Re: User-defined templates - are they safe? Is FreeMarker a secure sandbox?
Attila Szegedi <[email protected]>
| Newsgroups | gmane.comp.web.freemarker.user |
|---|---|
| Message-ID | <[email protected]> |
If you use the 2.4 prerelease, you can subject templates to Java security policy based on their source URL - the docs in the 2.4 distribution contain a description of how to do it. Attila. On 2009.01.17., at 1:51, Dobes Vandermeer wrote: > Hello All, > > I'd like to use FreeMarker to allow my users to customize the layout > and appearance of reports and invoices. However, I have to make > sure this won't negatively impact the security of my application. > > I'm wondering whether anyone has some ideas about whether rendering > user-defined freemarker templates would create a security hole. For > example, can you access global classes, the class instance of > objects (to call getClass().getResourceAsStream(...)), or other data > outside the scope of the data passed as a parameter to freemarker? > > Has anyone done this before? Is FreeMarker safe for this use? > > Thanks in advance, > Dobes Attila. -- home: http://www.szegedi.org twitter: http://twitter.com/szegedi weblog: http://constc.blogspot.com ------------------------------------------------------------------------------ This SF.net email is sponsored by: SourcForge Community SourceForge wants to tell your story. http://p.sf.net/sfu/sf-spreadtheword