emacs-orgmode
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [BUG][Security] begin_src :var evaluated before the prompt to confir


From: Max Nikulin
Subject: Re: [BUG][Security] begin_src :var evaluated before the prompt to confirm execution
Date: Thu, 27 Oct 2022 11:46:23 +0700
User-agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Thunderbird/102.2.2

On 27/10/2022 11:22, Jean Louis wrote:
* Max Nikulin [2022-10-27 06:21]:
Expected result:
No code from the Org buffer and linked files is executed prior to
confirmation from the user.
Should that be or is it a general policy for Org mode?
I am afraid, it is unrealistic. Spreadsheet feature will be unusable. 
And it is another reason why I am strongly against formats designed for 
personal use rather than for web in browser context.
I consider such issues as a reason why it is bad idea to use Emacs as a
handler for Org files downloaded from web.
I am lost here. Should people then use Vim as handler for Org files? 👀
I will respond if you ask the same in another thread. I created this one 
to track particular issue: arguments of source code blocks evaluated 
without a prompt. Content-Type will not help fix this issue.
Perhaps closely related issues exist with noweb references or some other 
way to use code outside of particular #+begin_src body. I am unsure if 
such problems should be discussed in this thread or in dedicated ones. I 
am still suffering from deja vu and I should just bump an earlier thread.





reply via email to

[Prev in Thread] Current Thread [Next in Thread]