From 9491b939516a7685c53e4cf18f3331295e3071b1 Mon Sep 17 00:00:00 2001 From: Ambrose Casanova <279373485+ambrose5773@users.noreply.github.com> Date: Mon, 5 Oct 2026 07:18:42 -0600 Subject: [PATCH] feat: drive view path containment via flight.views.restrict_to_path Expose the opt-in as a Flight::set() key in the flight.views.* family. Engine applies it to View::$restrictToPath when the view is created, same as path and extension. Default remains false. --- flight/Engine.php | 2 ++ flight/template/View.php | 1 + tests/EngineTest.php | 11 +++++++++++ 3 files changed, 14 insertions(+) diff --git a/flight/Engine.php b/flight/Engine.php index 8c1d69d..db27c1f 100644 --- a/flight/Engine.php +++ b/flight/Engine.php @@ -188,6 +188,7 @@ class Engine $this->loader->register('view', View::class, [], function (View $view) use ($self) { $view->path = $self->get('flight.views.path'); $view->extension = $self->get('flight.views.extension'); + $view->restrictToPath = (bool) $self->get('flight.views.restrict_to_path'); }); foreach (self::MAPPABLE_METHODS as $name) { @@ -202,6 +203,7 @@ class Engine $this->set('flight.debug', false); $this->set('flight.views.path', './views'); $this->set('flight.views.extension', '.php'); + $this->set('flight.views.restrict_to_path', false); $this->set('flight.content_length', true); $this->set('flight.v2.output_buffering', false); $this->set('flight.allow_method_override', true); diff --git a/flight/template/View.php b/flight/template/View.php index a2fd8f8..4798315 100644 --- a/flight/template/View.php +++ b/flight/template/View.php @@ -25,6 +25,7 @@ class View /** * When true, render(), fetch() and exists() only accept template files * that resolve inside $path. Off by default so existing behavior holds. + * Prefer Flight::set('flight.views.restrict_to_path', true); Engine applies it. */ public bool $restrictToPath = false; diff --git a/tests/EngineTest.php b/tests/EngineTest.php index 7c8226e..ed345d8 100644 --- a/tests/EngineTest.php +++ b/tests/EngineTest.php @@ -1380,4 +1380,15 @@ class EngineTest extends TestCase $this->assertSame('HEAD', $engine->request()->method); } + + public function testViewsRestrictToPathConfigIsAppliedToView(): void + { + $engine = new Engine(); + $this->assertFalse($engine->view()->restrictToPath); + + $engine = new Engine(); + $engine->set('flight.views.restrict_to_path', true); + $this->assertTrue($engine->view()->restrictToPath); + } + }