diff options
| author | Danilo M. <danix@danix.xyz> | 2026-08-02 17:40:54 +0200 |
|---|---|---|
| committer | Danilo M. <danix@danix.xyz> | 2026-08-02 17:40:54 +0200 |
| commit | 485e06b796603ef760576748fbd96bc177d5fa49 (patch) | |
| tree | cdc94fe5ae06510e90390cb09c291747ca923a9b /docs/superpowers | |
| parent | 3e540e8b2c79006524ad11d3629361bde663db27 (diff) | |
| download | qtmaildir-485e06b796603ef760576748fbd96bc177d5fa49.tar.gz qtmaildir-485e06b796603ef760576748fbd96bc177d5fa49.zip | |
fix: scope qtmaildir: allow to the exact document base URL
Whole-scheme allow meant a hostile message body could reference any
qtmaildir: URL (e.g. <img src="qtmaildir://other">) and have it pass,
with safety depending entirely on Task 11's still-unwritten scheme
handler. Add setDocumentUrl() and require an exact QUrl match; deny
all qtmaildir: URLs when it is unset (fail closed). Document URL
survives resetForNewMessage() since it is a property of the view, not
of a message.
Diffstat (limited to 'docs/superpowers')
0 files changed, 0 insertions, 0 deletions
