emacs-orgmode
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [BUG][Security] begin_src :var evaluated before the prompt to confir


From: Jean Louis
Subject: Re: [BUG][Security] begin_src :var evaluated before the prompt to confirm execution
Date: Fri, 28 Oct 2022 10:30:21 +0300
User-agent: Mutt/2.2.7+37 (a90f69b) (2022-09-02)

* Ihor Radchenko <yantar92@posteo.net> [2022-10-28 06:19]:
> Jean Louis <bugs@gnu.support> writes:
> 
> > * Max Nikulin <manikulin@gmail.com> [2022-10-27 06:21]:
> >> Expected result:
> >> No code from the Org buffer and linked files is executed prior to
> >> confirmation from the user.
> >
> > Should that be or is it a general policy for Org mode?
> 
> Yes, it is a general policy.
> Org should not execute arbitrary Elisp without confirmation, unless the
> user customizes the confirmation query to non-default.

✔️ That is nice to know. It opens doors for browsing Org files within Emacs.

-- 
Jean

Take action in Free Software Foundation campaigns:
https://www.fsf.org/campaigns

In support of Richard M. Stallman
https://stallmansupport.org/



reply via email to

[Prev in Thread] Current Thread [Next in Thread]