Re: [kopete-devel] [PATCH] Incoming file transfer in chat window

2008-08-20 Thread Roman Jarosz
On Wed, 20 Aug 2008 18:36:01 +0200, Joshua J. Berry <[EMAIL PROTECTED]> wrote: > On Wednesday 20 August 2008 07:50:05 Martijn Klingens wrote: > ... >> Back to Kopete, depending on the protocol, incoming messages are added >> to >> the raw HTML, making the risk that at least one protocol inadvert

Re: [kopete-devel] [PATCH] Incoming file transfer in chat window

2008-08-20 Thread Joshua J. Berry
On Wednesday 20 August 2008 07:50:05 Martijn Klingens wrote: ... > Back to Kopete, depending on the protocol, incoming messages are added to > the raw HTML, making the risk that at least one protocol inadvertedly > allows injection of scripts quite real. > > That said, Javascript provides a load of

Re: [kopete-devel] [PATCH] Incoming file transfer in chat window

2008-08-20 Thread Martijn Klingens
On Sunday 17 August 2008 17:12:41 Matt Rogers wrote: > On Aug 16, 2008, at 8:23 PM, Olivier Goffart wrote: > > - PLEASE DO NOT ENABLE JAVASCRIPT BY DEFAULT! No security whole in > > kopete > > please :-) enable it on demand just when we need it. but > > javascript > > injection stuff should