Twig

The flexible, fast, and secure
template engine for PHP

a Symfony Product
Docs Functions render_sandboxed
Docs for Twig version 3.x
Switch to another version: 1.x, 2.x

Questions & Feedback

License

Twig documentation is licensed under the new BSD license.

render_sandboxed

3.29

The render_sandboxed function was added in Twig 3.29.

The render_sandboxed function renders a template through a dedicated sandbox:

1
{{ render_sandboxed('newsletter.twig', {name: name}, 'html') }}

The second argument is the complete context passed to the sandboxed template. Variables from the trusted template are not included automatically.

The third argument declares the output escaping strategy. The result is considered safe only for that strategy. If it is used in a context with another escaping strategy, Twig escapes it for that context. The strategy must be a non-empty literal string other than all so Twig can determine safety when compiling the trusted template.

The output strategy does not sanitize the rendered output. Declaring html allows HTML written by an untrusted template author to reach the response. Use it only when this is intended.

The function is not available by default. Register the SandboxBridgeExtension and a lazy SandboxBridgeRuntime on the trusted environment:

1
2
3
4
5
6
7
8
9
10
use Twig\Extension\SandboxBridgeExtension;
use Twig\Runtime\SandboxBridgeRuntime;
use Twig\RuntimeLoader\FactoryRuntimeLoader;

$twig->addExtension(new SandboxBridgeExtension());
$twig->addRuntimeLoader(new FactoryRuntimeLoader([
    SandboxBridgeRuntime::class => fn () => new SandboxBridgeRuntime(
        $sandbox,
    ),
]));

Arguments

  • name: The name of the sandboxed template to render
  • context: The context passed to the sandboxed template
  • output_strategy: The escaping strategy for which the result is safe