On Sat, Oct 27, 2018 at 2:55 PM Edward K. Ream <[email protected]> wrote:

Only myLeoSettings.leo or leoSettings.leo can be allowed to enable settings
> that could cause code to be executed automatically.
>
...

> @data abbreviations-subst-env defines executable python code as the
> environment for abbreviations.
> This setting is useful but it could be lethal in the hands of a hacker.  *Leo
> must protect this setting!*
>

Done at rev b32fd6 of devel.  I know of no other settings that pose a
security risk.  Please report any that you find.

Edward

-- 
You received this message because you are subscribed to the Google Groups 
"leo-editor" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send email to [email protected].
Visit this group at https://groups.google.com/group/leo-editor.
For more options, visit https://groups.google.com/d/optout.

Reply via email to