ansible/docsite
James Cammarata fd30f53289 Fixing security issue with lookup returns not tainting the jinja2 environment
CVE-2017-7481

Lookup returns wrap the result in unsafe, however when used through the
standard templar engine, this does not result in the jinja2 environment being
marked as unsafe as a whole. This means the lookup result looses the unsafe
protection and may become simple unicode strings, which can result in bad
things being re-templated.

This also adds a global lookup param and cfg options for lookups to allow
unsafe returns, so users can force the previous (insecure) behavior.

(cherry picked from commit 72dfb1570d22ac519350a8c09e76c458789120ed)
(cherry picked from commit fadccda7c7a2e8d0650f4dee8e3cea93cf17acfd)
2017-05-08 15:59:55 -05:00
..
_static multiple spelling error changes 2014-04-29 10:41:05 -04:00
_themes/srtd updating stylesheet to make printing cleaner from HTML 2016-03-31 12:22:35 -04:00
js/ansible Remove extra "latest/" subdirectory in docs build structure. 2013-10-14 08:27:30 -04:00
man Remove extra "latest/" subdirectory in docs build structure. 2013-10-14 08:27:30 -04:00
rst Fixing security issue with lookup returns not tainting the jinja2 environment 2017-05-08 15:59:55 -05:00
.gitignore Add *.min.css to docsite/.gitignore 2014-01-06 17:15:04 -06:00
.nojekyll Subtree merge of ansible-docs 2012-10-08 07:44:38 -04:00
build-site.py Make "make webdocs" compatible with Python 3 2015-12-08 12:00:53 -05:00
conf.py Fix pygments lexer name 2016-03-13 09:50:52 +01:00
favicon.ico Retinafy favicon.ico 2014-05-12 11:29:45 -04:00
Makefile now generate list of playbook ojbect directives 2016-02-25 16:48:37 -05:00
modules.js Remove extra "latest/" subdirectory in docs build structure. 2013-10-14 08:27:30 -04:00
README.md Update README.md 2015-08-28 14:19:14 -04:00
variables.dot Add the start of a graphviz doc to illustrate variable precedence graphically. 2014-05-09 17:13:01 -04:00

Homepage and documentation source for Ansible

This project hosts the source behind docs.ansible.com

Contributions to the documentation are welcome. To make changes, submit a pull request that changes the reStructuredText files in the "rst/" directory only, and the core team can do a docs build and push the static files.

If you wish to verify output from the markup such as link references, you may install sphinx and build the documentation by running make viewdocs from the ansible/docsite directory.

To include module documentation you'll need to run make webdocs at the top level of the repository. The generated html files are in docsite/htmlout/.

If you do not want to learn the reStructuredText format, you can also file issues about documentation problems on the Ansible GitHub project.

Note that module documentation can actually be generated from a DOCUMENTATION docstring in the modules directory, so corrections to modules written as such need to be made in the module source, rather than in docsite source.

To install sphinx and the required theme, install pip and then "pip install sphinx sphinx_rtd_theme"