Commit 70fcae74 authored by Andreas Jung's avatar Andreas Jung

- reStructuredText/ZReST: setting raw_enabled to 0 for security

        reasons
parent 8e67e9ae
......@@ -18,6 +18,9 @@ Zope Changes
Bugs fixed
- reStructuredText/ZReST: setting raw_enabled to 0 for security
reasons
- Collector #2113: 'zopectl test' often masked Ctrl-C.
- OFS Application: Updated deprecation warnings.
......
......@@ -210,6 +210,9 @@ class ZReST(Item, PropertyManager, Historical, Implicit, Persistent):
# disallow use of the .. include directive for security reasons
pub.settings.file_insertion_enabled = 0
# disallow insertion of raw data through for security reasons
pub.settings.raw_enabled = 0
# don't break if we get errors
pub.settings.halt_level = 6
......
......@@ -72,6 +72,7 @@ def render(src,
settings['output_encoding'] = output_encoding
settings['stylesheet'] = stylesheet
settings['file_insertion_enabled'] = 0
settings['raw_enabled'] = 0
if language_code:
settings['language_code'] = language_code
settings['language_code'] = language_code
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment