Skip to content

Provide an option to disable environment access #2515

Description

@jandubois

We were having a debate about exposing YQ filter expression in the limactl list command, and the objection was that if this functionality is used in a web application, then it could potentially be abused to extract environment variable settings of the web server.

Personally I think this is somewhat of an unlikely scenario to begin with, and then depends on the server config not running with a sanitized environment, and the attacker knowing the name of the interesting environment variable(s). Because as far as I can tell there is no way to enumerate and query all variables from within YQ.

But anyways, in order to end this discussion, it would be great if there was some option that can be passed to yqlib, so all env functions always return an empty string instead of the actual value from the process environment.

It didn't seem obvious to me how you could implement this, as options don't seem to be passed to the individual operators, but maybe you have an idea how this could be done without too much effort?

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions