Franco Bagnoli wrote:
> I'm working on a related tool (a wiki site), and I think that there should 
> be a collective effort in enucleating the security weakness of the TT 
> system (thanks Randal).

Yes, that's a good idea.  TT2 is just way too open to consider doing
this without a full and thorough security review, and even then I think
there's a good chance you'll miss something until too late.

Better to wait until TT3 when it will be possible to only enable the 
features that you want, making it much easier to create a safe subset
of the TT language, plugins, filters, and so on.

But in the mean time, it would be an excellent idea to identify those
features that could cause problems.

A


_______________________________________________
templates mailing list
[EMAIL PROTECTED]
http://lists.template-toolkit.org/mailman/listinfo/templates

Reply via email to