]> sipb.mit.edu Git - ikiwiki.git/blobdiff - doc/security.mdwn
avoid floating boxes running up against the line at the bottom of the page
[ikiwiki.git] / doc / security.mdwn
index f3567d1558c5c2993571b5dc5a4eb0b9d33d2a46..dc763ef40a01bbae7d0f7ec09a3b8d08130dee89 100644 (file)
@@ -145,6 +145,13 @@ with a username containing html code (anymore).
 It's difficult to know for sure if all such avenues have really been
 closed though.
 
+## HTML::Template security
+
+If the [[plugins/template]] plugin is enabled, users can modify templates
+like any other part of the wiki. This assumes that HTML::Template is secure
+when used with untrusted/malicious templates. (Note that includes are not
+allowed, so that's not a problem.)
+
 ----
 
 # Fixed holes