1
# This file is for listing TODOs for branches that are being worked on.
2
# It should ALWAYS be empty in the mainline or in integration branches.
5
Security: it should be impossible, by default, to access files above the base of
6
the backing transport of the SmartServerRequestHandler. Currently '..' and the
7
like are not vetted, however.
9
Similarly, the SmartWSGIApp should also be careful to disallow '..' and the