Re: User-defined templates - are they safe? Is FreeMarker a secure sandbox?
Attila Szegedi <[email protected]>
| Newsgroups | gmane.comp.web.freemarker.user |
|---|---|
| Message-ID | <[email protected]> |
On 2009.01.17., at 23:01, Dobes Vandermeer wrote: > Ah, that sounds interesting! Is there any likelihood of the 2.4 > release going final in the next month or two? I don't honestly think so. There's some loose ends that we don't want to leave in in a final version, but nobody seems to find time to nab them. > How stable is 2.4? I wouldn't dare judge it. Jonathan overhauled quite a lot of things, and I don't see the effect of all of those changes. I did some work this summer while I was on vacation on stabilizing and polishing the new and changed stuff, and I did indeed discover several problematic corner cases then (that I fixed). I'm not convinced there aren't more such things lurking, but they would indeed be seldom-hit corner cases. It passes all the same tests as 2.3 does (plus some new ones), but that's not really saying much, considering our test suite achieves only 52% block coverage, see <http://freemarker.org:8085/download/FM-TRUNK/artifacts/build-292/EMMA-coverage-report/index.html >. (On the other hand, 52% ain't that bad either.) Overall, I think it's safe to use. If you run into anything, we're usually quite quick to fix things if you report them here. Attila. > > Thanks! > > On Sat, Jan 17, 2009 at 1:04 PM, Attila Szegedi <[email protected]> > wrote: > If you use the 2.4 prerelease, you can subject templates to Java > security policy based on their source URL - the docs in the 2.4 > distribution contain a description of how to do it. > > Attila. > > On 2009.01.17., at 1:51, Dobes Vandermeer wrote: > > > Hello All, > > > > I'd like to use FreeMarker to allow my users to customize the layout > > and appearance of reports and invoices. However, I have to make > > sure this won't negatively impact the security of my application. > > > > I'm wondering whether anyone has some ideas about whether rendering > > user-defined freemarker templates would create a security hole. For > > example, can you access global classes, the class instance of > > objects (to call getClass().getResourceAsStream(...)), or other data > > outside the scope of the data passed as a parameter to freemarker? > > > > Has anyone done this before? Is FreeMarker safe for this use? > > > > Thanks in advance, > > Dobes > > Attila. > > -- > home: http://www.szegedi.org > twitter: http://twitter.com/szegedi > weblog: http://constc.blogspot.com > > -- > > Dobes Vandermeer > Director, Habitsoft Inc. > [email protected] > 778-891-2922 Attila. -- home: http://www.szegedi.org twitter: http://twitter.com/szegedi weblog: http://constc.blogspot.com ------------------------------------------------------------------------------ This SF.net email is sponsored by: SourcForge Community SourceForge wants to tell your story. http://p.sf.net/sfu/sf-spreadtheword