Re: User-defined templates - are they safe? Is FreeMarker a secure sandbox?

Attila Szegedi <[email protected]>
Newsgroups gmane.comp.web.freemarker.user
Message-ID <[email protected]>
On 2009.01.17., at 23:01, Dobes Vandermeer wrote:

> Ah, that sounds interesting!  Is there any likelihood of the 2.4  
> release going final in the next month or two?

I don't honestly think so. There's some loose ends that we don't want  
to leave in in a final version, but nobody seems to find time to nab  
them.

> How stable is 2.4?

I wouldn't dare judge it. Jonathan overhauled quite a lot of things,  
and I don't see the effect of all of those changes. I did some work  
this summer while I was on vacation on stabilizing and polishing the  
new and changed stuff, and I did indeed discover several problematic  
corner cases then (that I fixed). I'm not convinced there aren't more  
such things lurking, but they would indeed be seldom-hit corner cases.

It passes all the same tests as 2.3 does (plus some new ones), but  
that's not really saying much, considering our test suite achieves  
only 52% block coverage, see <http://freemarker.org:8085/download/FM-TRUNK/artifacts/build-292/EMMA-coverage-report/index.html 
 >. (On the other hand, 52% ain't that bad either.)

Overall, I think it's safe to use. If you run into anything, we're  
usually quite quick to fix things if you report them here.

Attila.

>
> Thanks!
>
> On Sat, Jan 17, 2009 at 1:04 PM, Attila Szegedi <[email protected]>  
> wrote:
> If you use the 2.4 prerelease, you can subject templates to Java
> security policy based on their source URL - the docs in the 2.4
> distribution contain a description of how to do it.
>
> Attila.
>
> On 2009.01.17., at 1:51, Dobes Vandermeer wrote:
>
> > Hello All,
> >
> > I'd like to use FreeMarker to allow my users to customize the layout
> > and appearance of reports and invoices.  However, I have to make
> > sure this won't negatively impact the security of my application.
> >
> > I'm wondering whether anyone has some ideas about whether rendering
> > user-defined freemarker templates would create a security hole.  For
> > example, can you access global classes, the class instance of
> > objects (to call getClass().getResourceAsStream(...)), or other data
> > outside the scope of the data passed as a parameter to freemarker?
> >
> > Has anyone done this before?  Is FreeMarker safe for this use?
> >
> > Thanks in advance,
> > Dobes
>
> Attila.
>
> --
> home: http://www.szegedi.org
> twitter: http://twitter.com/szegedi
> weblog: http://constc.blogspot.com
>
> -- 
>
> Dobes Vandermeer
> Director, Habitsoft Inc.
> [email protected]
> 778-891-2922

Attila.

--
home: http://www.szegedi.org
twitter: http://twitter.com/szegedi
weblog: http://constc.blogspot.com






------------------------------------------------------------------------------
This SF.net email is sponsored by:
SourcForge Community
SourceForge wants to tell your story.
http://p.sf.net/sfu/sf-spreadtheword
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.