[vlc-devel] Re: [RFC] sanitize MRL format

Rémi Denis-Courmont rem at videolan.org
Fri Jun 15 16:53:38 CEST 2007


Le vendredi 15 juin 2007, Laurent Aimar a écrit :
> > What if I have a "http:" directory in the current path? Similarly,
> > if you give a filename, it must not end up trying to open the
> > network, even if the file cannot be stat'd for any reason
> > (including being unexpectedly missing).
>
>  In any case you are doomed here. We cannot guess in the input if the
> user want to open the file or the url. So it is up to the gui to
> prepand file:// when it know the user want a file and to produce good
> url otherwise.

No I am not doomed. I simply will screw users using malformatted URLs 
for the sake of the security of those who don't.

-- 
Rémi Denis-Courmont
http://www.remlab.net/
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 197 bytes
Desc: This is a digitally signed message part.
URL: <http://mailman.videolan.org/pipermail/vlc-devel/attachments/20070615/5f88f686/attachment.sig>


More information about the vlc-devel mailing list