~bzr-pqm/bzr/bzr.dev

« back to all changes in this revision

Viewing changes to BRANCH.TODO

  • Committer: Robert Collins
  • Date: 2005-10-18 13:11:57 UTC
  • mfrom: (1185.16.72) (0.2.1)
  • Revision ID: robertc@robertcollins.net-20051018131157-76a9970aa78e927e
Merged Martin.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
# This file is for listing TODOs for branches that are being worked on.
2
 
# It should ALWAYS be empty in the mainline or in integration branches.
3
 
4
 
 
5
 
Security: it should be impossible, by default, to access files above the base of
6
 
the backing transport of the SmartServerRequestHandler.  Currently '..' and the
7
 
like are not vetted, however.
8
 
 
9
 
Similarly, the SmartWSGIApp should also be careful to disallow '..' and the
10
 
like.