Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Respect ownership on code command installation #46962

Conversation

lloeki
Copy link
Contributor

@lloeki lloeki commented Mar 29, 2018

Fixes #46754

@lloeki
Copy link
Contributor Author

lloeki commented Mar 29, 2018

I'm winging this since my node build system is kinda dead locally. If anything looks or goes wrong I'll try and set it back up properly.

@lloeki
Copy link
Contributor Author

lloeki commented Mar 29, 2018

Note: there may be a privilege escalation vulnerability through injection here. A non-admin may put the app into a carefully crafted folder and ask an admin to authenticate to install the command. Is that a cause of concern? If so, is there an available facility to escape single quotes in a string?

@joaomoreno joaomoreno added this to the Backlog milestone Apr 3, 2018
@joaomoreno joaomoreno added macos Issues with VS Code on MAC/OS X workbench-os-integration Native OS integration issues labels Apr 3, 2018
@joaomoreno joaomoreno merged commit 67c4072 into microsoft:master Jul 6, 2018
@joaomoreno
Copy link
Member

Thanks! 🍻

@joaomoreno joaomoreno modified the milestones: Backlog, July 2018 Jul 6, 2018
@github-actions github-actions bot locked and limited conversation to collaborators Mar 27, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
macos Issues with VS Code on MAC/OS X workbench-os-integration Native OS integration issues
Projects
None yet
Development

Successfully merging this pull request may close these issues.

macOS: reckless ownership change of /usr/local/bin
2 participants