View Issue Details

This bug affects 1 person(s).
 2
IDProjectCategoryView StatusLast Update
19952Bug reportsTheme editorpublic2025-02-04 08:46
ReporterDenisChenu Assigned To 
PrioritynoneSeverityminor 
Status newResolutionopen 
Product Version6.6.x 
Summary19952: Unable to use {{ dump(aSurveyInfo) }} in
Description

When try to use {{ dump(aSurveyInfo) }} with debug set : receive

Twig\Sandbox\SecurityNotAllowedMethodError
Calling "__tostring" method on a "TemplateConfiguration" object is not allowed.

Steps To Reproduce

Steps to reproduce

Add {{ dump(aSurveyInfo) }} inside you theme file (or import inclided theme)
set debug
Test

Expected result

See the aSurveyInfo array

Actual result

Error page

TagsNo tags attached.
Attached Files
dump_vanilla.zip (114,636 bytes)
Bug heat2
Complete LimeSurvey version number (& build)6.10.2
I will donate to the project if issue is resolvedNo
Browsernot relevant
Database type & versionnot relevant
Server OS (if known)not relevant
Webserver software & version (if known)nginx
PHP VersionPHP Version 8.3.16

Relationships

related to 19894 new Calling "__tostring" method on a "SimpleXMLElement" object is not allowed 

Users monitoring this issue

There are no users monitoring this issue.

Activities

DenisChenu

DenisChenu

2025-02-04 08:45

developer   ~81966

Twig_Sandbox_SecurityNotAllowedMethodError.html (42,448 bytes)   
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" data-lt-installed="true"><head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<title>Twig\Sandbox\SecurityNotAllowedMethodError</title>

<style type="text/css">
/*<![CDATA[*/
html,body,div,span,applet,object,iframe,h1,h2,h3,h4,h5,h6,p,blockquote,pre,a,abbr,acronym,address,big,cite,code,del,dfn,em,font,img,ins,kbd,q,s,samp,small,strike,strong,sub,sup,tt,var,b,u,i,center,dl,dt,dd,ol,ul,li,fieldset,form,label,legend,table,caption,tbody,tfoot,thead,tr,th,td{border:0;outline:0;font-size:100%;vertical-align:baseline;background:transparent;margin:0;padding:0;}
body{line-height:1;}
ol,ul{list-style:none;}
blockquote,q{quotes:none;}
blockquote:before,blockquote:after,q:before,q:after{content:none;}
:focus{outline:0;}
ins{text-decoration:none;}
del{text-decoration:line-through;}
table{border-collapse:collapse;border-spacing:0;}

body {
	font: normal 9pt "Verdana";
	color: #000;
	background: #fff;
}

h1 {
	font: normal 18pt "Verdana";
	color: #f00;
	margin-bottom: .5em;
}

h2 {
	font: normal 14pt "Verdana";
	color: #800000;
	margin-bottom: .5em;
}

h3 {
	font: bold 11pt "Verdana";
}

pre {
	font: normal 11pt Menlo, Consolas, "Lucida Console", Monospace;
}

pre span.error {
	display: block;
	background: #fce3e3;
}

pre span.ln {
	color: #999;
	padding-right: 0.5em;
	border-right: 1px solid #ccc;
}

pre span.error-ln {
	font-weight: bold;
}

.container {
	margin: 1em 4em;
}

.version {
	color: gray;
	font-size: 8pt;
	border-top: 1px solid #aaa;
	padding-top: 1em;
	margin-bottom: 1em;
}

.message {
	color: #000;
	padding: 1em;
	font-size: 11pt;
	background: #f3f3f3;
	-webkit-border-radius: 10px;
	-moz-border-radius: 10px;
	border-radius: 10px;
	margin-bottom: 1em;
	line-height: 160%;
}

.source {
	margin-bottom: 1em;
}

.code pre {
	background-color: #ffe;
	margin: 0.5em 0;
	padding: 0.5em;
	line-height: 125%;
	border: 1px solid #eee;
}

.source .file {
	margin-bottom: 1em;
	font-weight: bold;
}

.traces {
	margin: 2em 0;
}

.trace {
	margin: 0.5em 0;
	padding: 0.5em;
}

.trace.app {
	border: 1px dashed #c00;
}

.trace .number {
	text-align: right;
	width: 2em;
	padding: 0.5em;
}

.trace .content {
	padding: 0.5em;
}

.trace .plus,
.trace .minus {
	display:inline;
	vertical-align:middle;
	text-align:center;
	border:1px solid #000;
	color:#000;
	font-size:10px;
	line-height:10px;
	margin:0;
	padding:0 1px;
	width:10px;
	height:10px;
}

.trace.collapsed .minus,
.trace.expanded .plus,
.trace.collapsed pre {
	display: none;
}

.trace-file {
	cursor: pointer;
	padding: 0.2em;
}

.trace-file:hover {
	background: #f0ffff;
}
/*]]>*/
</style>
</head>

<body>
<div class="container">
	<h1>Twig\Sandbox\SecurityNotAllowedMethodError</h1>

	<p class="message">
		Calling "__tostring" method on a "TemplateConfiguration" object is not allowed.	</p>

	<div class="source">
		<p class="file">/media/shnoulle/data/webdev/GITREPO/THEMES/skelvanilla_ls6/views/subviews/header/nav_bar.twig(98)</p>
		<div class="code"><pre><span class="ln">86</span>                         {{ include('./subviews/navigation/save_links.twig') }}
<span class="ln">87</span>                         {{ include('./subviews/navigation/clearall_links.twig') }}
<span class="ln">88</span>                         {{ include('./subviews/navigation/question_index_menu.twig') }}
<span class="ln">89</span>                         {{ include('./subviews/navigation/language_changer_top_menu.twig') }}
<span class="ln">90</span>                     &lt;/ul&gt;
<span class="ln">91</span>                 &lt;/div&gt;
<span class="ln">92</span>             {% endif %}
<span class="ln">93</span>         &lt;/div&gt;
<span class="ln">94</span>     &lt;/header&gt;
<span class="ln">95</span> {% endif %}
<span class="ln">96</span>     - {{ aSurveyInfo.aNavigator.load.show }}
<span class="ln">97</span>     - {{ aSurveyInfo.aNavigator.save.show }}
<span class="error"><span class="ln error-ln">98</span> {{ dump(aSurveyInfo) }}
</span></pre></div>	</div>

	<div class="traces">
		<h2>Stack Trace</h2>
				<table style="width:100%;">
						<tbody><tr class="trace app expanded">
			<td class="number">
				#0			</td>
			<td class="content">
				<div class="trace-file">
											<div class="plus">+</div>
						<div class="minus">–</div>
										&nbsp;/media/shnoulle/data/webdev/master/vendor/twig/twig/src/Extension/SandboxExtension.php(130): <strong>Twig\Sandbox\SecurityPolicy</strong>-&gt;<strong>checkMethodAllowed</strong>()				</div>

				<div class="code"><pre><span class="ln">125</span>             return $obj;
<span class="ln">126</span>         }
<span class="ln">127</span> 
<span class="ln">128</span>         if ($this-&gt;isSandboxed($source) &amp;&amp; \is_object($obj) &amp;&amp; method_exists($obj, '__toString')) {
<span class="ln">129</span>             try {
<span class="error"><span class="ln error-ln">130</span>                 $this-&gt;policy-&gt;checkMethodAllowed($obj, '__toString');
</span><span class="ln">131</span>             } catch (SecurityNotAllowedMethodError $e) {
<span class="ln">132</span>                 $e-&gt;setSourceContext($source);
<span class="ln">133</span>                 $e-&gt;setTemplateLine($lineno);
<span class="ln">134</span> 
<span class="ln">135</span>                 throw $e;
</pre></div>			</td>
		</tr>
						<tr class="trace app expanded">
			<td class="number">
				#1			</td>
			<td class="content">
				<div class="trace-file">
											<div class="plus">+</div>
						<div class="minus">–</div>
										&nbsp;/media/shnoulle/data/webdev/master/vendor/twig/twig/src/Extension/SandboxExtension.php(150): <strong>Twig\Extension\SandboxExtension</strong>-&gt;<strong>ensureToStringAllowed</strong>()				</div>

				<div class="code"><pre><span class="ln">145</span>             if (!$v) {
<span class="ln">146</span>                 continue;
<span class="ln">147</span>             }
<span class="ln">148</span> 
<span class="ln">149</span>             if (!\is_array($v)) {
<span class="error"><span class="ln error-ln">150</span>                 $this-&gt;ensureToStringAllowed($v, $lineno, $source);
</span><span class="ln">151</span>                 continue;
<span class="ln">152</span>             }
<span class="ln">153</span> 
<span class="ln">154</span>             if (\PHP_VERSION_ID &lt; 70400) {
<span class="ln">155</span>                 static $cookie;
</pre></div>			</td>
		</tr>
						<tr class="trace app expanded">
			<td class="number">
				#2			</td>
			<td class="content">
				<div class="trace-file">
											<div class="plus">+</div>
						<div class="minus">–</div>
										&nbsp;/media/shnoulle/data/webdev/master/vendor/twig/twig/src/Extension/SandboxExtension.php(179): <strong>Twig\Extension\SandboxExtension</strong>-&gt;<strong>ensureToStringAllowedForArray</strong>()				</div>

				<div class="code"><pre><span class="ln">174</span>                 }
<span class="ln">175</span> 
<span class="ln">176</span>                 $stack[$r-&gt;getId()] = true;
<span class="ln">177</span>             }
<span class="ln">178</span> 
<span class="error"><span class="ln error-ln">179</span>             $this-&gt;ensureToStringAllowedForArray($v, $lineno, $source, $stack);
</span><span class="ln">180</span>         }
<span class="ln">181</span>     }
<span class="ln">182</span> }
</pre></div>			</td>
		</tr>
						<tr class="trace app collapsed">
			<td class="number">
				#3			</td>
			<td class="content">
				<div class="trace-file">
											<div class="plus">+</div>
						<div class="minus">–</div>
										&nbsp;/media/shnoulle/data/webdev/master/vendor/twig/twig/src/Extension/SandboxExtension.php(123): <strong>Twig\Extension\SandboxExtension</strong>-&gt;<strong>ensureToStringAllowedForArray</strong>()				</div>

				<div class="code"><pre><span class="ln">118</span>     }
<span class="ln">119</span> 
<span class="ln">120</span>     public function ensureToStringAllowed($obj, int $lineno = -1, ?Source $source = null)
<span class="ln">121</span>     {
<span class="ln">122</span>         if (\is_array($obj)) {
<span class="error"><span class="ln error-ln">123</span>             $this-&gt;ensureToStringAllowedForArray($obj, $lineno, $source);
</span><span class="ln">124</span> 
<span class="ln">125</span>             return $obj;
<span class="ln">126</span>         }
<span class="ln">127</span> 
<span class="ln">128</span>         if ($this-&gt;isSandboxed($source) &amp;&amp; \is_object($obj) &amp;&amp; method_exists($obj, '__toString')) {
</pre></div>			</td>
		</tr>
						<tr class="trace app collapsed">
			<td class="number">
				#4			</td>
			<td class="content">
				<div class="trace-file">
											<div class="plus">+</div>
						<div class="minus">–</div>
										&nbsp;/media/shnoulle/data/webdev/master/tmp/runtime/twig_cache/44/44cccef532d83a4ac253c30b7176ab16.php(222): <strong>Twig\Extension\SandboxExtension</strong>-&gt;<strong>ensureToStringAllowed</strong>()				</div>

				<div class="code"><pre><span class="ln">217</span>         // line 97
<span class="ln">218</span>         yield $this-&gt;sandbox-&gt;ensureToStringAllowed(CoreExtension::getAttribute($this-&gt;env, $this-&gt;source, CoreExtension::getAttribute($this-&gt;env, $this-&gt;source, CoreExtension::getAttribute($this-&gt;env, $this-&gt;source, ($context["aSurveyInfo"] ?? null), "aNavigator", [], "any", false, false, true, 97), "save", [], "any", false, false, true, 97), "show", [], "any", false, false, true, 97), 97, $this-&gt;source);
<span class="ln">219</span>         yield "
<span class="ln">220</span> ";
<span class="ln">221</span>         // line 98
<span class="error"><span class="ln error-ln">222</span>         yield Twig\Extension\DebugExtension::dump($this-&gt;env, $context, ...[$this-&gt;sandbox-&gt;ensureToStringAllowed(($context["aSurveyInfo"] ?? null), 98, $this-&gt;source)]);
</span><span class="ln">223</span>         yield "
<span class="ln">224</span> ";
<span class="ln">225</span>         return; yield '';
<span class="ln">226</span>     }
<span class="ln">227</span> 
</pre></div>			</td>
		</tr>
						<tr class="trace app collapsed">
			<td class="number">
				#5			</td>
			<td class="content">
				<div class="trace-file">
											<div class="plus">+</div>
						<div class="minus">–</div>
										&nbsp;/media/shnoulle/data/webdev/master/vendor/twig/twig/src/Template.php(360): <strong>__TwigTemplate_2746f8525c547a6d2fe4fd254727116c</strong>-&gt;<strong>doDisplay</strong>()				</div>

				<div class="code"><pre><span class="ln">355</span>             }
<span class="ln">356</span> 
<span class="ln">357</span>             $level = ob_get_level();
<span class="ln">358</span>             ob_start();
<span class="ln">359</span> 
<span class="error"><span class="ln error-ln">360</span>             foreach ($this-&gt;doDisplay($context, $blocks) as $data) {
</span><span class="ln">361</span>                 if (ob_get_length()) {
<span class="ln">362</span>                     $data = ob_get_clean().$data;
<span class="ln">363</span>                     ob_start();
<span class="ln">364</span>                 }
<span class="ln">365</span> 
</pre></div>			</td>
		</tr>
						<tr class="trace app collapsed">
			<td class="number">
				#6			</td>
			<td class="content">
				<div class="trace-file">
											<div class="plus">+</div>
						<div class="minus">–</div>
										&nbsp;/media/shnoulle/data/webdev/master/vendor/twig/twig/src/Template.php(335): <strong>Twig\Template</strong>-&gt;<strong>yield</strong>()				</div>

				<div class="code"><pre><span class="ln">330</span>     }
<span class="ln">331</span> 
<span class="ln">332</span>     public function render(array $context): string
<span class="ln">333</span>     {
<span class="ln">334</span>         $content = '';
<span class="error"><span class="ln error-ln">335</span>         foreach ($this-&gt;yield($context) as $data) {
</span><span class="ln">336</span>             $content .= $data;
<span class="ln">337</span>         }
<span class="ln">338</span> 
<span class="ln">339</span>         return $content;
<span class="ln">340</span>     }
</pre></div>			</td>
		</tr>
						<tr class="trace app collapsed">
			<td class="number">
				#7			</td>
			<td class="content">
				<div class="trace-file">
											<div class="plus">+</div>
						<div class="minus">–</div>
										&nbsp;/media/shnoulle/data/webdev/master/vendor/twig/twig/src/TemplateWrapper.php(38): <strong>Twig\Template</strong>-&gt;<strong>render</strong>()				</div>

				<div class="code"><pre><span class="ln">33</span>         $this-&gt;template = $template;
<span class="ln">34</span>     }
<span class="ln">35</span> 
<span class="ln">36</span>     public function render(array $context = []): string
<span class="ln">37</span>     {
<span class="error"><span class="ln error-ln">38</span>         return $this-&gt;template-&gt;render($context);
</span><span class="ln">39</span>     }
<span class="ln">40</span> 
<span class="ln">41</span>     public function display(array $context = [])
<span class="ln">42</span>     {
<span class="ln">43</span>         // using func_get_args() allows to not expose the blocks argument
</pre></div>			</td>
		</tr>
						<tr class="trace app collapsed">
			<td class="number">
				#8			</td>
			<td class="content">
				<div class="trace-file">
											<div class="plus">+</div>
						<div class="minus">–</div>
										&nbsp;/media/shnoulle/data/webdev/master/vendor/twig/twig/src/Extension/CoreExtension.php(1435): <strong>Twig\TemplateWrapper</strong>-&gt;<strong>render</strong>()				</div>

				<div class="code"><pre><span class="ln">1430</span> 
<span class="ln">1431</span>             if ($isSandboxed &amp;&amp; $loaded) {
<span class="ln">1432</span>                 $loaded-&gt;unwrap()-&gt;checkSecurity();
<span class="ln">1433</span>             }
<span class="ln">1434</span> 
<span class="error"><span class="ln error-ln">1435</span>             return $loaded ? $loaded-&gt;render($variables) : '';
</span><span class="ln">1436</span>         } finally {
<span class="ln">1437</span>             if ($isSandboxed &amp;&amp; !$alreadySandboxed) {
<span class="ln">1438</span>                 $sandbox-&gt;disableSandbox();
<span class="ln">1439</span>             }
<span class="ln">1440</span>         }
</pre></div>			</td>
		</tr>
						<tr class="trace app collapsed">
			<td class="number">
				#9			</td>
			<td class="content">
				<div class="trace-file">
											<div class="plus">+</div>
						<div class="minus">–</div>
										&nbsp;/media/shnoulle/data/webdev/master/tmp/runtime/twig_cache/10/10c3967c6b6a85afc070929e0e201fbc.php(167): <strong>Twig\Extension\CoreExtension</strong>::<strong>include</strong>()				</div>

				<div class="code"><pre><span class="ln">162</span>     public function block_nav_bar($context, array $blocks = [])
<span class="ln">163</span>     {
<span class="ln">164</span>         $macros = $this-&gt;macros;
<span class="ln">165</span>         // line 21
<span class="ln">166</span>         yield "            ";
<span class="error"><span class="ln error-ln">167</span>         yield Twig\Extension\CoreExtension::include($this-&gt;env, $context, "./subviews/header/nav_bar.twig");
</span><span class="ln">168</span>         yield "
<span class="ln">169</span>           ";
<span class="ln">170</span>         return; yield '';
<span class="ln">171</span>     }
<span class="ln">172</span> 
</pre></div>			</td>
		</tr>
						<tr class="trace app collapsed">
			<td class="number">
				#10			</td>
			<td class="content">
				<div class="trace-file">
											<div class="plus">+</div>
						<div class="minus">–</div>
										&nbsp;/media/shnoulle/data/webdev/master/vendor/twig/twig/src/Template.php(430): <strong>__TwigTemplate_943c3104ad1ec2a16017eb5a65ef5eee</strong>-&gt;<strong>block_nav_bar</strong>()				</div>

				<div class="code"><pre><span class="ln">425</span>                 }
<span class="ln">426</span> 
<span class="ln">427</span>                 $level = ob_get_level();
<span class="ln">428</span>                 ob_start();
<span class="ln">429</span> 
<span class="error"><span class="ln error-ln">430</span>                 foreach ($template-&gt;$block($context, $blocks) as $data) {
</span><span class="ln">431</span>                     if (ob_get_length()) {
<span class="ln">432</span>                         $data = ob_get_clean().$data;
<span class="ln">433</span>                         ob_start();
<span class="ln">434</span>                     }
<span class="ln">435</span> 
</pre></div>			</td>
		</tr>
						<tr class="trace app collapsed">
			<td class="number">
				#11			</td>
			<td class="content">
				<div class="trace-file">
											<div class="plus">+</div>
						<div class="minus">–</div>
										&nbsp;/media/shnoulle/data/webdev/master/tmp/runtime/twig_cache/10/10c3967c6b6a85afc070929e0e201fbc.php(147): <strong>Twig\Template</strong>-&gt;<strong>yieldBlock</strong>()				</div>

				<div class="code"><pre><span class="ln">142</span>         $macros = $this-&gt;macros;
<span class="ln">143</span>         // line 19
<span class="ln">144</span>         yield "          ";
<span class="ln">145</span>         // line 20
<span class="ln">146</span>         yield "          ";
<span class="error"><span class="ln error-ln">147</span>         yield from $this-&gt;unwrap()-&gt;yieldBlock('nav_bar', $context, $blocks);
</span><span class="ln">148</span>         // line 23
<span class="ln">149</span>         yield "          ";
<span class="ln">150</span>         yield from $this-&gt;unwrap()-&gt;yieldBlock('description', $context, $blocks);
<span class="ln">151</span>         // line 25
<span class="ln">152</span>         yield "          &lt;!-- Outer Frame Container --&gt;
</pre></div>			</td>
		</tr>
						<tr class="trace app collapsed">
			<td class="number">
				#12			</td>
			<td class="content">
				<div class="trace-file">
											<div class="plus">+</div>
						<div class="minus">–</div>
										&nbsp;/media/shnoulle/data/webdev/master/vendor/twig/twig/src/Template.php(430): <strong>__TwigTemplate_943c3104ad1ec2a16017eb5a65ef5eee</strong>-&gt;<strong>block_body</strong>()				</div>

				<div class="code"><pre><span class="ln">425</span>                 }
<span class="ln">426</span> 
<span class="ln">427</span>                 $level = ob_get_level();
<span class="ln">428</span>                 ob_start();
<span class="ln">429</span> 
<span class="error"><span class="ln error-ln">430</span>                 foreach ($template-&gt;$block($context, $blocks) as $data) {
</span><span class="ln">431</span>                     if (ob_get_length()) {
<span class="ln">432</span>                         $data = ob_get_clean().$data;
<span class="ln">433</span>                         ob_start();
<span class="ln">434</span>                     }
<span class="ln">435</span> 
</pre></div>			</td>
		</tr>
						<tr class="trace app collapsed">
			<td class="number">
				#13			</td>
			<td class="content">
				<div class="trace-file">
											<div class="plus">+</div>
						<div class="minus">–</div>
										&nbsp;/media/shnoulle/data/webdev/master/tmp/runtime/twig_cache/10/10c3967c6b6a85afc070929e0e201fbc.php(105): <strong>Twig\Template</strong>-&gt;<strong>yieldBlock</strong>()				</div>

				<div class="code"><pre><span class="ln">100</span>         // line 17
<span class="ln">101</span>         yield $this-&gt;sandbox-&gt;ensureToStringAllowed(CoreExtension::getAttribute($this-&gt;env, $this-&gt;source, CoreExtension::getAttribute($this-&gt;env, $this-&gt;source, ($context["aSurveyInfo"] ?? null), "id", [], "any", false, false, true, 17), "dynamicreload", [], "any", false, false, true, 17), 17, $this-&gt;source);
<span class="ln">102</span>         yield "\"&gt;
<span class="ln">103</span>         ";
<span class="ln">104</span>         // line 18
<span class="error"><span class="ln error-ln">105</span>         yield from $this-&gt;unwrap()-&gt;yieldBlock('body', $context, $blocks);
</span><span class="ln">106</span>         // line 33
<span class="ln">107</span>         yield "      &lt;/div&gt;
<span class="ln">108</span>     ";
<span class="ln">109</span>         // line 34
<span class="ln">110</span>         yield from $this-&gt;unwrap()-&gt;yieldBlock('footer', $context, $blocks);
</pre></div>			</td>
		</tr>
						<tr class="trace app collapsed">
			<td class="number">
				#14			</td>
			<td class="content">
				<div class="trace-file">
											<div class="plus">+</div>
						<div class="minus">–</div>
										&nbsp;/media/shnoulle/data/webdev/master/vendor/twig/twig/src/Template.php(360): <strong>__TwigTemplate_943c3104ad1ec2a16017eb5a65ef5eee</strong>-&gt;<strong>doDisplay</strong>()				</div>

				<div class="code"><pre><span class="ln">355</span>             }
<span class="ln">356</span> 
<span class="ln">357</span>             $level = ob_get_level();
<span class="ln">358</span>             ob_start();
<span class="ln">359</span> 
<span class="error"><span class="ln error-ln">360</span>             foreach ($this-&gt;doDisplay($context, $blocks) as $data) {
</span><span class="ln">361</span>                 if (ob_get_length()) {
<span class="ln">362</span>                     $data = ob_get_clean().$data;
<span class="ln">363</span>                     ob_start();
<span class="ln">364</span>                 }
<span class="ln">365</span> 
</pre></div>			</td>
		</tr>
						<tr class="trace app collapsed">
			<td class="number">
				#15			</td>
			<td class="content">
				<div class="trace-file">
											<div class="plus">+</div>
						<div class="minus">–</div>
										&nbsp;/media/shnoulle/data/webdev/master/vendor/twig/twig/src/Template.php(335): <strong>Twig\Template</strong>-&gt;<strong>yield</strong>()				</div>

				<div class="code"><pre><span class="ln">330</span>     }
<span class="ln">331</span> 
<span class="ln">332</span>     public function render(array $context): string
<span class="ln">333</span>     {
<span class="ln">334</span>         $content = '';
<span class="error"><span class="ln error-ln">335</span>         foreach ($this-&gt;yield($context) as $data) {
</span><span class="ln">336</span>             $content .= $data;
<span class="ln">337</span>         }
<span class="ln">338</span> 
<span class="ln">339</span>         return $content;
<span class="ln">340</span>     }
</pre></div>			</td>
		</tr>
						<tr class="trace app collapsed">
			<td class="number">
				#16			</td>
			<td class="content">
				<div class="trace-file">
											<div class="plus">+</div>
						<div class="minus">–</div>
										&nbsp;/media/shnoulle/data/webdev/master/vendor/twig/twig/src/TemplateWrapper.php(38): <strong>Twig\Template</strong>-&gt;<strong>render</strong>()				</div>

				<div class="code"><pre><span class="ln">33</span>         $this-&gt;template = $template;
<span class="ln">34</span>     }
<span class="ln">35</span> 
<span class="ln">36</span>     public function render(array $context = []): string
<span class="ln">37</span>     {
<span class="error"><span class="ln error-ln">38</span>         return $this-&gt;template-&gt;render($context);
</span><span class="ln">39</span>     }
<span class="ln">40</span> 
<span class="ln">41</span>     public function display(array $context = [])
<span class="ln">42</span>     {
<span class="ln">43</span>         // using func_get_args() allows to not expose the blocks argument
</pre></div>			</td>
		</tr>
						<tr class="trace app collapsed">
			<td class="number">
				#17			</td>
			<td class="content">
				<div class="trace-file">
											<div class="plus">+</div>
						<div class="minus">–</div>
										&nbsp;/media/shnoulle/data/webdev/master/application/core/LSETwigViewRenderer.php(519): <strong>Twig\TemplateWrapper</strong>-&gt;<strong>render</strong>()				</div>

				<div class="code"><pre><span class="ln">514</span>             list($sString, $aData) = $this-&gt;getPluginsData($sString, $aData);
<span class="ln">515</span>         }
<span class="ln">516</span> 
<span class="ln">517</span>         // Twig rendering
<span class="ln">518</span>         $oTwigTemplate = $twig-&gt;createTemplate($sString);
<span class="error"><span class="ln error-ln">519</span>         $sHtml         = $oTwigTemplate-&gt;render($aData, false);
</span><span class="ln">520</span> 
<span class="ln">521</span>         return $sHtml;
<span class="ln">522</span>     }
<span class="ln">523</span> 
<span class="ln">524</span>     /**
</pre></div>			</td>
		</tr>
						<tr class="trace app collapsed">
			<td class="number">
				#18			</td>
			<td class="content">
				<div class="trace-file">
											<div class="plus">+</div>
						<div class="minus">–</div>
										&nbsp;/media/shnoulle/data/webdev/master/application/core/LSETwigViewRenderer.php(72): <strong>LSETwigViewRenderer</strong>-&gt;<strong>convertTwigToHtml</strong>()				</div>

				<div class="code"><pre><span class="ln">67</span>     {
<span class="ln">68</span>         $oTemplate = Template::getLastInstance();
<span class="ln">69</span>         $oLayoutTemplate = $this-&gt;getTemplateForView($sLayout, $oTemplate);
<span class="ln">70</span>         if ($oLayoutTemplate) {
<span class="ln">71</span>             $line       = file_get_contents($oLayoutTemplate-&gt;viewPath . $sLayout);
<span class="error"><span class="ln error-ln">72</span>             $sHtml      = $this-&gt;convertTwigToHtml($line, $aData, $oTemplate);
</span><span class="ln">73</span>             $sEmHiddenInputs = LimeExpressionManager::FinishProcessPublicPage(true);
<span class="ln">74</span>             if ($sEmHiddenInputs) {
<span class="ln">75</span>                 $sHtml = str_replace(
<span class="ln">76</span>                     "&lt;!-- emScriptsAndHiddenInputs --&gt;",
<span class="ln">77</span>                     "&lt;!-- emScriptsAndHiddenInputs updated --&gt;\n" .
</pre></div>			</td>
		</tr>
						<tr class="trace app collapsed">
			<td class="number">
				#19			</td>
			<td class="content">
				<div class="trace-file">
											<div class="plus">+</div>
						<div class="minus">–</div>
										&nbsp;/media/shnoulle/data/webdev/master/application/helpers/frontend_helper.php(1903): <strong>LSETwigViewRenderer</strong>-&gt;<strong>renderTemplateFromFile</strong>()				</div>

				<div class="code"><pre><span class="ln">1898</span>     $thissurvey['surveyUrl'] = Yii::app()-&gt;getController()-&gt;createUrl("survey/index", array("sid" =&gt; $surveyid)); // For form action (will remove newtest)
<span class="ln">1899</span>     $thissurvey['attr']['welcomecontainer'] = $thissurvey['attr']['surveyname'] = $thissurvey['attr']['description'] = $thissurvey['attr']['welcome'] = $thissurvey['attr']['questioncount'] = '';
<span class="ln">1900</span> 
<span class="ln">1901</span>     $thissurvey['include_content'] = 'firstpage';
<span class="ln">1902</span> 
<span class="error"><span class="ln error-ln">1903</span>     Yii::app()-&gt;twigRenderer-&gt;renderTemplateFromFile("layout_global.twig", array('oSurvey' =&gt; Survey::model()-&gt;findByPk($surveyid), 'aSurveyInfo' =&gt; $thissurvey), false);
</span><span class="ln">1904</span> }
<span class="ln">1905</span> 
<span class="ln">1906</span> /**
<span class="ln">1907</span> * killSurveySession : reset $_SESSION part for the survey
<span class="ln">1908</span> * @param int $iSurveyID
</pre></div>			</td>
		</tr>
						<tr class="trace app collapsed">
			<td class="number">
				#20			</td>
			<td class="content">
				<div class="trace-file">
											<div class="plus">+</div>
						<div class="minus">–</div>
										&nbsp;/media/shnoulle/data/webdev/master/application/helpers/SurveyRuntimeHelper.php(1094): <strong>display_first_page</strong>()				</div>

				<div class="code"><pre><span class="ln">1089</span>             $this-&gt;aSurveyInfo['datasecurity_notice_label'] = Survey::replacePolicyLink($this-&gt;aSurveyInfo['datasecurity_notice_label'], $this-&gt;aSurveyInfo['sid']);
<span class="ln">1090</span>         }
<span class="ln">1091</span> 
<span class="ln">1092</span>         if ($bDisplayFirstPage) {
<span class="ln">1093</span>             $_SESSION[$this-&gt;LEMsessid]['test'] = time();
<span class="error"><span class="ln error-ln">1094</span>             display_first_page($this-&gt;thissurvey, $this-&gt;aSurveyInfo);
</span><span class="ln">1095</span>             Yii::app()-&gt;end(); // So we can still see debug messages
<span class="ln">1096</span>         }
<span class="ln">1097</span>     }
<span class="ln">1098</span> 
<span class="ln">1099</span>     private function checkForDataSecurityAccepted()
</pre></div>			</td>
		</tr>
						<tr class="trace app collapsed">
			<td class="number">
				#21			</td>
			<td class="content">
				<div class="trace-file">
											<div class="plus">+</div>
						<div class="minus">–</div>
										&nbsp;/media/shnoulle/data/webdev/master/application/helpers/SurveyRuntimeHelper.php(213): <strong>SurveyRuntimeHelper</strong>-&gt;<strong>displayFirstPageIfNeeded</strong>()				</div>

				<div class="code"><pre><span class="ln">208</span>             $this-&gt;checkForDataSecurityAccepted(); // must be called after initMove to allow LEM to be initialized
<span class="ln">209</span>             if (EmCacheHelper::useCache()) {
<span class="ln">210</span>                 $this-&gt;aSurveyInfo['emcache'] = true;
<span class="ln">211</span>             }
<span class="ln">212</span>             $this-&gt;checkQuotas(); // check quotas (then the process will stop here)
<span class="error"><span class="ln error-ln">213</span>             $this-&gt;displayFirstPageIfNeeded();
</span><span class="ln">214</span>             $this-&gt;saveAllIfNeeded();
<span class="ln">215</span>             $this-&gt;saveSubmitIfNeeded();
<span class="ln">216</span>             // TODO: move somewhere else
<span class="ln">217</span>             $this-&gt;setNotAnsweredAndNotValidated();
<span class="ln">218</span>         } else {
</pre></div>			</td>
		</tr>
						<tr class="trace app collapsed">
			<td class="number">
				#22			</td>
			<td class="content">
				<div class="trace-file">
											<div class="plus">+</div>
						<div class="minus">–</div>
										&nbsp;/media/shnoulle/data/webdev/master/application/controllers/survey/SurveyIndex.php(662): <strong>SurveyRuntimeHelper</strong>-&gt;<strong>run</strong>()				</div>

				<div class="code"><pre><span class="ln">657</span>         unset($redata);
<span class="ln">658</span>         $redata = compact(array_keys(get_defined_vars()));
<span class="ln">659</span>         Yii::import('application.helpers.SurveyRuntimeHelper');
<span class="ln">660</span>         $tmp = new SurveyRuntimeHelper();
<span class="ln">661</span>         // try {
<span class="error"><span class="ln error-ln">662</span>             $tmp-&gt;run($surveyid, $redata);
</span><span class="ln">663</span>         // } catch (WrongTemplateVersionException $ex) {
<span class="ln">664</span>         //     echo $ex-&gt;getMessage();
<span class="ln">665</span>         // }
<span class="ln">666</span>     }
<span class="ln">667</span> 
</pre></div>			</td>
		</tr>
						<tr class="trace app collapsed">
			<td class="number">
				#23			</td>
			<td class="content">
				<div class="trace-file">
											<div class="plus">+</div>
						<div class="minus">–</div>
										&nbsp;/media/shnoulle/data/webdev/master/application/controllers/survey/SurveyIndex.php(22): <strong>SurveyIndex</strong>-&gt;<strong>action</strong>()				</div>

				<div class="code"><pre><span class="ln">17</span>     public $oTemplate;
<span class="ln">18</span> 
<span class="ln">19</span>     public function run()
<span class="ln">20</span>     {
<span class="ln">21</span>         useFirebug();
<span class="error"><span class="ln error-ln">22</span>         $this-&gt;action();
</span><span class="ln">23</span>     }
<span class="ln">24</span> 
<span class="ln">25</span>     /**
<span class="ln">26</span>      *
<span class="ln">27</span>      * todo: this function is toooo long, to many things happening here. Should be refactored asap!
</pre></div>			</td>
		</tr>
						<tr class="trace core collapsed">
			<td class="number">
				#24			</td>
			<td class="content">
				<div class="trace-file">
											<div class="plus">+</div>
						<div class="minus">–</div>
										&nbsp;/media/shnoulle/data/webdev/master/vendor/yiisoft/yii/framework/web/actions/CAction.php(76): <strong>SurveyIndex</strong>-&gt;<strong>run</strong>()				</div>

				<div class="code"><pre><span class="ln">71</span>     {
<span class="ln">72</span>         $method=new ReflectionMethod($this, 'run');
<span class="ln">73</span>         if($method-&gt;getNumberOfParameters()&gt;0)
<span class="ln">74</span>             return $this-&gt;runWithParamsInternal($this, $method, $params);
<span class="ln">75</span> 
<span class="error"><span class="ln error-ln">76</span>         $this-&gt;run();
</span><span class="ln">77</span>         return true;
<span class="ln">78</span>     }
<span class="ln">79</span> 
<span class="ln">80</span>     /**
<span class="ln">81</span>      * Executes a method of an object with the supplied named parameters.
</pre></div>			</td>
		</tr>
						<tr class="trace core collapsed">
			<td class="number">
				#25			</td>
			<td class="content">
				<div class="trace-file">
											<div class="plus">+</div>
						<div class="minus">–</div>
										&nbsp;/media/shnoulle/data/webdev/master/vendor/yiisoft/yii/framework/web/CController.php(308): <strong>CAction</strong>-&gt;<strong>runWithParams</strong>()				</div>

				<div class="code"><pre><span class="ln">303</span>     {
<span class="ln">304</span>         $priorAction=$this-&gt;_action;
<span class="ln">305</span>         $this-&gt;_action=$action;
<span class="ln">306</span>         if($this-&gt;beforeAction($action))
<span class="ln">307</span>         {
<span class="error"><span class="ln error-ln">308</span>             if($action-&gt;runWithParams($this-&gt;getActionParams())===false)
</span><span class="ln">309</span>                 $this-&gt;invalidActionParams($action);
<span class="ln">310</span>             else
<span class="ln">311</span>                 $this-&gt;afterAction($action);
<span class="ln">312</span>         }
<span class="ln">313</span>         $this-&gt;_action=$priorAction;
</pre></div>			</td>
		</tr>
						<tr class="trace core collapsed">
			<td class="number">
				#26			</td>
			<td class="content">
				<div class="trace-file">
											<div class="plus">+</div>
						<div class="minus">–</div>
										&nbsp;/media/shnoulle/data/webdev/master/vendor/yiisoft/yii/framework/web/CController.php(286): <strong>CController</strong>-&gt;<strong>runAction</strong>()				</div>

				<div class="code"><pre><span class="ln">281</span>      * @see runAction
<span class="ln">282</span>      */
<span class="ln">283</span>     public function runActionWithFilters($action,$filters)
<span class="ln">284</span>     {
<span class="ln">285</span>         if(empty($filters))
<span class="error"><span class="ln error-ln">286</span>             $this-&gt;runAction($action);
</span><span class="ln">287</span>         else
<span class="ln">288</span>         {
<span class="ln">289</span>             $priorAction=$this-&gt;_action;
<span class="ln">290</span>             $this-&gt;_action=$action;
<span class="ln">291</span>             CFilterChain::create($this,$action,$filters)-&gt;run();
</pre></div>			</td>
		</tr>
						<tr class="trace core collapsed">
			<td class="number">
				#27			</td>
			<td class="content">
				<div class="trace-file">
											<div class="plus">+</div>
						<div class="minus">–</div>
										&nbsp;/media/shnoulle/data/webdev/master/vendor/yiisoft/yii/framework/web/CController.php(265): <strong>CController</strong>-&gt;<strong>runActionWithFilters</strong>()				</div>

				<div class="code"><pre><span class="ln">260</span>         {
<span class="ln">261</span>             if(($parent=$this-&gt;getModule())===null)
<span class="ln">262</span>                 $parent=Yii::app();
<span class="ln">263</span>             if($parent-&gt;beforeControllerAction($this,$action))
<span class="ln">264</span>             {
<span class="error"><span class="ln error-ln">265</span>                 $this-&gt;runActionWithFilters($action,$this-&gt;filters());
</span><span class="ln">266</span>                 $parent-&gt;afterControllerAction($this,$action);
<span class="ln">267</span>             }
<span class="ln">268</span>         }
<span class="ln">269</span>         else
<span class="ln">270</span>             $this-&gt;missingAction($actionID);
</pre></div>			</td>
		</tr>
						<tr class="trace core collapsed">
			<td class="number">
				#28			</td>
			<td class="content">
				<div class="trace-file">
											<div class="plus">+</div>
						<div class="minus">–</div>
										&nbsp;/media/shnoulle/data/webdev/master/vendor/yiisoft/yii/framework/web/CWebApplication.php(282): <strong>CController</strong>-&gt;<strong>run</strong>()				</div>

				<div class="code"><pre><span class="ln">277</span>         {
<span class="ln">278</span>             list($controller,$actionID)=$ca;
<span class="ln">279</span>             $oldController=$this-&gt;_controller;
<span class="ln">280</span>             $this-&gt;_controller=$controller;
<span class="ln">281</span>             $controller-&gt;init();
<span class="error"><span class="ln error-ln">282</span>             $controller-&gt;run($actionID);
</span><span class="ln">283</span>             $this-&gt;_controller=$oldController;
<span class="ln">284</span>         }
<span class="ln">285</span>         else
<span class="ln">286</span>             throw new CHttpException(404,Yii::t('yii','Unable to resolve the request "{route}".',
<span class="ln">287</span>                 array('{route}'=&gt;$route===''?$this-&gt;defaultController:$route)));
</pre></div>			</td>
		</tr>
						<tr class="trace core collapsed">
			<td class="number">
				#29			</td>
			<td class="content">
				<div class="trace-file">
											<div class="plus">+</div>
						<div class="minus">–</div>
										&nbsp;/media/shnoulle/data/webdev/master/vendor/yiisoft/yii/framework/web/CWebApplication.php(141): <strong>CWebApplication</strong>-&gt;<strong>runController</strong>()				</div>

				<div class="code"><pre><span class="ln">136</span>             foreach(array_splice($this-&gt;catchAllRequest,1) as $name=&gt;$value)
<span class="ln">137</span>                 $_GET[$name]=$value;
<span class="ln">138</span>         }
<span class="ln">139</span>         else
<span class="ln">140</span>             $route=$this-&gt;getUrlManager()-&gt;parseUrl($this-&gt;getRequest());
<span class="error"><span class="ln error-ln">141</span>         $this-&gt;runController($route);
</span><span class="ln">142</span>     }
<span class="ln">143</span> 
<span class="ln">144</span>     /**
<span class="ln">145</span>      * Registers the core application components.
<span class="ln">146</span>      * This method overrides the parent implementation by registering additional core components.
</pre></div>			</td>
		</tr>
						<tr class="trace core collapsed">
			<td class="number">
				#30			</td>
			<td class="content">
				<div class="trace-file">
											<div class="plus">+</div>
						<div class="minus">–</div>
										&nbsp;/media/shnoulle/data/webdev/master/vendor/yiisoft/yii/framework/base/CApplication.php(185): <strong>CWebApplication</strong>-&gt;<strong>processRequest</strong>()				</div>

				<div class="code"><pre><span class="ln">180</span>     public function run()
<span class="ln">181</span>     {
<span class="ln">182</span>         if($this-&gt;hasEventHandler('onBeginRequest'))
<span class="ln">183</span>             $this-&gt;onBeginRequest(new CEvent($this));
<span class="ln">184</span>         register_shutdown_function(array($this,'end'),0,false);
<span class="error"><span class="ln error-ln">185</span>         $this-&gt;processRequest();
</span><span class="ln">186</span>         if($this-&gt;hasEventHandler('onEndRequest'))
<span class="ln">187</span>             $this-&gt;onEndRequest(new CEvent($this));
<span class="ln">188</span>     }
<span class="ln">189</span> 
<span class="ln">190</span>     /**
</pre></div>			</td>
		</tr>
						<tr class="trace app collapsed">
			<td class="number">
				#31			</td>
			<td class="content">
				<div class="trace-file">
											<div class="plus">+</div>
						<div class="minus">–</div>
										&nbsp;/media/shnoulle/data/webdev/master/index.php(161): <strong>CApplication</strong>-&gt;<strong>run</strong>()				</div>

				<div class="code"><pre><span class="ln">156</span> require_once APPPATH . 'core/LSYii_Application' . EXT;
<span class="ln">157</span> 
<span class="ln">158</span> $config = require_once(APPPATH . 'config/internal' . EXT);
<span class="ln">159</span> 
<span class="ln">160</span> Yii::$enableIncludePath = false;
<span class="error"><span class="ln error-ln">161</span> Yii::createApplication('LSYii_Application', $config)-&gt;run();
</span><span class="ln">162</span> 
<span class="ln">163</span> /* End of file index.php */
<span class="ln">164</span> /* Location: ./index.php */
</pre></div>			</td>
		</tr>
				</tbody></table>
	</div>

	<div class="version">
		2025-02-04 07:39:15 nginx/1.22.1 <a href="https://www.yiiframework.com/">Yii Framework</a>/1.1.30	</div>
</div>

<script type="text/javascript">
/*<![CDATA[*/
var traceReg = new RegExp("(^|\\s)trace-file(\\s|$)");
var collapsedReg = new RegExp("(^|\\s)collapsed(\\s|$)");

var e = document.getElementsByTagName("div");
for(var j=0,len=e.length;j<len;j++){
	if(traceReg.test(e[j].className)){
		e[j].onclick = function(){
			var trace = this.parentNode.parentNode;
			if(collapsedReg.test(trace.className))
				trace.className = trace.className.replace("collapsed", "expanded");
			else
				trace.className = trace.className.replace("expanded", "collapsed");
		}
	}
}
/*]]>*/
</script>



</body></html>

Issue History

Date Modified Username Field Change
2025-02-04 08:45 DenisChenu New Issue
2025-02-04 08:45 DenisChenu File Added: dump_vanilla.zip
2025-02-04 08:45 DenisChenu Note Added: 81966
2025-02-04 08:45 DenisChenu File Added: Twig_Sandbox_SecurityNotAllowedMethodError.html
2025-02-04 08:45 DenisChenu Bug heat 0 => 2
2025-02-04 08:46 DenisChenu Relationship added related to 19894