We were having a debate about exposing YQ filter expression in the limactl list command, and the objection was that if this functionality is used in a web application, then it could potentially be abused to extract environment variable settings of the web server.
Personally I think this is somewhat of an unlikely scenario to begin with, and then depends on the server config not running with a sanitized environment, and the attacker knowing the name of the interesting environment variable(s). Because as far as I can tell there is no way to enumerate and query all variables from within YQ.
But anyways, in order to end this discussion, it would be great if there was some option that can be passed to yqlib, so all env functions always return an empty string instead of the actual value from the process environment.
It didn't seem obvious to me how you could implement this, as options don't seem to be passed to the individual operators, but maybe you have an idea how this could be done without too much effort?
We were having a debate about exposing YQ filter expression in the
limactl listcommand, and the objection was that if this functionality is used in a web application, then it could potentially be abused to extract environment variable settings of the web server.Personally I think this is somewhat of an unlikely scenario to begin with, and then depends on the server config not running with a sanitized environment, and the attacker knowing the name of the interesting environment variable(s). Because as far as I can tell there is no way to enumerate and query all variables from within YQ.
But anyways, in order to end this discussion, it would be great if there was some option that can be passed to yqlib, so all env functions always return an empty string instead of the actual value from the process environment.
It didn't seem obvious to me how you could implement this, as options don't seem to be passed to the individual operators, but maybe you have an idea how this could be done without too much effort?