mirror of
https://github.com/junegunn/fzf.vim.git
synced 2026-09-30 23:52:24 +08:00
Keep the whole tag address inside the preview sandbox
':sandbox' is a modifier and covers only the command up to the first '|', so an address like '/pat/|!touch file' still ran the shell command as soon as an entry was highlighted. ':execute' on a value taken from the environment keeps all of it inside the sandbox, and takes the address out of the '-c' string as well. :Helptags previews a plugin's doc/tags through the same script.
This commit is contained in:
+7
-5
@@ -30,12 +30,14 @@ else
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# The address comes from a tags file, which can be untrusted, and a preview
|
||||
# runs as soon as an entry is highlighted. Sandboxed as a builtin tag jump is,
|
||||
# so that it cannot run a shell command or touch a file
|
||||
CENTER="$("${VIMNAME}" -R -i NONE -u NONE -e -m -s "${FILE}" \
|
||||
# The address comes from a tags file, which can be untrusted, and a preview runs
|
||||
# as soon as an entry is highlighted. Sandboxed as a builtin tag jump is, so that
|
||||
# it cannot run a shell command or touch a file. ':sandbox' on its own only
|
||||
# covers the command up to the first '|', hence 'sandbox execute' on a value
|
||||
# passed through the environment, which keeps the whole address inside
|
||||
CENTER="$(FZFVIM_EXCMD="${EXCMD}" "${VIMNAME}" -R -i NONE -u NONE -e -m -s "${FILE}" \
|
||||
-c "set nomagic" \
|
||||
-c "silent sandbox ${EXCMD}" \
|
||||
-c 'silent sandbox execute $FZFVIM_EXCMD' \
|
||||
-c 'let l=line(".") | new | put =l | print | qa!')" || exit
|
||||
|
||||
START_LINE="$(( CENTER - FZF_PREVIEW_LINES / 2 ))"
|
||||
|
||||
Reference in New Issue
Block a user