Edgewall Software

Ticket #123 (closed enhancement: fixed)

Opened 7 years ago

Last modified 7 years ago

Optional disable python code blocks patch

Reported by: fschwindt@… Owned by: cmlenz
Priority: minor Milestone: 0.5
Component: Template processing Version: 0.4
Keywords: python code block patch Cc:

Description (last modified by cmlenz) (diff)

Hi,

We're starting to use Genshi at work and we'd like to have a switch to disable python code blocks to avoid any possible misuse and abuse from the content editors.

I've attached the diff (including unittest). It's fairly simple. Passing True to python_disable (yuk, I couldn't think of any other name for it) will raise a TemplateSyntaxError if it encounters such blocks, otherwise the behaviour is the same as the current one.

Are there any chances that this can be included in Genshi, in this or some other form?

Thanks,

f.-

Attachments

disable_python.patch Download (7.3 KB) - added by fschwindt@… 7 years ago.
disable python code blocks

Change History

Changed 7 years ago by fschwindt@…

disable python code blocks

Changed 7 years ago by cmlenz

  • description modified (diff)

Hmm, how about allow_exec=True instead of disable_python=False? Or maybe allow_code_blocks=True, but that's too long IMHO.

The name disable_python is misleading as expressions are also Python.

(I've modified the description to improve readability/formatting)

Changed 7 years ago by fschwindt@…

allow_exec is fine (was my first choice) but it does not fully reflect what it is for (it's too tied with the code internals). I like allow_code_blocks but I agree it's too long so I'm not sure.

Changed 7 years ago by cmlenz

Hmm, actually exec is (or should be) quite well-known to Python developers, due to the  exec statement/keyword.

Changed 7 years ago by anonymous

I was thinking in the EXEC StreamEventKind honestly. Of course exec should be well-known to any Python developer, but you're assuming that people will know how Genshi works under the hood. Anyway, if you are happy with allow_exec, I'm happy as well.

Changed 7 years ago by cmlenz

  • status changed from new to closed
  • resolution set to fixed

Implemented in [654].

Add/Change #123 (Optional disable python code blocks patch)

Author


E-mail address and user name can be saved in the Preferences.


Change Properties
<Author field>
Action
as closed
The resolution will be deleted. Next status will be 'reopened'
 
Note: See TracTickets for help on using tickets.