Commit cf4279c7 authored by Andreas Jung's avatar Andreas Jung

disabled the reST .. include directive

parent 59a2fae2
...@@ -192,6 +192,9 @@ class ZReST(Item, PropertyManager, Historical, Implicit, Persistent): ...@@ -192,6 +192,9 @@ class ZReST(Item, PropertyManager, Historical, Implicit, Persistent):
# set the reporting level to something sane # set the reporting level to something sane
pub.settings.report_level = int(self.report_level) pub.settings.report_level = int(self.report_level)
# disallow use of the .. include directive for security reasons
pub.settings.file_insertion_enabled = 0
# don't break if we get errors # don't break if we get errors
pub.settings.halt_level = 6 pub.settings.halt_level = 6
......
...@@ -74,6 +74,7 @@ def render(src, ...@@ -74,6 +74,7 @@ def render(src,
if language_code: if language_code:
settings['language_code'] = language_code settings['language_code'] = language_code
settings['language_code'] = language_code settings['language_code'] = language_code
settings['file_insertion_enabled '] = 0
# starting level for <H> elements: # starting level for <H> elements:
settings['initial_header_level'] = initial_header_level + 1 settings['initial_header_level'] = initial_header_level + 1
# set the reporting level to something sane: # set the reporting level to something sane:
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment