<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: On Sandboxing Genshi</title>
	<link>http://lucumr.pocoo.org/cogitations/2007/09/26/on-sandboxing-genshi/</link>
	<description>Armin Ronacher thinking</description>
	<pubDate>Thu, 28 Aug 2008 02:43:27 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2</generator>

	<item>
		<title>By: Alice McGregor</title>
		<link>http://lucumr.pocoo.org/cogitations/2007/09/26/on-sandboxing-genshi/#comment-10564</link>
		<author>Alice McGregor</author>
		<pubDate>Tue, 19 Aug 2008 08:24:50 +0000</pubDate>
		<guid>http://lucumr.pocoo.org/cogitations/2007/09/26/on-sandboxing-genshi/#comment-10564</guid>
		<description>I'm -very- interested in securing Genshi.  Specifically removing any possibility of users including other files or even building  blocks whatsoever.  That would go a long way towards securing a template.

I couldn't easily tell what changes you had made in your branch, if any.  Is there any forward progress?</description>
		<content:encoded><![CDATA[<p>I&#8217;m -very- interested in securing Genshi.  Specifically removing any possibility of users including other files or even building  blocks whatsoever.  That would go a long way towards securing a template.</p>
<p>I couldn&#8217;t easily tell what changes you had made in your branch, if any.  Is there any forward progress?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Armin Ronacher</title>
		<link>http://lucumr.pocoo.org/cogitations/2007/09/26/on-sandboxing-genshi/#comment-468</link>
		<author>Armin Ronacher</author>
		<pubDate>Thu, 27 Sep 2007 16:17:53 +0000</pubDate>
		<guid>http://lucumr.pocoo.org/cogitations/2007/09/26/on-sandboxing-genshi/#comment-468</guid>
		<description>I have no idea how comments are parsed in WordPress, probably some limited amount of HTML, i shortened the link in the admin.

That thing is definitively bad, I thought the django template loader makes sure nothing outside of the django root is included. That couldn't happen with Genshi ;-)</description>
		<content:encoded><![CDATA[<p>I have no idea how comments are parsed in WordPress, probably some limited amount of HTML, i shortened the link in the admin.</p>
<p>That thing is definitively bad, I thought the django template loader makes sure nothing outside of the django root is included. That couldn&#8217;t happen with Genshi ;-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Christopher Lenz</title>
		<link>http://lucumr.pocoo.org/cogitations/2007/09/26/on-sandboxing-genshi/#comment-466</link>
		<author>Christopher Lenz</author>
		<pubDate>Thu, 27 Sep 2007 12:37:41 +0000</pubDate>
		<guid>http://lucumr.pocoo.org/cogitations/2007/09/26/on-sandboxing-genshi/#comment-466</guid>
		<description>Btw, about Django templates being sandboxed/secure:

  &lt;a href="http://groups.google.com/group/django-developers/browse_thread/thread/28eac0b3787de93/51e1946f5b97e97e#51e1946f5b97e97e" rel="nofollow"&gt;include tag security hole&lt;/a&gt;

(Hope that comes out right, there are no hints here about how comments are supposed to be formatted to include links etc)</description>
		<content:encoded><![CDATA[<p>Btw, about Django templates being sandboxed/secure:</p>
<p>  <a href="http://groups.google.com/group/django-developers/browse_thread/thread/28eac0b3787de93/51e1946f5b97e97e#51e1946f5b97e97e" rel="nofollow">include tag security hole</a></p>
<p>(Hope that comes out right, there are no hints here about how comments are supposed to be formatted to include links etc)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
