aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--desktop/NotificationRow.qml2
-rw-r--r--notifications/NotificationBalloon.qml2
-rw-r--r--shared/Notify.qml8
3 files changed, 10 insertions, 2 deletions
diff --git a/desktop/NotificationRow.qml b/desktop/NotificationRow.qml
index 04b0c0d..923cc9e 100644
--- a/desktop/NotificationRow.qml
+++ b/desktop/NotificationRow.qml
@@ -92,7 +92,7 @@ Rectangle {
Text {
width: parent.width
visible: text !== ""
- text: row.notification.body || ""
+ text: Notify.sanitize(row.notification.body)
textFormat: Text.RichText
wrapMode: Text.WordWrap
maximumLineCount: 2
diff --git a/notifications/NotificationBalloon.qml b/notifications/NotificationBalloon.qml
index b77ca2a..bfccda3 100644
--- a/notifications/NotificationBalloon.qml
+++ b/notifications/NotificationBalloon.qml
@@ -123,7 +123,7 @@ Rectangle {
Text {
width: parent.width
visible: text !== ""
- text: b.notification.body || ""
+ text: Notify.sanitize(b.notification.body)
textFormat: Text.RichText
wrapMode: Text.WordWrap
maximumLineCount: 3
diff --git a/shared/Notify.qml b/shared/Notify.qml
index 897e50b..c79f5f5 100644
--- a/shared/Notify.qml
+++ b/shared/Notify.qml
@@ -65,6 +65,14 @@ Singleton {
}
function close(id) { root.run(["close", String(id)]); }
function closeAll() { root.run(["close-all"]); }
+
+ // Inline images are local only. A notification is untrusted input, and a
+ // remote <img src> would otherwise make the shell fetch a URL, which leaks
+ // that the notification was shown. This removes such tags before the
+ // RichText body renders; a local path or file:// source is left alone.
+ function sanitize(body) {
+ return (body || "").replace(/<img\b[^>]*\bsrc\s*=\s*["']?\s*https?:\/\/[^>]*>/gi, "");
+ }
function action(id, key) { root.run(["action", String(id), key]); }
function clearHistory() { root.run(["clear-history"]); }