Make quoteIfContainsWhite quote argument, so it can be safely passed to shell.
On Windows put it in double quotes and escape double quotes using backslash. On Posix put it in single quotes and escape single quotes using '"'"'. This commit changes what quoteIfContainsWhite does, but before that change it was used incorrectly all over standard library, which caused security issues.
This commit is contained in:
parent
5dcfa97fb9
commit
e7e8c77062
2 changed files with 45 additions and 8 deletions
|
|
@ -28,6 +28,8 @@ Changes affecting backwards compatibility
|
|||
require an error code to be passed to them. This error code can be retrieved
|
||||
using the new ``OSLastError`` proc.
|
||||
- ``os.parentDir`` now returns "" if there is no parent dir.
|
||||
- ``quoteIfContainsWhite`` now escapes argument in such way that it can be safely
|
||||
passed to shell, instead of just adding double quotes.
|
||||
|
||||
|
||||
Compiler Additions
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue