Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Load the command list from an url #9

Open
plainas opened this issue May 18, 2022 · 0 comments
Open

Load the command list from an url #9

plainas opened this issue May 18, 2022 · 0 comments

Comments

@plainas
Copy link
Owner

plainas commented May 18, 2022

Allow passing an url pointing to the command list when launching icl. Use -u /--url. The file could contain escape sequences that are injected in the terminal. This is essentially a blatant window for remote code execution. So needs to be used with full awareness of the risks.

  • For safety reasons only https should be allowed.
  • Disable this feature by default or show a huge red warning each time this is used. Use an environment variable to allow disabling this security check.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant