Document that the template system isn't safe against untrusted template authors
A few times (e.g. #12772) and in some security reports, the question has come up about whether or not the Django template language is safe against untrusted template authors. We should document that it is not, perhaps in docs/topics/templates.txt.
Change History
(6)
Triage Stage: |
Unreviewed → Accepted
|
Has patch: |
set
|
Owner: |
changed from nobody to Andrew Nester
|
Status: |
new → assigned
|
Patch needs improvement: |
set
|
Patch needs improvement: |
unset
|
Resolution: |
→ fixed
|
Status: |
assigned → closed
|
I created PR for this ticket PR