Enable sandboxing by default #3
Reference in New Issue
Block a user
No description provided.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Grist python formula execution seems to be pretty permissive and doesn't seem to be contained at all. This could be problematic if people share documents in anonymous edit mode. I suggest we should sandbox by default.
See here: https://support.getgrist.com/self-managed/#how-do-i-sandbox-documents
There are two sandboxing options with
GRIST_SANDBOX_FLAVOR:gvisorshould be faster, but it didn't work out of the box for mepyoditeis slower, but works for me wellI suggest enabling
pyoditeby default as it should work everywhere. It may be slow, but at least doesn't expose unwary operators to security risks. Any thoughts?