Re: [Evolution] Security implications of WebKit migration



El jue, 20-09-2012 a las 11:39 +0200, Dan Vratil escribiÃ:

The only unfortunate thing we haven't "fixed" yet are plugins. We have to have 
plugins enabled in order to be able to inject GtkWidgets (like attachment bar) 
into WebKit. This also means that Flash or Java content in enabled and that 
they WILL be displayed and executed (assuming you have necessary plugins 
installed) in the mail preview. We are aware of this and I have already 
discussed with Milan a possible solution - writing our own "ad-block" 
extension and force replace all <object> and <applet> tags by a placeholder.

A possibility would be avoiding embeding gtk at all, even for the
attachment bar, and implement it completely on html. Is this something
considered, or is the work to implement this is out of scope now?





[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]