Angel Ezquerra avatar Angel Ezquerra committed 950e3df

Document that the [projrc] section is not transferred by default

Comments (0)

Files changed (1)

 same length, the key is *included* (i.e. inclusion takes precedence
 over exclusion).
 
+The extension excludes the ``[projrc]`` section by default. This
+ensures that a malicious user cannot add a ``[projrc]`` section to
+the remote ``projrc`` file to override the user's global projrc
+settings (e.g. to enable the transfer of the ``[hooks]`` section).
+
 Confirmation Settings
 ---------------------
 
Tip: Filter by directory path e.g. /media app.js to search for public/media/app.js.
Tip: Use camelCasing e.g. ProjME to search for ProjectModifiedEvent.java.
Tip: Filter by extension type e.g. /repo .js to search for all .js files in the /repo directory.
Tip: Separate your search with spaces e.g. /ssh pom.xml to search for src/ssh/pom.xml.
Tip: Use ↑ and ↓ arrow keys to navigate and return to view the file.
Tip: You can also navigate files with Ctrl+j (next) and Ctrl+k (previous) and view the file with Ctrl+o.
Tip: You can also navigate files with Alt+j (next) and Alt+k (previous) and view the file with Alt+o.