Process Tags security update

Freshness Warning
This blog post is over 21 years old. It's possible that the information you read below isn't current and the links no longer work.

If you use the Process Tags plugin and you have multiple authors on your blog, it would be a good idea to remember that the plugin allows any author to insert Movable Type tags into their entries. This could potentially lead to bad things happening, especially if you use the SQL or PerlScript plugins. Please use common sense when using this (or any other) plugin.

Paul Winkeler
July 18, 2003 9:57 AM

Hi Guys Can we not think of some kind of restrictions to impose on the evaluation of tags inside entry contexts? Perhaps only entries authored by the "owner" of the blog can have this feature activated by careful crafting of the template? Any other ideas to manage this risk would be greatly appreciated. PaulW

This discussion has been closed.

Recently Written

Input metrics lead to outcomes (Sep 1)
An easy to understand example of using input metrics to track progress toward an outcome.
Lagging Outcomes (Aug 22)
Long-term things often end up off a team's goals because they can't see how to define measurable outcomes for them. Here's how to solve that.
Tyranny of Outcomes (Aug 19)
An extreme focus on outcomes can have an undesired effect on product teams.
The Trap of The Sales-Led Product (Dec 10)
It’s not a winning way to build a product company.
The Hidden Cost of Custom Customer Features (Dec 7)
One-off features will cost you more than you think and make your customers unhappy.
Domain expertise in Product Management (Nov 16)
When you're hiring software product managers, hire for product management skills. Looking for domain experts will reduce the pool of people you can hire and might just be worse for your product.
Strategy Means Saying No (Oct 27)
An oft-overlooked aspect of strategy is to define what you are not doing. There are lots of adjacent problems you can attack. Strategy means defining which ones you will ignore.
Understanding vision, strategy, and execution (Oct 24)
Vision is what you're trying to do. Strategy is broad strokes on how you'll get there. Execution is the tasks you complete to complete the strategy.

Older...

What I'm Reading

Contact

Adam Kalsey

+1 916 600 2497

Resume

Public Key

© 1999-2023 Adam Kalsey.