From: Joey Hess Date: Fri, 23 Apr 2010 21:38:37 +0000 (-0400) Subject: update re template change X-Git-Tag: 3.20100427~33 X-Git-Url: http://git.tremily.us/?a=commitdiff_plain;h=1473bf84c525d18f933fa2dcae86628af9dfff76;p=ikiwiki.git update re template change --- diff --git a/doc/security.mdwn b/doc/security.mdwn index 21aef316b..34a005239 100644 --- a/doc/security.mdwn +++ b/doc/security.mdwn @@ -162,10 +162,11 @@ closed though. ## HTML::Template security -If the [[plugins/template]] plugin is enabled, users can modify templates -like any other part of the wiki. This assumes that HTML::Template is secure +If the [[plugins/template]] plugin is enabled, all users can modify templates +like any other part of the wiki. Some trusted users can modify templates +without it too. This assumes that HTML::Template is secure when used with untrusted/malicious templates. (Note that includes are not -allowed, so that's not a problem.) +allowed.) ----