Armin Ronacher | ccf284b | 2007-05-21 16:44:26 +0200 | [diff] [blame] | 1 | # -*- coding: utf-8 -*- |
| 2 | """ |
| 3 | unit test for security features |
| 4 | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
| 5 | |
| 6 | :copyright: 2007 by Armin Ronacher. |
| 7 | :license: BSD, see LICENSE for more details. |
| 8 | """ |
Armin Ronacher | 6df604e | 2008-05-23 22:18:38 +0200 | [diff] [blame] | 9 | from jinja2.sandbox import SandboxedEnvironment, \ |
| 10 | ImmutableSandboxedEnvironment, unsafe |
Armin Ronacher | ccf284b | 2007-05-21 16:44:26 +0200 | [diff] [blame] | 11 | |
| 12 | |
| 13 | class PrivateStuff(object): |
Armin Ronacher | 4f7d2d5 | 2008-04-22 10:40:26 +0200 | [diff] [blame] | 14 | |
| 15 | def bar(self): |
| 16 | return 23 |
| 17 | |
| 18 | @unsafe |
| 19 | def foo(self): |
| 20 | return 42 |
| 21 | |
| 22 | def __repr__(self): |
| 23 | return 'PrivateStuff' |
Armin Ronacher | ccf284b | 2007-05-21 16:44:26 +0200 | [diff] [blame] | 24 | |
| 25 | |
| 26 | class PublicStuff(object): |
Armin Ronacher | ccf284b | 2007-05-21 16:44:26 +0200 | [diff] [blame] | 27 | bar = lambda self: 23 |
Armin Ronacher | 4f7d2d5 | 2008-04-22 10:40:26 +0200 | [diff] [blame] | 28 | _foo = lambda self: 42 |
| 29 | |
| 30 | def __repr__(self): |
| 31 | return 'PublicStuff' |
Armin Ronacher | ccf284b | 2007-05-21 16:44:26 +0200 | [diff] [blame] | 32 | |
| 33 | |
| 34 | test_unsafe = ''' |
Armin Ronacher | 4f7d2d5 | 2008-04-22 10:40:26 +0200 | [diff] [blame] | 35 | >>> env = MODULE.SandboxedEnvironment() |
Armin Ronacher | ccf284b | 2007-05-21 16:44:26 +0200 | [diff] [blame] | 36 | >>> env.from_string("{{ foo.foo() }}").render(foo=MODULE.PrivateStuff()) |
Armin Ronacher | 4f7d2d5 | 2008-04-22 10:40:26 +0200 | [diff] [blame] | 37 | Traceback (most recent call last): |
| 38 | ... |
Armin Ronacher | 5cdc1ac | 2008-05-07 12:17:18 +0200 | [diff] [blame] | 39 | SecurityError: <bound method PrivateStuff.foo of PrivateStuff> is not safely callable |
Armin Ronacher | ccf284b | 2007-05-21 16:44:26 +0200 | [diff] [blame] | 40 | >>> env.from_string("{{ foo.bar() }}").render(foo=MODULE.PrivateStuff()) |
| 41 | u'23' |
| 42 | |
Armin Ronacher | 4f7d2d5 | 2008-04-22 10:40:26 +0200 | [diff] [blame] | 43 | >>> env.from_string("{{ foo._foo() }}").render(foo=MODULE.PublicStuff()) |
| 44 | Traceback (most recent call last): |
| 45 | ... |
Armin Ronacher | 5cdc1ac | 2008-05-07 12:17:18 +0200 | [diff] [blame] | 46 | SecurityError: access to attribute '_foo' of 'PublicStuff' object is unsafe. |
Armin Ronacher | ccf284b | 2007-05-21 16:44:26 +0200 | [diff] [blame] | 47 | >>> env.from_string("{{ foo.bar() }}").render(foo=MODULE.PublicStuff()) |
| 48 | u'23' |
| 49 | |
| 50 | >>> env.from_string("{{ foo.__class__ }}").render(foo=42) |
| 51 | u'' |
Armin Ronacher | ccf284b | 2007-05-21 16:44:26 +0200 | [diff] [blame] | 52 | >>> env.from_string("{{ foo.func_code }}").render(foo=lambda:None) |
| 53 | u'' |
Armin Ronacher | 4f7d2d5 | 2008-04-22 10:40:26 +0200 | [diff] [blame] | 54 | >>> env.from_string("{{ foo.__class__.__subclasses__() }}").render(foo=42) |
| 55 | Traceback (most recent call last): |
| 56 | ... |
Armin Ronacher | 5cdc1ac | 2008-05-07 12:17:18 +0200 | [diff] [blame] | 57 | SecurityError: access to attribute '__class__' of 'int' object is unsafe. |
Armin Ronacher | ccf284b | 2007-05-21 16:44:26 +0200 | [diff] [blame] | 58 | ''' |
| 59 | |
| 60 | |
| 61 | test_restricted = ''' |
Armin Ronacher | 4f7d2d5 | 2008-04-22 10:40:26 +0200 | [diff] [blame] | 62 | >>> env = MODULE.SandboxedEnvironment() |
Armin Ronacher | ccf284b | 2007-05-21 16:44:26 +0200 | [diff] [blame] | 63 | >>> env.from_string("{% for item.attribute in seq %}...{% endfor %}") |
| 64 | Traceback (most recent call last): |
| 65 | ... |
Armin Ronacher | 09c002e | 2008-05-10 22:21:30 +0200 | [diff] [blame] | 66 | TemplateSyntaxError: expected token 'in', got '.' (line 1) |
Armin Ronacher | ecc051b | 2007-06-01 18:25:28 +0200 | [diff] [blame] | 67 | >>> env.from_string("{% for foo, bar.baz in seq %}...{% endfor %}") |
| 68 | Traceback (most recent call last): |
| 69 | ... |
Armin Ronacher | 09c002e | 2008-05-10 22:21:30 +0200 | [diff] [blame] | 70 | TemplateSyntaxError: expected token 'in', got '.' (line 1) |
Armin Ronacher | ccf284b | 2007-05-21 16:44:26 +0200 | [diff] [blame] | 71 | ''' |
Armin Ronacher | 6df604e | 2008-05-23 22:18:38 +0200 | [diff] [blame] | 72 | |
| 73 | |
| 74 | test_immutable_environment = ''' |
| 75 | >>> env = MODULE.ImmutableSandboxedEnvironment() |
| 76 | >>> env.from_string('{{ [].append(23) }}').render() |
| 77 | Traceback (most recent call last): |
| 78 | ... |
| 79 | SecurityError: access to attribute 'append' of 'list' object is unsafe. |
| 80 | >>> env.from_string('{{ {1:2}.clear() }}').render() |
| 81 | Traceback (most recent call last): |
| 82 | ... |
| 83 | SecurityError: access to attribute 'clear' of 'dict' object is unsafe. |
| 84 | ''' |