Fix: (org-ql-view--expand-buffers-files) Remove eval support
This prevents arbitrary code execution when opening "org-ql-search:" links. (The links feature was just pushed to master in the last day or so, and no stable release with the feature has been tagged.) This fix also means that arbitrary expressions are no longer accepted when interactively completing the buffers-files argument to org-ql-search (a worthy trade, I think; users who need to do that can call the function from Lisp).
This commit is contained in:
parent
c2c7efed00
commit
6ab74454d0
4 changed files with 37 additions and 41 deletions
|
|
@ -119,7 +119,6 @@ Interactively, may also be:
|
|||
- `all': search all Org buffers
|
||||
- `agenda': search buffers returned by the function `org-agenda-files'
|
||||
- `directory': search Org files in `org-directory'
|
||||
- An expression which evaluates to a list of files/buffers
|
||||
- A space-separated list of file or buffer names
|
||||
|
||||
QUERY: An `org-ql' query in either sexp or non-sexp form (see
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue