From: Ihor Radchenko <yantar92@posteo.net>
To: "Dr. Arne Babenhauserheide" <arne_bab@web.de>
Cc: Jean Louis <bugs@gnu.support>,
bug-gnu-emacs@gnu.org, emacs-orgmode@gnu.org
Subject: Re: 29.0.50; [WISH]: Let us make EWW browse WWW Org files correctly
Date: Tue, 25 Oct 2022 23:03:00 +0000 [thread overview]
Message-ID: <87v8o7qzff.fsf@localhost> (raw)
In-Reply-To: <87bkq0t03l.fsf@web.de>
"Dr. Arne Babenhauserheide" <arne_bab@web.de> writes:
> This sounds dangerous. Org mode can execute untrusted code, so this
> could trick people into running untrusted code with the permissions of
> their Emacs.
>
> Links in org-mode can run shell scripts. Yes, they usually ask, but this
> may be changed it a local Emacs, trusting that it will only be used to
> open trusted local files.
You are exaggerating the situation.
The "problem" with shell links you are describing is a question of
setting variables and is also disabled by default.
eww-mode, when loading Org page, could simply set
org-link-shell-confirm-function to its default value.
--
Ihor Radchenko // yantar92,
Org mode contributor,
Learn more about Org mode at <https://orgmode.org/>.
Support Org development at <https://liberapay.com/org-mode>,
or support my work at <https://liberapay.com/yantar92>
next prev parent reply other threads:[~2022-10-25 23:03 UTC|newest]
Thread overview: 49+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-10-25 12:06 29.0.50; [WISH]: Let us make EWW browse WWW Org files correctly Jean Louis
2022-10-25 15:02 ` Dr. Arne Babenhauserheide
2022-10-25 19:56 ` bug#58774: " Jean Louis
2022-10-25 21:54 ` Dr. Arne Babenhauserheide
2022-10-26 7:57 ` bug#58774: " Jean Louis
2022-10-26 11:55 ` Dr. Arne Babenhauserheide
2022-10-26 12:20 ` Jean Louis
2022-10-26 12:45 ` bug#58774: " Andreas Schwab
2022-10-26 13:19 ` Jean Louis
[not found] ` <Y1kz5PKQh1SMr1BO@protected.localdomain>
2022-10-26 13:55 ` Andreas Schwab
[not found] ` <mvmh6zqadu9.fsf@suse.de>
2022-10-26 17:36 ` Jean Louis
[not found] ` <Y1lwNABImLQnQojU@protected.localdomain>
2022-10-27 7:58 ` Andreas Schwab
[not found] ` <mvma65hae9p.fsf@suse.de>
2022-10-27 8:40 ` Jean Louis
[not found] ` <Y1pD/h1INh3457ou@protected.localdomain>
2022-10-27 11:22 ` Andreas Schwab
2022-10-27 11:23 ` Dr. Arne Babenhauserheide
2022-10-26 7:59 ` Jean Louis
2022-10-25 23:03 ` Ihor Radchenko [this message]
2022-10-26 6:07 ` Stefan Kangas
[not found] ` <CADwFkm=zOc6K6=eOa_WgXrnnpCRa47wKHeB+yfDM4Q0Fjzjd8A@mail.gmail.com>
2022-10-26 6:52 ` Ihor Radchenko
2022-10-26 8:21 ` Jean Louis
2022-10-26 17:07 ` Max Nikulin
2022-10-26 18:37 ` Jean Louis
2022-10-26 21:16 ` Dr. Arne Babenhauserheide
2022-10-26 21:56 ` indieterminacy
[not found] ` <87zgdjoz3r.fsf@localhost>
2022-10-26 8:24 ` Jean Louis
2022-10-26 20:22 ` indieterminacy
2022-10-26 11:30 ` Dr. Arne Babenhauserheide
2022-10-26 13:15 ` Stefan Kangas
2022-10-25 22:13 ` Ag Ibragimov
2022-10-26 8:28 ` Jean Louis
2022-10-26 13:00 ` Rudolf Adamkovič
2022-10-26 13:42 ` bug#58774: " Jean Louis
2022-10-27 4:55 ` Jean Louis
2022-10-27 11:13 ` Dr. Arne Babenhauserheide
2022-10-27 17:41 ` Jean Louis
2022-10-27 21:43 ` Dr. Arne Babenhauserheide
2022-10-27 15:35 ` Max Nikulin
[not found] ` <d8bead8c-f97d-1de5-ae06-df81fefb7389@gmail.com>
2022-10-27 17:58 ` Jean Louis
2022-10-27 21:49 ` Dr. Arne Babenhauserheide
2022-10-27 18:25 ` Jean Louis
2022-10-27 19:53 ` Quiliro Ordóñez
2022-10-27 19:58 ` Quiliro Ordóñez
2022-10-27 21:57 ` Dr. Arne Babenhauserheide
[not found] ` <87y1t0or6q.fsf@web.de>
2022-10-27 22:18 ` Jean Louis
[not found] ` <Y1sD0bXYnDCY2Yw4@protected.localdomain>
2022-10-27 23:14 ` Dr. Arne Babenhauserheide
2022-10-27 23:20 ` Ihor Radchenko
[not found] ` <87zgdgn9av.fsf@localhost>
2022-10-28 8:28 ` Dr. Arne Babenhauserheide
[not found] ` <87h6zony3p.fsf@web.de>
2022-11-02 4:09 ` Ihor Radchenko
2023-09-02 8:53 ` Stefan Kangas
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
List information: https://www.gnu.org/software/emacs/
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=87v8o7qzff.fsf@localhost \
--to=yantar92@posteo.net \
--cc=arne_bab@web.de \
--cc=bug-gnu-emacs@gnu.org \
--cc=bugs@gnu.support \
--cc=emacs-orgmode@gnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
Code repositories for project(s) associated with this public inbox
https://git.savannah.gnu.org/cgit/emacs.git
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).