Fabien Potencier
Fabien Potencier
A PR for this very first step would be really nice. Bonus if you can add some tests proving that it works well with open_basedir.
Thank you @jnoordsij.
> @fabpot Regarding tests: I suppose the fixture-based tests (`*.test`) are necessary to do integration testing, e. g. including the escaping mechanism? Should I go for such tests or write...
Thank you @alexandre-daubois.
It looks like tests are still failing.
Thank you @MrYamous.
Closing as there is no more activities and the current code cannot be merged as is. Feel free to reopen.
[Playground](https://twig.symfony.com/play?data=eyJ0ZW1wbGF0ZXMiOltbImluZGV4LnR3aWciLCJ7JSBhcHBseSBsb3dlciAlfXt7IG5hbWUgfX17JSBlbmRhcHBseSAlfVxuIl1dLCJjb250ZXh0Ijp7Im5hbWUiOiJXb3JsZCdzIGJlc3QifSwidmVyc2lvbiI6IjMuMTkuMCIsIm9wdGlvbnMiOnsic3RyaWN0X3ZhcmlhYmxlcyI6dHJ1ZSwiY2hhcnNldCI6IlVURi04IiwiYXV0b2VzY2FwZSI6Imh0bWwifX0%3D)
The way it works currently is that the `apply` call is done after the evaluation of the content, so on the already escaped content. While some filters might be safe...
Closing as there is no more activities and the current code cannot be merged as is. Feel free to reopen.