John J. Barton wrote:
Jonas Sicking wrote:
L. David Baron wrote:
* (maybe) ability to copy/paste file names (via context menu?)
I'd avoid 'paste' at this point since there are security concerns.
I.e. if you can get the user to copy the string '/etc/passwd' and then
paste it to the right place.
Is this different from a web page that instructs them to type
'/etc/passwd' in to the control? The "if you can get the user" part is
exactly what makes this not a security hole.
This is why we have disallowed typing a file-name. We had numerous
exploits due to allowing typing filenames.
I'm not saying we shouldn't look at these features at some point,
however it seems like a good idea to stay away from controversial 'new'
features at this point.
When do we get new reasonable features then? Dealing with files in
Firefox is significantly more painful than it should be.
Ok, I stand corrected. It's not that we shouldn't focus on adding these
features now. It's that we shouldn't do it as part of rewriting the
existing control.
If you have ideas for how to safely add any features feel free to start
a thread about how to do it. We can do it anytime, but we should treat
it separately to revamping the existing control.
/ Jonas
_______________________________________________
dev-tech-layout mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-tech-layout