summaryrefslogtreecommitdiff
path: root/doc/plugins
diff options
context:
space:
mode:
authorjoshtriplett <joshtriplett@0fa5a96a-9a0e-0410-b3b2-a0fd24251071>2007-04-09 09:09:02 +0000
committerjoshtriplett <joshtriplett@0fa5a96a-9a0e-0410-b3b2-a0fd24251071>2007-04-09 09:09:02 +0000
commit54a4151306458686ec1de8ba3d2adbb86a69e576 (patch)
tree61de4e00fdac9596965bcd7b3ba4dc70f68af55a /doc/plugins
parentaf388addc609a8b7993f73b980daf61fd567fe6d (diff)
* Add a graphviz plugin.
* Suggests: graphviz
Diffstat (limited to 'doc/plugins')
-rw-r--r--doc/plugins/graphviz.mdwn39
1 files changed, 39 insertions, 0 deletions
diff --git a/doc/plugins/graphviz.mdwn b/doc/plugins/graphviz.mdwn
new file mode 100644
index 000000000..c8844d0d6
--- /dev/null
+++ b/doc/plugins/graphviz.mdwn
@@ -0,0 +1,39 @@
+[[template id=plugin name=graphviz author="[[JoshTriplett]]"]]
+[[tag type/chrome type/format]]
+
+This plugin allows embedding [graphviz](http://www.graphviz.org/) graphs in a
+page. Example usage:
+
+ \[[graph src="a -> b -> c; a -> c;"]]
+
+Note that graphs will only show up in previews if your browser has
+[[wikipedia data: URI]] support, or if the same graph already exists on that
+page.
+
+Security implications: graphviz does not seem to have any syntax exploitable to
+perform file access or shell commands on the server. However, the graphviz
+plugin does make denial of service attacks somewhat easier: any user with edit
+privileges can use this plugin to create large files without the need to send
+large amounts of data, allowing them to more quickly fill the disk, run the
+server out of memory, or use up large amounts of bandwidth. Any user can
+already do these things with just the core of ikiwiki, but the graphviz plugin
+allows for an amplification attack, since users can send less data to use large
+amounts of processing time and disk usage.
+
+The `graph` directive supports the following parameters:
+
+- `src` - The graphviz source to render.
+- `type` - The type of graph to render: `graph` or `digraph`. Defaults to
+ `digraph`.
+- `prog` - The graphviz program to render with: `dot`, `neato`, `fdp`, `twopi`,
+ or `circo`. Defaults to `dot`.
+- `height`, `width` - Limit the size of the graph to a given height and width,
+ in inches. You must specify both to limit the size; otherwise, graphviz will
+ choose a size, without any limit.
+
+[[if test="enabled(graphviz)" then="""
+Some example graphs:
+
+[[graph src="a -> b -> c; a -> b;"]]
+[[graph src="a -- b -- c -- a;" prog="circo" type="graph"]]
+"""]]