Re: [Evolution] Security implications of WebKit migration
- From: Jose Dapena Paz <jdapena igalia com>
- To: Dan Vratil <dvratil redhat com>
- Cc: evolution-list gnome org
- Subject: Re: [Evolution] Security implications of WebKit migration
- Date: Thu, 20 Sep 2012 11:56:01 +0200
El jue, 20-09-2012 a las 11:39 +0200, Dan Vratil escribiÃ:
The only unfortunate thing we haven't "fixed" yet are plugins. We have to have
plugins enabled in order to be able to inject GtkWidgets (like attachment bar)
into WebKit. This also means that Flash or Java content in enabled and that
they WILL be displayed and executed (assuming you have necessary plugins
installed) in the mail preview. We are aware of this and I have already
discussed with Milan a possible solution - writing our own "ad-block"
extension and force replace all <object> and <applet> tags by a placeholder.
A possibility would be avoiding embeding gtk at all, even for the
attachment bar, and implement it completely on html. Is this something
considered, or is the work to implement this is out of scope now?
[
Date Prev][
Date Next] [
Thread Prev][
Thread Next]
[
Thread Index]
[
Date Index]
[
Author Index]