From f63519ff1e8d375df30deba63156a2fc97aa9ee7 Mon Sep 17 00:00:00 2001 From: Luke Towers Date: Fri, 18 Dec 2020 12:14:18 -0600 Subject: [PATCH] Further improvements to the Twig SecurityPolicy --- modules/system/twig/SecurityPolicy.php | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/modules/system/twig/SecurityPolicy.php b/modules/system/twig/SecurityPolicy.php index aacd39ba6..b06601e8f 100644 --- a/modules/system/twig/SecurityPolicy.php +++ b/modules/system/twig/SecurityPolicy.php @@ -18,10 +18,18 @@ final class SecurityPolicy implements SecurityPolicyInterface * @var array List of forbidden methods. */ protected $blockedMethods = [ + // \October\Rain\Extension\ExtendableTrait 'addDynamicMethod', 'addDynamicProperty', + + // \October\Rain\Support\Traits\Emitter 'bindEvent', 'bindEventOnce', + + // Eloquent & Halcyon data modification + 'insert', + 'update', + 'delete', ]; /**