From 802be941044a1ba3caa8dc3cea9e8932472c3a02 Mon Sep 17 00:00:00 2001 From: intrigeri Date: Thu, 6 Nov 2008 14:17:33 +0100 Subject: po: use prep_writefile before creating any files in refreshpot and refreshpo Signed-off-by: intrigeri --- doc/plugins/po.mdwn | 6 ------ 1 file changed, 6 deletions(-) (limited to 'doc/plugins') diff --git a/doc/plugins/po.mdwn b/doc/plugins/po.mdwn index dddb46fc8..c9d5b664e 100644 --- a/doc/plugins/po.mdwn +++ b/doc/plugins/po.mdwn @@ -219,12 +219,6 @@ Security checks thoroughly to prevent any security issue (command injection, etc.). > Always pass `system()` a list of parameters to avoid the shell. > I've checked in a change fixing that. --[[Joey]] -- `refreshpofiles` and `refreshpot` create new files; this may need - some checks, e.g. using `IkiWiki::prep_writefile()` - > Yes, it would be ideal to call `prep_writefile` on each file - > that they write, beforehand. This way you'd avoid symlink attacks etc to the - > generated po/pot files. I haven't done it, but it seems pretty trivial. - > --[[Joey]] - Can any sort of directives be put in po files that will cause mischief (ie, include other files, run commands, crash gettext, whatever). -- cgit v1.2.3