Kozea / WeasyPrint

The awesome document factory
https://weasyprint.org
BSD 3-Clause "New" or "Revised" License
7.11k stars 679 forks source link

Add safe argument #2199

Closed AndreyFrolov44 closed 2 months ago

AndreyFrolov44 commented 2 months ago

Hi!

I suggest adding the safe argument, in which url_fetcher will be used, in which it will be impossible to download local files

liZe commented 2 months ago

Hi!

Thanks for this pull request.

Unfortunately, I don’t think that adding a safe option is a good idea, because it may give the impression that using it solves all the security concerns. Avoiding access to local files is only one small part of all the possible security problems that may happen with WeasyPrint, and there’s no silver bullet to avoid them all.