velocity-user mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From sebb <seb...@gmail.com>
Subject Re: Validate templates before use
Date Mon, 06 Feb 2012 14:41:46 GMT
On 6 February 2012 12:17, Chad La Joie <lajoie@itumi.biz> wrote:
> Is there a way to "validate" a template prior to using it?  I'd like
> to check that some user supplied templates are, at least, parsable
> during system startup.

Just because it's parseable does not mean it's safe to use ...
allowing an end-user to provide a template without manual checking
sounds like a recipe for inviting exploits.

But perhaps I'm missing something here, and you have some other way of
protecting against valid (but faulty or malicious) templates.

> Thanks.
>
> --
> Chad La Joie
> www.itumi.biz
> trusted identities, delivered
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: user-unsubscribe@velocity.apache.org
> For additional commands, e-mail: user-help@velocity.apache.org
>

---------------------------------------------------------------------
To unsubscribe, e-mail: user-unsubscribe@velocity.apache.org
For additional commands, e-mail: user-help@velocity.apache.org


Mime
View raw message