[vlc-devel] Re: [RFC] sanitize MRL format
Rémi Denis-Courmont
rem at videolan.org
Fri Jun 15 16:53:38 CEST 2007
Le vendredi 15 juin 2007, Laurent Aimar a écrit :
> > What if I have a "http:" directory in the current path? Similarly,
> > if you give a filename, it must not end up trying to open the
> > network, even if the file cannot be stat'd for any reason
> > (including being unexpectedly missing).
>
> In any case you are doomed here. We cannot guess in the input if the
> user want to open the file or the url. So it is up to the gui to
> prepand file:// when it know the user want a file and to produce good
> url otherwise.
No I am not doomed. I simply will screw users using malformatted URLs
for the sake of the security of those who don't.
--
Rémi Denis-Courmont
http://www.remlab.net/
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 197 bytes
Desc: This is a digitally signed message part.
URL: <http://mailman.videolan.org/pipermail/vlc-devel/attachments/20070615/5f88f686/attachment.sig>
More information about the vlc-devel
mailing list