add gzip to exec bigbrother for sites and fix passphase print in site creator

This commit is contained in:
Kevin Froman 2020-01-29 15:44:44 -06:00
parent d0291c2fb3
commit 2bc14b5c63
2 changed files with 3 additions and 1 deletions

View file

@ -45,9 +45,11 @@ def block_exec(event, info):
"""Prevent arbitrary code execution in eval/exec and log it."""
# because libraries have stupid amounts of compile/exec/eval,
# We have to use a whitelist where it can be tolerated
# Generally better than nothing, not a silver bullet
whitelisted_code = [
'netrc.py',
'shlex.py',
'gzip.py',
'<werkzeug routing>',
'werkzeug/test.py',
'multiprocessing/popen_fork.py',