diff options
author | Sébastien Helleu <flashcode@flashtux.org> | 2019-03-09 17:51:40 +0100 |
---|---|---|
committer | Sébastien Helleu <flashcode@flashtux.org> | 2019-03-09 17:54:06 +0100 |
commit | dd44c1db16d0ec9359f6403337bbff59f98a389b (patch) | |
tree | 7d66cd5858cfedab82f69d5fbc2adee8fdd683cf /doc/en/autogen | |
parent | 2f5aa3b5097db7a0c475ab73e487a2af30a59b99 (diff) | |
download | weechat-dd44c1db16d0ec9359f6403337bbff59f98a389b.zip |
relay: add extra forbidden commands in weechat protocol (issue #928)
Commands were already forbidden (option relay.weechat.commands):
- /exec
- /upgrade
- /quit
These extra commands are now forbidden by default:
- /fset
- /set
- /unset
- /plugin
- /script
- /python
- /perl
- /ruby
- /lua
- /tcl
- /guile
- /javascript
- /php
- /secure
Diffstat (limited to 'doc/en/autogen')
-rw-r--r-- | doc/en/autogen/user/relay_options.adoc | 4 |
1 files changed, 2 insertions, 2 deletions
diff --git a/doc/en/autogen/user/relay_options.adoc b/doc/en/autogen/user/relay_options.adoc index c47fbbb87..0de413c16 100644 --- a/doc/en/autogen/user/relay_options.adoc +++ b/doc/en/autogen/user/relay_options.adoc @@ -183,7 +183,7 @@ ** default value: `+""+` * [[option_relay.weechat.commands]] *relay.weechat.commands* -** description: pass:none[comma-separated list of commands allowed/denied when input data (text or command) is received from a client; "*" means any command, a name beginning with "!" is a negative value to prevent a command from being executed, wildcard "*" is allowed in names; by default all commands are allowed except /exec, /upgrade and /quit (which could lead to denial of service or remote code execution if the client is not trusted)] +** description: pass:none[comma-separated list of commands allowed/denied when input data (text or command) is received from a client; "*" means any command, a name beginning with "!" is a negative value to prevent a command from being executed, wildcard "*" is allowed in names; by default some commands are not allowed (they could lead to denial of service or remote code execution if the client is not trusted)] ** type: string ** values: any string -** default value: `+"*,!exec,!upgrade,!quit"+` +** default value: `+"*,!exec,!fset,!set,!unset,!plugin,!script,!python,!perl,!ruby,!lua,!tcl,!guile,!javascript,!php,!secure,!upgrade,!quit"+` |