Application.load_config_file loads all files with same basename as given file
还没有人认领这个 Issue。
评估
调研方向
从 Application.load_config_file 开始,使用临时的 .py 和 .json 文件重现 issue 中的两个案例。跟踪请求的路径是如何解析的,以及匹配的文件是如何选择的。添加一个回归测试,证明加载一个绝对路径不会执行或解析另一个具有相同基本名称的文件。
由索引模型根据 Issue 内容生成。
描述
Even if load_config_file is given an absolute path to a config file, it will load all files that have the same basename that are in that directory.
This is highly surprising and potentially a security issue.
Example:
from pathlib import Path
from traitlets import Integer
from traitlets.config import Application
from tempfile import TemporaryDirectory
class Foo(Application):
bar = Integer(0).tag(config=True)
def start(self):
print(self.bar)
if __name__ == "__main__":
with TemporaryDirectory() as tmpdir:
tmpdir = Path(tmpdir)
json_path = tmpdir / "foo.json"
py_path = tmpdir / "foo.py"
# valid python, invalid
py_path.write_text("c.Foo.bar = 10")
json_path.write_text("Invalid json")
app = Foo()
app.load_config_file(py_path)
app.start()
# other way around
py_path.write_text("raise Exception('You loaded the python file!')")
json_path.write_text('{"Foo": {"bar": 11}}')
app = Foo()
app.load_config_file(json_path)
app.start()
- 主要语言
- Python
- 星标
- 653
- 派生
- 217
- 平均合并
- 2 天 21 小时
- 30 天内合并 PR
- 2
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
ipython/traitlets 的其他 Issue
-
难度 1/5 1 小时以内 新手友好度 65/100
-
难度 1/5 1-3 小时 新手友好度 65/100
-
good first issue
难度 1/5 1 小时以内 新手友好度 85/100
-
documentation
难度 1/5 1 小时以内 新手友好度 65/100
-
难度 3/5 1-2 天 新手友好度 45/100
查看 ipython/traitlets 的全部 Issue
相似的 Issue
-
area: harness bug status: needs-triage
难度 2/5 1-3 小时 新手友好度 75/100
Human-Agent-Society/reef#625 ·
-
难度 2/5 1-3 小时 新手友好度 70/100
-
难度 1/5 1 小时以内 新手友好度 80/100
learningequality/kolibri#15351 · 2 条评论 ·
-
难度 2/5 1-3 小时 新手友好度 75/100
-
Name consistency 未关闭
难度 2/5 1-3 小时 新手友好度 75/100
eellak/triplestore#65 · 1 条评论 ·