Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Ah but! The problem is SSI includes the bang directive, which outputs the results of a shell command.

Once that's available, people will demand and abuse it, and we're back at cgi-bin.



> SSI includes the bang directive,

Not in ngx_http_ssi_module or any modern webserver I've used? As for "people"? What people? I guess your implicit assumption is this is a group or commercial project? I was thinking more website made by a human person.


https://httpd.apache.org/docs/current/howto/ssi.html

(I've still never seen the need to switch to more trendy web servers, so they may well have disabled exec)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: