[common] Prevent command execution in ExpandPathVariables (#87)

Command execution is not something users would expect. Even though
there is no security issue (right now), it's probably better to turn
it off.
This commit is contained in:
Lutz Justen
2023-03-06 15:25:49 +01:00
committed by GitHub
parent a8059e8572
commit c481b6a27f
2 changed files with 6 additions and 3 deletions
+2 -2
View File
@@ -104,8 +104,8 @@ absl::Status GetKnownFolderPath(FolderId folder_id, std::string* path);
// Expands environment path variables like %APPDATA% on Windows or ~ on Linux.
// On Windows, variables are matched case invariantly. Unknown environment
// variables are not changed.
// On Linux, performs a shell-like expansion. Returns an error if multiple
// results would be returned, e.g. from *.txt.
// On Linux, performs a shell-like expansion, but without command substitution.
// Returns an error if multiple results would be returned, e.g. from *.txt.
absl::Status ExpandPathVariables(std::string* path);
// Returns the environment variable with given |name| in |value|.