[exim-cvs] Docs: add note on non-functionality of "exists" f…

Startseite
Nachricht löschen
Nachricht beantworten
Autor: Exim Git Commits Mailing List
Datum:  
To: exim-cvs
Betreff: [exim-cvs] Docs: add note on non-functionality of "exists" for de-tainting
Gitweb: https://git.exim.org/exim.git/commitdiff/040494b780a1f6db9f7dba0058c29e975241c1b0
Commit:     040494b780a1f6db9f7dba0058c29e975241c1b0
Parent:     63c4307e5873801eaed051ef258d90a52a7d19e7
Author:     Jeremy Harris <jgh146exb@???>
AuthorDate: Sun Jul 12 13:36:10 2020 +0100
Committer:  Jeremy Harris <jgh146exb@???>
CommitDate: Sun Jul 12 13:36:10 2020 +0100


    Docs: add note on non-functionality of "exists" for de-tainting
---
 doc/doc-docbook/spec.xfpt | 5 +++++
 1 file changed, 5 insertions(+)


diff --git a/doc/doc-docbook/spec.xfpt b/doc/doc-docbook/spec.xfpt
index 0ffc88c..d981f62 100644
--- a/doc/doc-docbook/spec.xfpt
+++ b/doc/doc-docbook/spec.xfpt
@@ -11656,6 +11656,11 @@ condition is true if the named file (or directory) exists. The existence test
is done by calling the &[stat()]& function. The use of the &%exists%& test in
users' filter files may be locked out by the system administrator.

+.new
+&*Note:*& Testing a path using this condition is not a sufficient way of
+de-tainting it.
+.wen
+
.vitem &*first_delivery*&
.cindex "delivery" "first"
.cindex "first delivery"