On Monday, September 1, 2008 at 9:14:19 AM UTC-7, Noah Kantrowitz wrote: > > Richard Liao wrote: > > I searched days ago, and think we need do something to this problem, > > because this can be a serious security problem in some circumstances. > > Think of that someone trigger this function by adding a very long > > template, the server will die siliently. > > > > Don't throw around the term "security issue" unless you can back it up. > This is at worst an annoyance, however I don't know of any way to > exploit it remotely or do anything worse than DoS the server should the > admin leave a broken page up. > > This is also not a Trac issue, it is a design problem in Genshi. The > simple solution is stop nesting filters so deeply. > > --Noah >
After reading the comments here and in (1), with my limited knowledge of Genshi I implemented a workaround for the same issue in (2). I'm interested to know if anyone has an idea of a better way to append a column to a long table using Genshi. I might just switch to a JavaScript implementation. (1) https://groups.google.com/d/msg/genshi/foqJpReEcUo/VOvd-_cibLIJ (2) https://trac-hacks.org/ticket/12198#comment:3 -- You received this message because you are subscribed to the Google Groups "Trac Development" group. To unsubscribe from this group and stop receiving emails from it, send an email to trac-dev+unsubscr...@googlegroups.com. To post to this group, send email to trac-dev@googlegroups.com. Visit this group at http://groups.google.com/group/trac-dev. For more options, visit https://groups.google.com/d/optout.