|
From: | Max Nikulin |
Subject: | Re: [BUG][Security] begin_src :var evaluated before the prompt to confirm execution |
Date: | Thu, 27 Oct 2022 11:46:23 +0700 |
User-agent: | Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Thunderbird/102.2.2 |
On 27/10/2022 11:22, Jean Louis wrote:
* Max Nikulin [2022-10-27 06:21]:Expected result: No code from the Org buffer and linked files is executed prior to confirmation from the user.Should that be or is it a general policy for Org mode?
I am afraid, it is unrealistic. Spreadsheet feature will be unusable. And it is another reason why I am strongly against formats designed for personal use rather than for web in browser context.
I consider such issues as a reason why it is bad idea to use Emacs as a handler for Org files downloaded from web.I am lost here. Should people then use Vim as handler for Org files? 👀
I will respond if you ask the same in another thread. I created this one to track particular issue: arguments of source code blocks evaluated without a prompt. Content-Type will not help fix this issue.
Perhaps closely related issues exist with noweb references or some other way to use code outside of particular #+begin_src body. I am unsure if such problems should be discussed in this thread or in dedicated ones. I am still suffering from deja vu and I should just bump an earlier thread.
[Prev in Thread] | Current Thread | [Next in Thread] |