#4952: include tag can access files outside of allowed directories
-----------------------+----------------------------------------------------
   Reporter:  gwilson  |                Owner:  adrian         
     Status:  new      |            Component:  Template system
    Version:  SVN      |           Resolution:                 
   Keywords:           |                Stage:  Accepted       
  Has_patch:  1        |           Needs_docs:  0              
Needs_tests:  0        |   Needs_better_patch:  0              
-----------------------+----------------------------------------------------
Changes (by SmileyChris):

  * needs_tests:  1 => 0

Comment:

 Ok, I made a `safe_join` util which should work across OSes and used that
 in the `get_template_sources` functions.
 
 I added my tests to the existing `templates` regressions unit tests
 instead of creating a new test suite.
 
 No refactoring, due to Gary's investigation of `technical_500_response`.
 It's not much overhead anyway.

-- 
Ticket URL: <http://code.djangoproject.com/ticket/4952#comment:10>
Django Code <http://code.djangoproject.com/>
The web framework for perfectionists with deadlines
--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups 
"Django updates" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to [EMAIL PROTECTED]
For more options, visit this group at 
http://groups.google.com/group/django-updates?hl=en
-~----------~----~----~----~------~----~------~--~---

Reply via email to