frep icon indicating copy to clipboard operation
frep copied to clipboard

Do not use environment variables by default - security issue

Open FlipSky opened this issue 4 years ago • 1 comments

Please exclude support for environment variables in the templates (the .Env.* insertions according to the documentation). This can expose a lot of unintentional information (just run set in your shell to see what is available).

Preferred behaviour:

  1. Change default value of --no-sys-env to true (or rename option).
  2. Remove all support for system environments and only accept definitions from --env, --json or --load.

Simple work around is to add --no-sys-env parameter.

FlipSky avatar Nov 28 '20 17:11 FlipSky

This will bring to backward compatibility problems, need update in next major version release.

subchen avatar Dec 03 '20 05:12 subchen