You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
If we trust the users they should be able to inject into the server new plans (and objects?) similar to how they do they do now when they are at the beamline. This needs to be done carefully as it is letting the users send us arbitrary Python code. We should consider
details of the mechanism (eval/exec, write to disk and import)
how to persist user added plans + devices
should we bother trying to validate / sanitize / sandbox (S. Dower has publicly said this is a lost cause)
if there needs to be any review steps by BL staff before the code is accepted to the system
The text was updated successfully, but these errors were encountered:
If we trust the users they should be able to inject into the server new plans (and objects?) similar to how they do they do now when they are at the beamline. This needs to be done carefully as it is letting the users send us arbitrary Python code. We should consider
The text was updated successfully, but these errors were encountered: