DataSpell auto‑run on notebook open: missing per‑file permission boundary
25K reputation · 02 Jul 2020, 13:04 UTC
Feature Overview
DataSpell offers a global setting to automatically run all cells of a notebook when it is opened. The option appears under Settings/Preferences → Tools → DataSpell and is enabled by default in several releases.
Current Constraint
There is no per‑notebook or per‑file permission prompt. A notebook opened from any directory will execute immediately, regardless of its provenance or the user’s trust level.
Unresolved Decision
The IDE documentation does not mention a safeguard to verify the source of a notebook or to warn the user before execution. JetBrains has not announced plans to provide a per‑file dialog or a “trusted‑directories only” toggle.
Key Questions
- Will JetBrains introduce a per‑notebook permission dialog that asks the user to confirm auto‑run before execution?
- Is there a roadmap to implement a global setting that restricts auto‑run to notebooks located in user‑specified trusted directories?
- What mechanisms can be added to detect untrusted notebooks and prevent accidental execution without disabling the feature entirely?