Maybe make them a config area that must be explicitly pushed, pulled or
synced along with skins, users, etc.? (Assuming that isn't how they're
already implemented.)
On 02/13/2012 05:37 PM, Steve Bennett wrote:
On 14/02/2012, at 9:30 AM, Gé Weijers wrote:
On Mon, Feb 13, 2012 at 1:49 PM, Steve Bennett
<[email protected] <mailto:[email protected]>> wrote:
Joe Mistachkin has recently added support for calling TH1 scripts
on certain actions.
See http://www.fossil-scm.org/index.html/info/0b61e3c019
In the jimtcl branch, TH1 is replaced with Jim Tcl, so any of
these scripts has the full power of Jim Tcl, including exec.
This sounds a whole lot like mobile code. I was left wondering: would
it be enough to do a 'fossil clone <something>' to download a malware
script
onto my system? How is this capability secured?
I'm sure Joe could tell you how it is implemented, but I don't see how
it would
make any sense to clone these scripts. Aren't some settings
transferred with clone and some not?
Surely these are in the "not" group.
Cheers,
Steve
--
µWeb: Embedded Web Framework - http://uweb.workware.net.au/
WorkWare Systems Pty Ltd
W: www.workware.net.au <http://www.workware.net.au> P: +61 434
921 300
E: [email protected] <mailto:[email protected]> F: +61 7
3391 6002
_______________________________________________
fossil-users mailing list
[email protected]
http://lists.fossil-scm.org:8080/cgi-bin/mailman/listinfo/fossil-users
_______________________________________________
fossil-users mailing list
[email protected]
http://lists.fossil-scm.org:8080/cgi-bin/mailman/listinfo/fossil-users