Skip to content

Security consequences of passing include_loader (and supporting mj-include) not being warned about?Β #588

@hartwork

Description

@hartwork

Hi! Thanks for sharing this project as software libre! πŸ™

It has come to my attention that use of loaders http_loader and local_loader is showcased in the docs without any mention of security consequences. I do find security notes in the related implementation but not in places targeting end users. Are you aware?

PS: Kudos for not enabling mj-include by default πŸ‘

Best, Sebastian

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions