feat: drive view path containment via flight.views.restrict_to_path

Expose the opt-in as a Flight::set() key in the flight.views.* family. Engine applies it to View::$restrictToPath when the view is created, same as path and extension. Default remains false.
pull/729/head
Ambrose Casanova 2 days ago
parent eac9fef021
commit 9491b93951

@ -188,6 +188,7 @@ class Engine
$this->loader->register('view', View::class, [], function (View $view) use ($self) { $this->loader->register('view', View::class, [], function (View $view) use ($self) {
$view->path = $self->get('flight.views.path'); $view->path = $self->get('flight.views.path');
$view->extension = $self->get('flight.views.extension'); $view->extension = $self->get('flight.views.extension');
$view->restrictToPath = (bool) $self->get('flight.views.restrict_to_path');
}); });
foreach (self::MAPPABLE_METHODS as $name) { foreach (self::MAPPABLE_METHODS as $name) {
@ -202,6 +203,7 @@ class Engine
$this->set('flight.debug', false); $this->set('flight.debug', false);
$this->set('flight.views.path', './views'); $this->set('flight.views.path', './views');
$this->set('flight.views.extension', '.php'); $this->set('flight.views.extension', '.php');
$this->set('flight.views.restrict_to_path', false);
$this->set('flight.content_length', true); $this->set('flight.content_length', true);
$this->set('flight.v2.output_buffering', false); $this->set('flight.v2.output_buffering', false);
$this->set('flight.allow_method_override', true); $this->set('flight.allow_method_override', true);

@ -25,6 +25,7 @@ class View
/** /**
* When true, render(), fetch() and exists() only accept template files * When true, render(), fetch() and exists() only accept template files
* that resolve inside $path. Off by default so existing behavior holds. * that resolve inside $path. Off by default so existing behavior holds.
* Prefer Flight::set('flight.views.restrict_to_path', true); Engine applies it.
*/ */
public bool $restrictToPath = false; public bool $restrictToPath = false;

@ -1380,4 +1380,15 @@ class EngineTest extends TestCase
$this->assertSame('HEAD', $engine->request()->method); $this->assertSame('HEAD', $engine->request()->method);
} }
public function testViewsRestrictToPathConfigIsAppliedToView(): void
{
$engine = new Engine();
$this->assertFalse($engine->view()->restrictToPath);
$engine = new Engine();
$engine->set('flight.views.restrict_to_path', true);
$this->assertTrue($engine->view()->restrictToPath);
}
} }

Loading…
Cancel
Save