Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtp (Exim 4.84_2) (envelope-from ) id 1bWiHs-0005cB-Rb for pgadmin-hackers@arkaria.postgresql.org; Mon, 08 Aug 2016 11:00:04 +0000 Received: from localhost ([127.0.0.1] helo=postgresql.org) by malur.postgresql.org with smtp (Exim 4.84_2) (envelope-from ) id 1bWiHs-0000ve-BI for pgadmin-hackers@arkaria.postgresql.org; Mon, 08 Aug 2016 11:00:04 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_CBC_SHA384:256) (Exim 4.84_2) (envelope-from ) id 1bWiHe-0000dG-B2 for pgadmin-hackers@postgresql.org; Mon, 08 Aug 2016 10:59:50 +0000 Received: from mahout.postgresql.org ([2001:4800:1501:1::227]) by magus.postgresql.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_CBC_SHA384:256) (Exim 4.84_2) (envelope-from ) id 1bWiHW-0007RY-Dz for pgadmin-hackers@postgresql.org; Mon, 08 Aug 2016 10:59:49 +0000 Received: from gothos.postgresql.org ([204.145.124.243]) by mahout.postgresql.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_CBC_SHA1:256) (Exim 4.84_2) (envelope-from ) id 1bWiHU-0003vg-Fv for pgadmin-hackers@postgresql.org; Mon, 08 Aug 2016 10:59:40 +0000 Received: from git by gothos.postgresql.org with local (Exim 4.84_2) (envelope-from ) id 1bWiHT-0004vH-NM for pgadmin-hackers@postgresql.org; Mon, 08 Aug 2016 10:59:39 +0000 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 From: Dave Page To: pgadmin-hackers@postgresql.org Subject: pgAdmin 4 commit: Prevent the user attempting to run external commands Message-Id: Date: Mon, 08 Aug 2016 10:59:39 +0000 X-Pg-Spam-Score: -7.4 (-------) List-Archive: List-Help: List-ID: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: X-Mailing-List: pgadmin-hackers Precedence: bulk Sender: pgadmin-hackers-owner@postgresql.org UHJldmVudCB0aGUgdXNlciBhdHRlbXB0aW5nIHRvIHJ1biBleHRlcm5hbCBj b21tYW5kcyBpZiB0aGUgYmluIHBhdGggaXMgbm90IGNvbmZpZ3VyZWQuIEZp eGVzICMxMTc3CgpCcmFuY2gKLS0tLS0tCm1hc3RlcgoKRGV0YWlscwotLS0t LS0tCmh0dHA6Ly9naXQucG9zdGdyZXNxbC5vcmcvZ2l0d2ViP3A9cGdhZG1p bjQuZ2l0O2E9Y29tbWl0ZGlmZjtoPWY3ODAyNDgwOGU4MGZlZjY3ZGUxYWVm NWM5N2QxNzU2YzY3NzFjMGUKQXV0aG9yOiBIYXJzaGFsIERodW1hbCA8aGFy c2hhbC5kaHVtYWxAZW50ZXJwcmlzZWRiLmNvbT4KCk1vZGlmaWVkIEZpbGVz Ci0tLS0tLS0tLS0tLS0tCi4uLi9icm93c2VyL3RlbXBsYXRlcy9icm93c2Vy L2pzL2Jyb3dzZXIuanMgICAgICAgIHwgMTcgKysrKysKd2ViL3BnYWRtaW4v cHJlZmVyZW5jZXMvX19pbml0X18ucHkgICAgICAgICAgICAgICAgfCAyNyAr KysrKystCi4uLi90b29scy9iYWNrdXAvdGVtcGxhdGVzL2JhY2t1cC9qcy9i YWNrdXAuanMgICAgIHwgODYgKysrKysrKysrKysrKysrKysrKysrKwouLi4v dGVtcGxhdGVzL2ltcG9ydF9leHBvcnQvanMvaW1wb3J0X2V4cG9ydC5qcyAg ICB8IDQzICsrKysrKysrKysrCi4uLi90ZW1wbGF0ZXMvbWFpbnRlbmFuY2Uv anMvbWFpbnRlbmFuY2UuanMgICAgICAgIHwgNDcgKysrKysrKysrKystCi4u Li90b29scy9yZXN0b3JlL3RlbXBsYXRlcy9yZXN0b3JlL2pzL3Jlc3RvcmUu anMgIHwgNDQgKysrKysrKysrKysKd2ViL3BnYWRtaW4vdXRpbHMvcHJlZmVy ZW5jZXMucHkgICAgICAgICAgICAgICAgICAgfCAxMyArKy0tCjcgZmlsZXMg Y2hhbmdlZCwgMjY1IGluc2VydGlvbnMoKyksIDEyIGRlbGV0aW9ucygtKQoK Ci0tIApTZW50IHZpYSBwZ2FkbWluLWhhY2tlcnMgbWFpbGluZyBsaXN0IChw Z2FkbWluLWhhY2tlcnNAcG9zdGdyZXNxbC5vcmcpClRvIG1ha2UgY2hhbmdl cyB0byB5b3VyIHN1YnNjcmlwdGlvbjoKaHR0cDovL3d3dy5wb3N0Z3Jlc3Fs Lm9yZy9tYWlscHJlZi9wZ2FkbWluLWhhY2tlcnMK