argumentLoop
  541. }
  542. }
  543. // We're done parsing the function call, next variable part
  544. continue variableLoop
  545. }
  546. // No dot or function call? Then we're done with the variable parsing
  547. break
  548. }
  549. return resolver, nil
  550. }
  551. func (p *Parser) parseVariableOrLiteralWithFilter() (*nodeFilteredVariable, *Error) {
  552. v := &nodeFilteredVariable{
  553. locationToken: p.Current(),
  554. }
  555. // Parse the variable name
  556. resolver, err := p.parseVariableOrLiteral()
  557. if err != nil {
  558. return nil, err
  559. }
  560. v.resolver = resolver
  561. // Parse all the filters
  562. filterLoop:
  563. for p.Match(TokenSymbol, "|") != nil {
  564. // Parse one single filter
  565. filter, err := p.parseFilter()
  566. if err != nil {
  567. return nil, err
  568. }
  569. // Check sandbox filter restriction
  570. if _, isBanned := p.template.set.bannedFilters[filter.name]; isBanned {
  571. return nil, p.Error(fmt.Sprintf("Usage of filter '%s' is not allowed (sandbox restriction active).", filter.name), nil)
  572. }
  573. v.filterChain = append(v.filterChain, filter)
  574. continue filterLoop
  575. }
  576. return v, nil
  577. }
  578. func (p *Parser) parseVariableElement() (INode, *Error) {
  579. node := &nodeVariable{
  580. locationToken: p.Current(),
  581. }
  582. p.Consume() // consume '{{'
  583. expr, err := p.ParseExpression()
  584. if err != nil {
  585. return nil, err
  586. }
  587. node.expr = expr
  588. if p.Match(TokenSymbol, "}}") == nil {
  589. return nil, p.Error("'}}' expected", nil)
  590. }
  591. return node, nil
  592. }