Re: User-defined templates - are they safe? Is FreeMarker a secure sandbox?

Attila Szegedi <[email protected]>
Newsgroups gmane.comp.web.freemarker.user
Message-ID <[email protected]>
If you use the 2.4 prerelease, you can subject templates to Java  
security policy based on their source URL - the docs in the 2.4  
distribution contain a description of how to do it.

Attila.

On 2009.01.17., at 1:51, Dobes Vandermeer wrote:

> Hello All,
>
> I'd like to use FreeMarker to allow my users to customize the layout  
> and appearance of reports and invoices.  However, I have to make  
> sure this won't negatively impact the security of my application.
>
> I'm wondering whether anyone has some ideas about whether rendering  
> user-defined freemarker templates would create a security hole.  For  
> example, can you access global classes, the class instance of  
> objects (to call getClass().getResourceAsStream(...)), or other data  
> outside the scope of the data passed as a parameter to freemarker?
>
> Has anyone done this before?  Is FreeMarker safe for this use?
>
> Thanks in advance,
> Dobes

Attila.

--
home: http://www.szegedi.org
twitter: http://twitter.com/szegedi
weblog: http://constc.blogspot.com






------------------------------------------------------------------------------
This SF.net email is sponsored by:
SourcForge Community
SourceForge wants to tell your story.
http://p.sf.net/sfu/sf-spreadtheword
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.