diff options
| author | Danilo M. <danix@danix.xyz> | 2026-08-02 17:40:54 +0200 |
|---|---|---|
| committer | Danilo M. <danix@danix.xyz> | 2026-08-04 12:52:26 +0200 |
| commit | 14843569125f7aeb4adaf547c323c8eb18961461 (patch) | |
| tree | a5d336ae18eb37f9e01fe5b78ac59d905940cd14 /src/mimeparser.h | |
| parent | ab4498ba12107529b8545f7d03dfe27433a3ffe2 (diff) | |
| download | qtmaildir-14843569125f7aeb4adaf547c323c8eb18961461.tar.gz qtmaildir-14843569125f7aeb4adaf547c323c8eb18961461.zip | |
fix: scope qtmaildir: allow to the exact document base URL
Whole-scheme allow meant a hostile message body could reference any
qtmaildir: URL (e.g. <img src="qtmaildir://other">) and have it pass,
with safety depending entirely on Task 11's still-unwritten scheme
handler. Add setDocumentUrl() and require an exact QUrl match; deny
all qtmaildir: URLs when it is unset (fail closed). Document URL
survives resetForNewMessage() since it is a property of the view, not
of a message.
Diffstat (limited to 'src/mimeparser.h')
0 files changed, 0 insertions, 0 deletions
