mirror of
https://github.com/junegunn/fzf.vim.git
synced 2026-10-04 19:28:53 +08:00
Keep the whole tag address inside the preview sandbox
':sandbox' is a modifier and covers only the command up to the first '|', so an address like '/pat/|!touch file' still ran the shell command as soon as an entry was highlighted. ':execute' on a value taken from the environment keeps all of it inside the sandbox, and takes the address out of the '-c' string as well. :Helptags previews a plugin's doc/tags through the same script.
This commit is contained in:
1 file changed
+7
-5
+7
-5
@@ -30,12 +30,14 @@ else
|
|||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# The address comes from a tags file, which can be untrusted, and a preview
|
# The address comes from a tags file, which can be untrusted, and a preview runs
|
||||||
# runs as soon as an entry is highlighted. Sandboxed as a builtin tag jump is,
|
# as soon as an entry is highlighted. Sandboxed as a builtin tag jump is, so that
|
||||||
# so that it cannot run a shell command or touch a file
|
# it cannot run a shell command or touch a file. ':sandbox' on its own only
|
||||||
CENTER="$("${VIMNAME}" -R -i NONE -u NONE -e -m -s "${FILE}" \
|
# covers the command up to the first '|', hence 'sandbox execute' on a value
|
||||||
|
# passed through the environment, which keeps the whole address inside
|
||||||
|
CENTER="$(FZFVIM_EXCMD="${EXCMD}" "${VIMNAME}" -R -i NONE -u NONE -e -m -s "${FILE}" \
|
||||||
-c "set nomagic" \
|
-c "set nomagic" \
|
||||||
-c "silent sandbox ${EXCMD}" \
|
-c 'silent sandbox execute $FZFVIM_EXCMD' \
|
||||||
-c 'let l=line(".") | new | put =l | print | qa!')" || exit
|
-c 'let l=line(".") | new | put =l | print | qa!')" || exit
|
||||||
|
|
||||||
START_LINE="$(( CENTER - FZF_PREVIEW_LINES / 2 ))"
|
START_LINE="$(( CENTER - FZF_PREVIEW_LINES / 2 ))"
|
||||||
|
|||||||
Reference in new issue
Block a user