[Zope3-dev] Re: Through-the-web reStructuredText

Tres Seaver tseaver at palladion.com
Sat Jul 8 00:29:43 EDT 2006


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Michael Haubenwallner wrote:
> Tres Seaver wrote:
>> -----BEGIN PGP SIGNED MESSAGE-----
>> Hash: SHA1
>>
>> Jim Fulton wrote:
>>
>>> Zope 3, as releases is not affected by the security hole that
>>> has plagued Zope 2, however, Michael Haubenwallner has pointed
>>> out that some add-on-products, such as zwiki and bugtracker, may
>>> provide TTW reST.
>>
>> They appear to be "safe" for the moment, but not because they
>> intentionally disable file inclusion:  rather, they have a bug (they set
>> the 'encoding' to 'unicode', which then causes an exception).
>>
> 
> Both restructuredText directives 'include' and 'raw' have an 'encoding'
> option to set the name of text encoding of the external data file/raw
> data (file or URL), it defaults to the document's encoding (if specified).
> 
> .. include:: filename.ext
>   :encoding: utf-8
> 
> .. raw:: html
>   :file: filename.ext
>   :encoding: utf-8
> 
> should work as expected
> 
> Michael


Verified.  Both wikis and bugtracker issues are capable of including
arbitrary files using that spelling (in an instance created from today's
Zope3 trunk, anyway).


Tres.
- --
===================================================================
Tres Seaver          +1 202-558-7113          tseaver at palladion.com
Palladion Software   "Excellence by Design"    http://palladion.com
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFErzS3+gerLs4ltQ4RAhboAKC0oxRwqZKBOiZxYEEPXoPi1NE0tACbBepr
f5qWSi/OFDafP05XGXaOqxI=
=x4ny
-----END PGP SIGNATURE-----



More information about the Zope3-dev mailing list